Skip to main content
One Workflow

Capture Cloud Attachments With Metadata

The Critical Evidence Gap in Email Investigations

Many tools capture only the hyperlink. Aid4Mail retrieves the linked documents from OneDrive, SharePoint, and Google Drive—with detailed metadata and optional point-in-time revision matching.

Microsoft & Google platforms
Optional revision matching
Per-file status logging

What Sets Aid4Mail Apart

Microsoft & Google

OneDrive, SharePoint, and Google Drive in one workflow

Document Revisions

Optionally match the version current at send time

AI-Ready Evidence

Classify and analyze attachment content, not just collect it

Metadata & Linkage

17 fields per file, linked to its parent email by EDRM MIH+

The Modern Attachment Challenge

Many business emails now link to cloud documents instead of attaching them. Collect only the message and you capture the link, not the file—leaving gaps in your investigation.

Link-Only Tools

  • Capture only the hyperlink
  • No document content collected
  • No file metadata or access roles
  • No point-in-time version
  • Gaps in the evidentiary record

Aid4Mail Solution

  • Retrieve the actual documents
  • Collect from Microsoft and Google
  • Detailed metadata, captured per file
  • Optional as-sent version matching
  • Per-file status for auditable exceptions
Link only

what many link-only tools and basic native searches return for a cloud attachment

File + metadata

what Aid4Mail collects from OneDrive, SharePoint, and Google Drive

One workflow

Microsoft 365 and Google Workspace, collected together

Core Collection Capabilities

Collect cloud attachments from both the Microsoft and Google ecosystems in a single workflow—available in the Aid4Mail Investigator and Enterprise editions.

Dual-Platform Collection

Among the few tools that collect cloud attachments from both Microsoft 365 and Google Workspace in a single email-collection workflow.

Both ecosystems

Match Document Revision

By default, Aid4Mail collects each document’s latest available version. Enable Match document revision to instead capture the version current when the email was sent.

As-sent version

Rich Metadata Export

A FileMetadata.csv record per collection: authors, collaborators, viewers, timestamps, identifiers, file size, MIME type, source, version, and per-file status.

17 fields per file

Parent-Email Linkage

Each collected file records its parent email’s EDRM MIH+ identifier, preserving the email-to-file family relationship through review and production.

Family relationship preserved

AI-Ready Collection

Feed collected attachment content into Aid4Mail’s AI Filter, Classify, and Analyze tasks in the same workflow—analyze the linked file, not just collect it. Optional; requires downloaded files.

Collect, then classify

Tenant-Wide Scale

App-Only Access enables tenant-wide Microsoft 365 collection, with concurrent processing for large, high-volume matters.

Tenant-wide

How Cloud Attachment Collection Works

A four-step workflow: detect the links, authenticate, collect the files and metadata, and produce an auditable package.

1

Automatic Detection

Aid4Mail scans each processed email body (the message text) for cloud document links, regardless of the source email format (PST, OST, MSG, OLM, mbox, EML, and more). Links are read from the message body, so a cloud link contained only inside a traditional attachment isn’t detected.

Format-agnostic: Detects OneDrive, SharePoint, and Google Drive links in any supported source format

2

Authentication & Access

Connect with OAuth 2.1, use Microsoft 365 App-Only Access for tenant-wide collection, or access public files without credentials.

Flexible options: Delegated accounts, App-Only Access, or the Remote Authenticator for custodian consent

3

Intelligent Collection

Collect files with configurable controls: file-size limits, metadata-only mode, and optional document-revision matching.

Scope control: Pre-acquisition filtering and size limits keep collections proportional

4

Evidence Package

Output includes the original files, a FileMetadata.csv record, and a per-file status for every link processed. Collected files and metadata stay searchable through the Aid4Mail filter script in the same workflow.

Auditable: Per-file status logging makes exception sets defensible and reviewable

Turn Collected Attachments Into AI-Ready Evidence

Collected cloud attachments can feed Aid4Mail’s AI tasks—so you can filter, classify, and analyze the linked file’s content, not just collect it.

Analyze content, not just collect it

  • Feed downloaded attachment text into Aid4Mail’s AI Filter, Classify, and Analyze tasks
  • Enabled per task with Include attachment data under Project Settings → AI
  • Cloud-attachment filenames are always included in the AI payload, even in metadata-only mode

Good to know

  • ! Optional and off by default; requires the file to be downloaded (not metadata-only mode)
  • ! No OCR; encrypted or password-protected files aren’t extracted
  • ! The combined AI payload can exceed the model’s context window—validate on a representative sample first

Business Impact & ROI

Close the gap between what was shared and what you collect.

Collect the Files, Not Just the Links

Retrieve the documents that link-only exports leave behind

  • Actual documents retrieved, not just hyperlinks
  • Both Microsoft and Google ecosystems in one workflow
  • Detailed metadata captured per file
  • Per-file status logging for auditable exception sets

Point-in-Time Collection

Collect the latest version by default, or match the as-sent version

  • By default, Aid4Mail collects the latest available version
  • Enable Match document revision for the as-sent version
  • Collect the version that was current when the email was sent
  • Revision-notification emails are retained for review

Reduce Collection Gaps

Collect cloud-hosted files that link-only tools and basic native searches leave behind

Save Investigation Time

Automate cloud-attachment collection instead of issuing manual document requests

Preserve Evidentiary Families

Keep each collected file linked to its parent email by its EDRM MIH+ identifier for defensible production

Support Compliance

Use scope-limiting controls to support data-minimization obligations like GDPR, CCPA, and PIPA

Real-World Applications

See how investigators and legal teams use cloud-attachment collection across matters.

Litigation Support

  • Produce the linked documents, not just their hyperlinks, under your ESI protocol
  • Collect linked files plus their access-role metadata
  • Capture the as-sent document version when required
  • Preserve the email-to-file family link with an EDRM MIH+ identifier

IP Theft Investigations

  • Trace documents shared through cloud links
  • Identify files shared outside the organization
  • Record collaborators and viewers on sensitive files
  • Build a timeline from email-to-file linkage

Regulatory Compliance

  • Include linked files in GDPR data subject access responses
  • Collect financial documents referenced in emails
  • Apply scope-limiting controls for data minimization
  • Keep an auditable per-file status record

Incident Response

  • Identify cloud-hosted files shared in suspect emails
  • Record who had access to a file at collection time
  • Assess third-party collaboration exposure
  • Document the spread of sensitive documents

Technical Specifications

Built for professional collection workflows—available in the Aid4Mail Investigator and Enterprise editions.

Supported Sources

  • OneDrive (Personal)
  • OneDrive for Business
  • SharePoint
  • Google Drive
  • Google Vault exports

Authentication

  • OAuth 2.1
  • Microsoft 365 App-Only Access
  • Delegated permissions
  • Public file access (no credentials)

Processing

  • Document revision matching (optional)
  • AI attachment-content analysis (optional)
  • Searchable via filter script (Has:CloudAttachment)
  • Incremental processing
  • Concurrent processing
  • Recursive MIME & archive scanning
  • Multi-account collection

Output Formats

  • Original file formats preserved
  • Google Workspace → Office/CSV (10 MB export limit)
  • FileMetadata.csv export (17 fields)
  • Per-file status logging

App-Only Access applies to Microsoft 365 work tenants for tenant-wide collection. Personal Microsoft accounts reach OneDrive Personal; work accounts reach OneDrive for Business and SharePoint. With no account selected, Aid4Mail collects public files only. Google Workspace files export to Microsoft Office or CSV formats, subject to Google’s 10 MB export limit.

Defensible Cloud Evidence Collection

17

Metadata fields per file

OAuth 2.1

Secure authentication

10–500 MB

Optional file-size cap (default: no limit)

Both

Microsoft & Google ecosystems

Implementation Best Practices

Recommended Settings

  • Enable Match document revision only when the as-sent version is required
  • Set a file-size limit (10–500 MB) for high-volume collections
  • Use pre-acquisition filtering to narrow scope before collection
  • For large Google collections, export via Google Vault first (include linked Drive files) to avoid throttling
  • Review the per-file status column to audit exceptions

Common Pitfalls to Avoid

  • Don’t enable revision matching without considering notification volume
  • Don’t filter out notification emails by default—they may be the only link to a document
  • Don’t collect without proper authorization
  • Don’t exceed provider API quotas—watch for throttling (HTTP 429)

Stop Missing Critical Cloud Evidence

Collect cloud attachments and their metadata from Microsoft 365 and Google Workspace. Start your free trial today.