Capture Cloud Attachments With Metadata
The Critical Evidence Gap in Email Investigations
Many tools capture only the hyperlink. Aid4Mail retrieves the linked documents from OneDrive, SharePoint, and Google Drive—with detailed metadata and optional point-in-time revision matching.
What Sets Aid4Mail Apart
Microsoft & Google
OneDrive, SharePoint, and Google Drive in one workflow
Document Revisions
Optionally match the version current at send time
AI-Ready Evidence
Classify and analyze attachment content, not just collect it
Metadata & Linkage
17 fields per file, linked to its parent email by EDRM MIH+
The Modern Attachment Challenge
Many business emails now link to cloud documents instead of attaching them. Collect only the message and you capture the link, not the file—leaving gaps in your investigation.
Link-Only Tools
- ⯈ Capture only the hyperlink
- ⯈ No document content collected
- ⯈ No file metadata or access roles
- ⯈ No point-in-time version
- ⯈ Gaps in the evidentiary record
Aid4Mail Solution
- ⯈ Retrieve the actual documents
- ⯈ Collect from Microsoft and Google
- ⯈ Detailed metadata, captured per file
- ⯈ Optional as-sent version matching
- ⯈ Per-file status for auditable exceptions
what many link-only tools and basic native searches return for a cloud attachment
what Aid4Mail collects from OneDrive, SharePoint, and Google Drive
Microsoft 365 and Google Workspace, collected together
Core Collection Capabilities
Collect cloud attachments from both the Microsoft and Google ecosystems in a single workflow—available in the Aid4Mail Investigator and Enterprise editions.
Dual-Platform Collection
Among the few tools that collect cloud attachments from both Microsoft 365 and Google Workspace in a single email-collection workflow.
Both ecosystems
Match Document Revision
By default, Aid4Mail collects each document’s latest available version. Enable Match document revision to instead capture the version current when the email was sent.
As-sent version
Rich Metadata Export
A FileMetadata.csv record per collection: authors, collaborators, viewers, timestamps, identifiers, file size, MIME type, source, version, and per-file status.
17 fields per file
Parent-Email Linkage
Each collected file records its parent email’s EDRM MIH+ identifier, preserving the email-to-file family relationship through review and production.
Family relationship preserved
AI-Ready Collection
Feed collected attachment content into Aid4Mail’s AI Filter, Classify, and Analyze tasks in the same workflow—analyze the linked file, not just collect it. Optional; requires downloaded files.
Collect, then classify
Tenant-Wide Scale
App-Only Access enables tenant-wide Microsoft 365 collection, with concurrent processing for large, high-volume matters.
Tenant-wide
How Cloud Attachment Collection Works
A four-step workflow: detect the links, authenticate, collect the files and metadata, and produce an auditable package.
Automatic Detection
Aid4Mail scans each processed email body (the message text) for cloud document links, regardless of the source email format (PST, OST, MSG, OLM, mbox, EML, and more). Links are read from the message body, so a cloud link contained only inside a traditional attachment isn’t detected.
Format-agnostic: Detects OneDrive, SharePoint, and Google Drive links in any supported source format
Authentication & Access
Connect with OAuth 2.1, use Microsoft 365 App-Only Access for tenant-wide collection, or access public files without credentials.
Flexible options: Delegated accounts, App-Only Access, or the Remote Authenticator for custodian consent
Intelligent Collection
Collect files with configurable controls: file-size limits, metadata-only mode, and optional document-revision matching.
Scope control: Pre-acquisition filtering and size limits keep collections proportional
Evidence Package
Output includes the original files, a FileMetadata.csv record, and a per-file status for every link processed. Collected files and metadata stay searchable through the Aid4Mail filter script in the same workflow.
Auditable: Per-file status logging makes exception sets defensible and reviewable
Turn Collected Attachments Into AI-Ready Evidence
Collected cloud attachments can feed Aid4Mail’s AI tasks—so you can filter, classify, and analyze the linked file’s content, not just collect it.
Analyze content, not just collect it
- ✓ Feed downloaded attachment text into Aid4Mail’s AI Filter, Classify, and Analyze tasks
- ✓ Enabled per task with Include attachment data under Project Settings → AI
- ✓ Cloud-attachment filenames are always included in the AI payload, even in metadata-only mode
Good to know
- ! Optional and off by default; requires the file to be downloaded (not metadata-only mode)
- ! No OCR; encrypted or password-protected files aren’t extracted
- ! The combined AI payload can exceed the model’s context window—validate on a representative sample first
Business Impact & ROI
Close the gap between what was shared and what you collect.
Collect the Files, Not Just the Links
Retrieve the documents that link-only exports leave behind
- Actual documents retrieved, not just hyperlinks
- Both Microsoft and Google ecosystems in one workflow
- Detailed metadata captured per file
- Per-file status logging for auditable exception sets
Point-in-Time Collection
Collect the latest version by default, or match the as-sent version
- By default, Aid4Mail collects the latest available version
- Enable Match document revision for the as-sent version
- Collect the version that was current when the email was sent
- Revision-notification emails are retained for review
Reduce Collection Gaps
Collect cloud-hosted files that link-only tools and basic native searches leave behind
Save Investigation Time
Automate cloud-attachment collection instead of issuing manual document requests
Preserve Evidentiary Families
Keep each collected file linked to its parent email by its EDRM MIH+ identifier for defensible production
Support Compliance
Use scope-limiting controls to support data-minimization obligations like GDPR, CCPA, and PIPA
Real-World Applications
See how investigators and legal teams use cloud-attachment collection across matters.
Litigation Support
- Produce the linked documents, not just their hyperlinks, under your ESI protocol
- Collect linked files plus their access-role metadata
- Capture the as-sent document version when required
- Preserve the email-to-file family link with an EDRM MIH+ identifier
IP Theft Investigations
- Trace documents shared through cloud links
- Identify files shared outside the organization
- Record collaborators and viewers on sensitive files
- Build a timeline from email-to-file linkage
Regulatory Compliance
- Include linked files in GDPR data subject access responses
- Collect financial documents referenced in emails
- Apply scope-limiting controls for data minimization
- Keep an auditable per-file status record
Incident Response
- Identify cloud-hosted files shared in suspect emails
- Record who had access to a file at collection time
- Assess third-party collaboration exposure
- Document the spread of sensitive documents
Technical Specifications
Built for professional collection workflows—available in the Aid4Mail Investigator and Enterprise editions.
Supported Sources
- ✓ OneDrive (Personal)
- ✓ OneDrive for Business
- ✓ SharePoint
- ✓ Google Drive
- ✓ Google Vault exports
Authentication
- ✓ OAuth 2.1
- ✓ Microsoft 365 App-Only Access
- ✓ Delegated permissions
- ✓ Public file access (no credentials)
Processing
- ✓ Document revision matching (optional)
- ✓ AI attachment-content analysis (optional)
- ✓ Searchable via filter script (Has:CloudAttachment)
- ✓ Incremental processing
- ✓ Concurrent processing
- ✓ Recursive MIME & archive scanning
- ✓ Multi-account collection
Output Formats
- ✓ Original file formats preserved
- ✓ Google Workspace → Office/CSV (10 MB export limit)
- ✓ FileMetadata.csv export (17 fields)
- ✓ Per-file status logging
App-Only Access applies to Microsoft 365 work tenants for tenant-wide collection. Personal Microsoft accounts reach OneDrive Personal; work accounts reach OneDrive for Business and SharePoint. With no account selected, Aid4Mail collects public files only. Google Workspace files export to Microsoft Office or CSV formats, subject to Google’s 10 MB export limit.
Defensible Cloud Evidence Collection
17
Metadata fields per file
OAuth 2.1
Secure authentication
10–500 MB
Optional file-size cap (default: no limit)
Both
Microsoft & Google ecosystems
Implementation Best Practices
Recommended Settings
- → Enable Match document revision only when the as-sent version is required
- → Set a file-size limit (10–500 MB) for high-volume collections
- → Use pre-acquisition filtering to narrow scope before collection
- → For large Google collections, export via Google Vault first (include linked Drive files) to avoid throttling
- → Review the per-file status column to audit exceptions
Common Pitfalls to Avoid
- ✗ Don’t enable revision matching without considering notification volume
- ✗ Don’t filter out notification emails by default—they may be the only link to a document
- ✗ Don’t collect without proper authorization
- ✗ Don’t exceed provider API quotas—watch for throttling (HTTP 429)
Stop Missing Critical Cloud Evidence
Collect cloud attachments and their metadata from Microsoft 365 and Google Workspace. Start your free trial today.