With the increase of cybercrimes in the cloud, cloud forensics has become an ongoing research area. Evidence collection is the fundamental and significant forensic phase for conducting the investigation in the information-rich cloud environment. To find the suspect and submit the potential evidence to the law enforcement system, evidence acquisition is the core forensic phase. Hence, acquiring forensic-rich evidence from the suspected system is essential in the cloud environment.