Cloud Computing has fundamentally transformed how organizations worldwide provision and manage infrastructure, while at the same time introducing notable challenges for digital forensics and incident response. The traditional forensic approach relies heavily on physical access and static storage. This approach does not work well with cloud environments, as everything is virtual and dynamic, and evidence is distributed across many services and is volatile in nature. This paper presents a flexible cloud-focused forensic analysis framework. The framework integrates data from various AWS services, including CloudTrail, VPC Flow Logs, AWS Config, IAM Activity, and Security Configurations. It also gathers data from virtual machines, such as system logs and live memory snapshots, all managed by an API-driven framework. This framework helps investigators connect different types of evidence and build clear timelines, making it easier to identify security problems with less manual work. We tested this framework in a typical AWS environment. The results indicate that it can collect and link evidence from different parts of a system and assist in reconstructing events during suspicious activities. This work suggests that the framework can improve forensic processes and points to future research in automated forensics for both single-cloud and multi-cloud environments.