What is the difference between a cloud file and a local file?¶
A cloud file is stored within a cloud service. A local file is stored on the device being examined.
The same content may exist in both places, but the two copies may have different histories and metadata.
What this means in practice¶
A local file may also continue to exist after the cloud version is deleted. It may have been downloaded, exported, copied or left behind by synchronisation.
Neither copy automatically proves authorship or user knowledge.
When examining the evidence, identify whether the device holds the full content, a cached copy, an offline copy or only a reference to the cloud file.
What this may show¶
A cloud application may show a filename, thumbnail or placeholder while the full content remains online. The file may download only when opened.
Cloud records may show ownership, sharing, versions, server-side timestamps and access history. Local records may show download paths, application use, cached content, filesystem timestamps and device-specific activity.
The two sets of timestamps may differ. A cloud “modified” time may reflect an online edit. A local modification time may reflect download, synchronisation or local processing.
What this does not show on its own¶
The dangerous assumption is that a file displayed on a device must be fully stored there.
What to do next¶
Record the acquisition source. A provider export, a live account view and a forensic recovery from local storage are different evidence sources.
Compare cloud and local identifiers where available. Matching file IDs, hashes, names or version records may help establish the relationship, but each has limits.
Key takeaway
Cloud and local files may represent different copies of the same content, so establish where each copy existed, how it arrived and which history each source records.