Skip to content
CLD-156 Cloud Services

How do I distinguish device evidence from cloud evidence?

Device evidence is held on or generated by the physical device. Cloud evidence is held or generated by the provider or organisational cloud environment.

Evidential caution: that finding the same file or event in both places means the records are identical.

What this means

A device may hold a local copy, cache, preview, browser artefact, application database, token or synchronisation record.

The cloud service may hold account details, session logs, audit events, sharing history, versions, deleted items and administrator actions.

The two sources often describe different stages of the same activity.

A device may record when a file was created locally. The provider may record when it was uploaded. A second device may record when it synchronised.

A difference may explain the sequence rather than indicate an error.

Also consider that cloud activity may exist with no local device copy, while a downloaded file may remain after the provider version is deleted.

The strongest reconstruction comes from linking device and cloud evidence while retaining their separate meanings.

Where collection is staged, keep a source map showing which records came from the device, provider, organisation and connected applications. This prevents later duplication or confusion.

What to check or do next

  • Investigators should preserve each source separately and record what system generated each field.
  • Compare file IDs, versions, hashes, timestamps, paths, account IDs and session details.
  • Do not overwrite one source with the other.

Operational takeaway

Treat device and cloud records as separate evidence sources that may describe different events, then link them through identifiers, versions, sessions and timing.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.