Cloud Storage Clients on Mac: Dropbox, Drive, OneDrive
Dropbox, Google Drive and OneDrive on macOS keep sync databases, logs and File Provider folders that show which files were synced, shared or uploaded.
- Location
- ~/Library/CloudStorage/ plus each client's Application Support, Group Container and log folders
- Proves
- Which cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deleted
- Timestamps
- Mixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logs
- Access
- Owning user; some client databases are encrypted or obfuscated and need the user's keychain
- Retention
- Databases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trash
- Collection
- UAC, ditto, Disk image
Tools
Compare all tools- sqlite3CLI · built into macOS
- FSEventsParserCLI · open source
- plutilCLI · built into macOS
- grepCLI · built into macOS
What it is
Third-party sync clients are the most common route for data to leave a Mac in insider cases, and a frequent staging area for intruders. On current macOS, Dropbox, Google Drive and OneDrive all integrate through Apple's File Provider framework: files appear under ~/Library/CloudStorage/<Provider>-<account>/ and can be "online-only" placeholders that download on demand. Older installations (and some configurations) use legacy sync folders in the home directory instead.
Each client also keeps its own metadata databases and logs. These survive when the synced files themselves are gone or never downloaded. For Apple's own service, see iCloud Drive.
Where it lives
| Client | Paths | Notes |
|---|---|---|
| File Provider roots | ~/Library/CloudStorage/ | One folder per account, macOS 12.x and later for most vendors |
| Dropbox | ~/.dropbox/ (info.json, instance1/), ~/Library/Application Support/Dropbox/, ~/Dropbox on legacy installs | Several databases are encrypted with keys tied to the user's keychain |
| Google Drive (Drive for desktop) | ~/Library/Application Support/Google/DriveFS/ (root_preference_sqlite.db, <account_id>/metadata_sqlite_db, <account_id>/mirror_sqlite.db, Logs/) | Account ID folders are numeric |
| OneDrive | ~/Library/Containers/com.microsoft.OneDrive-mac/, ~/Library/Group Containers/UBF8T346G9.OneDriveStandaloneSuite/, ~/Library/Logs/OneDrive/ and ~/Library/Application Support/OneDrive/ depending on version | Settings per account (Personal, Business1) |
| File Provider state | ~/Library/Application Support/FileProvider/ | Apple's per-domain databases for all providers |
Paths shift with client versions more than with macOS versions. Search the home folder for the vendor names rather than trusting a fixed list.
What it proves
- Which accounts (e-mail, tenant, account ID) were linked on this Mac, and when the client was set up.
- The names, paths, sizes and hashes of files in the synced tree, including online-only files the Mac never downloaded.
- Uploads, downloads, deletions, renames and sharing actions, from client logs and databases.
- Moves of local files into a synced folder, from FSEvents: the classic exfiltration pattern of copying a project folder into Dropbox or OneDrive.
Key fields
| Source | Useful content |
|---|---|
Google Drive metadata_sqlite_db | items table: stable_id, local_title, mime_type, is_folder, trashed, modified_date, viewed_by_me_date, file_size; stable_parents for the tree |
Google Drive mirror_sqlite.db | Local mirror of synced items and their local paths |
Google Drive Logs/drive_fs*.txt | Sync events, uploads, account details |
Dropbox info.json | Personal and business account paths and host ID |
OneDrive settings (<account>.ini, ClientPolicy*.ini, <cid>.dat) | Account, tenant, library list; .dat holds the synced tree in a binary format |
OneDrive logs (.odl, .odlgz) | Obfuscated binary logs with sync operations |
Column names change with client versions; always inspect the schema.
Timestamps
Expect a mix: Unix epoch in seconds or milliseconds in Google Drive and Dropbox databases, plist dates in configuration files, local-time text in some logs, and Mac absolute time in File Provider data. Server-side dates (such as modified_date from the cloud) describe the cloud copy, not activity on this Mac; separate them from local sync events.
Retention
- Metadata databases reflect the current state of the account, so they also list files added from other devices.
- Deleted items disappear from the local databases but usually stay in the service's own trash or version history for weeks; request them from the provider or the tenant admin.
- Client logs rotate by size and age, typically covering days to weeks.
Collection
sudo ditto "/Users/<user>/Library/Application Support/Google/DriveFS" ./case/DriveFS_<user>
sudo ditto /Users/<user>/.dropbox ./case/dropbox_<user>
sudo ditto "/Users/<user>/Library/Group Containers/UBF8T346G9.OneDriveStandaloneSuite" ./case/onedrive_gc_<user>
sudo ditto "/Users/<user>/Library/Logs/OneDrive" ./case/onedrive_logs_<user>
ls -laR "/Users/<user>/Library/CloudStorage" > ./case/cloudstorage_listing_<user>.txt
Listing ~/Library/CloudStorage does not download placeholder files, but opening or hashing them can: avoid reading file content on a live system unless you intend to trigger downloads. UAC has artifacts for Dropbox and Google Drive databases and logs.
Parsing
sqlite3 -readonly metadata_sqlite_db \
"SELECT local_title, is_folder, trashed, datetime(modified_date/1000,'unixepoch') FROM items LIMIT 50;"
python3 FSEParser_V4.1.py -s ./case/fseventsd -t folder -o ./out -c case01
grep -iE 'upload|delete|share' ./case/DriveFS_<user>/Logs/drive_fs*.txt | head
Confirm the epoch unit (seconds or milliseconds) on a known file before converting.
Investigator tips
- Start with FSEvents: moves into
~/Library/CloudStorage/or the legacy sync folder around the time of interest give you file names even if the client data is encrypted. - netusage totals for the client process help size an upload.
- Files that arrived from a cloud folder usually carry no quarantine record; their absence in Quarantine events is expected.
- Enterprise tenants keep far better audit logs (Microsoft 365 unified audit log, Google Workspace Drive audit) than the Mac; ask for them early.