Skip to content

File accessNetwork

Cloud Storage Clients on Mac: Dropbox, Drive, OneDrive

Dropbox, Google Drive and OneDrive on macOS keep sync databases, logs and File Provider folders that show which files were synced, shared or uploaded.

Location
~/Library/CloudStorage/ plus each client's Application Support, Group Container and log folders
Proves
Which cloud accounts were linked, which files existed in or passed through the synced folders, and when they were uploaded, downloaded or deleted
Timestamps
Mixed: Unix epoch (seconds or milliseconds) in most client databases, Mac absolute time in File Provider data, local time in some logs
Access
Owning user; some client databases are encrypted or obfuscated and need the user's keychain
Retention
Databases track the current sync state; logs rotate by size and age; deleted files may remain in the cloud service's own trash
Collection
UAC, ditto, Disk image

What it is

Third-party sync clients are the most common route for data to leave a Mac in insider cases, and a frequent staging area for intruders. On current macOS, Dropbox, Google Drive and OneDrive all integrate through Apple's File Provider framework: files appear under ~/Library/CloudStorage/<Provider>-<account>/ and can be "online-only" placeholders that download on demand. Older installations (and some configurations) use legacy sync folders in the home directory instead.

Each client also keeps its own metadata databases and logs. These survive when the synced files themselves are gone or never downloaded. For Apple's own service, see iCloud Drive.

Where it lives

ClientPathsNotes
File Provider roots~/Library/CloudStorage/One folder per account, macOS 12.x and later for most vendors
Dropbox~/.dropbox/ (info.json, instance1/), ~/Library/Application Support/Dropbox/, ~/Dropbox on legacy installsSeveral databases are encrypted with keys tied to the user's keychain
Google Drive (Drive for desktop)~/Library/Application Support/Google/DriveFS/ (root_preference_sqlite.db, <account_id>/metadata_sqlite_db, <account_id>/mirror_sqlite.db, Logs/)Account ID folders are numeric
OneDrive~/Library/Containers/com.microsoft.OneDrive-mac/, ~/Library/Group Containers/UBF8T346G9.OneDriveStandaloneSuite/, ~/Library/Logs/OneDrive/ and ~/Library/Application Support/OneDrive/ depending on versionSettings per account (Personal, Business1)
File Provider state~/Library/Application Support/FileProvider/Apple's per-domain databases for all providers

Paths shift with client versions more than with macOS versions. Search the home folder for the vendor names rather than trusting a fixed list.

What it proves

  • Which accounts (e-mail, tenant, account ID) were linked on this Mac, and when the client was set up.
  • The names, paths, sizes and hashes of files in the synced tree, including online-only files the Mac never downloaded.
  • Uploads, downloads, deletions, renames and sharing actions, from client logs and databases.
  • Moves of local files into a synced folder, from FSEvents: the classic exfiltration pattern of copying a project folder into Dropbox or OneDrive.

Key fields

SourceUseful content
Google Drive metadata_sqlite_dbitems table: stable_id, local_title, mime_type, is_folder, trashed, modified_date, viewed_by_me_date, file_size; stable_parents for the tree
Google Drive mirror_sqlite.dbLocal mirror of synced items and their local paths
Google Drive Logs/drive_fs*.txtSync events, uploads, account details
Dropbox info.jsonPersonal and business account paths and host ID
OneDrive settings (<account>.ini, ClientPolicy*.ini, <cid>.dat)Account, tenant, library list; .dat holds the synced tree in a binary format
OneDrive logs (.odl, .odlgz)Obfuscated binary logs with sync operations

Column names change with client versions; always inspect the schema.

Timestamps

Expect a mix: Unix epoch in seconds or milliseconds in Google Drive and Dropbox databases, plist dates in configuration files, local-time text in some logs, and Mac absolute time in File Provider data. Server-side dates (such as modified_date from the cloud) describe the cloud copy, not activity on this Mac; separate them from local sync events.

Retention

  • Metadata databases reflect the current state of the account, so they also list files added from other devices.
  • Deleted items disappear from the local databases but usually stay in the service's own trash or version history for weeks; request them from the provider or the tenant admin.
  • Client logs rotate by size and age, typically covering days to weeks.

Collection

sudo ditto "/Users/<user>/Library/Application Support/Google/DriveFS" ./case/DriveFS_<user>
sudo ditto /Users/<user>/.dropbox ./case/dropbox_<user>
sudo ditto "/Users/<user>/Library/Group Containers/UBF8T346G9.OneDriveStandaloneSuite" ./case/onedrive_gc_<user>
sudo ditto "/Users/<user>/Library/Logs/OneDrive" ./case/onedrive_logs_<user>
ls -laR "/Users/<user>/Library/CloudStorage" > ./case/cloudstorage_listing_<user>.txt

Listing ~/Library/CloudStorage does not download placeholder files, but opening or hashing them can: avoid reading file content on a live system unless you intend to trigger downloads. UAC has artifacts for Dropbox and Google Drive databases and logs.

Parsing

sqlite3 -readonly metadata_sqlite_db \
  "SELECT local_title, is_folder, trashed, datetime(modified_date/1000,'unixepoch') FROM items LIMIT 50;"

python3 FSEParser_V4.1.py -s ./case/fseventsd -t folder -o ./out -c case01
grep -iE 'upload|delete|share' ./case/DriveFS_<user>/Logs/drive_fs*.txt | head

Confirm the epoch unit (seconds or milliseconds) on a known file before converting.

Investigator tips

  • Start with FSEvents: moves into ~/Library/CloudStorage/ or the legacy sync folder around the time of interest give you file names even if the client data is encrypted.
  • netusage totals for the client process help size an upload.
  • Files that arrived from a cloud folder usually carry no quarantine record; their absence in Quarantine events is expected.
  • Enterprise tenants keep far better audit logs (Microsoft 365 unified audit log, Google Workspace Drive audit) than the Mac; ask for them early.

See also