Blog >> pCloud

Investigating pCloud

14/04/2022 Friday

pCloud is a cloud storage service developed by a Swiss company founded in 2013. It is a standard cloud storage service for keeping files private, stable, and accessible across all platforms. pCloud also provides file management, sharing, versioning, security, backup, and digital assets management. The app is available on Windows, Mac, Linux, Android, and iOS devices.


Digital Forensics Value of pCloud Artifact


pCloud artifacts provide information about files and folders that the user created, modified, uploaded, and used in pCloud, as well as files and folders shared with other users. Tracking such information can be critical during a digital forensic analysis.


Location and Structure of pCloud Artifact


In Windows 10, pCloud artifacts are found in the following location:

%systempartititon%\Users\%username%\AppData\Local\pCloud

The artifacts are mainly extracted from the database and cache files seen below.


Analyzing pCloud Recent Files with ArtiFast Windows

This section will discuss how to use ArtiFast to extract pCloud artifacts from Windows and what kind of digital forensic insights we can gain from the artifacts.

After you have created your case and added evidence for the investigation, at the Artifact Selection phase, you can select pCloud artifacts.





Once ArtiFast parser plugins complete processing the artifact for analysis, it can be reviewed via “Artifact View” or “Timeline View,” with indexing, filtering, and searching capabilities. Below is a detailed description of Windows pCloud artifacts in ArtiFast.


pCloud Drive Files

pCloud Folders

pCloud Local Files

pCloud Local Folders

pCloud Sync Folders

pCloud User Information



For more information or suggestions please contact: ekrma.elnour@forensafe.com