Posts tagged: #audit-logs
What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.
Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.
Step by step: load Google Workspace audit exports into a free in-browser analyzer, read the verdict and evidence, build a timeline, work the remediation list.
Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.
How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.