<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Google Workspace Forensics — Blog</title>
    <link>https://www.googleworkspaceforensics.com/en/blog</link>
    <description>Latest from Blog</description>
    <language>en</language>
    <lastBuildDate>Mon, 28 Sep 2026 22:07:49 GMT</lastBuildDate>
    <atom:link href="https://www.googleworkspaceforensics.com/en/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>Google Workspace Audit Log Retention and Other Limits</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-audit-log-limitations</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-audit-log-limitations</guid>
      <description>What Google Workspace audit logs can&apos;t tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.</description>
      <author>Florian Amette</author>
      <pubDate>Sun, 27 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace BEC Investigation Example (Fictional Case)</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-bec-investigation-example</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-bec-investigation-example</guid>
      <description>A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 24 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace Incident Response Checklist: First Hour</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-incident-response-checklist</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-incident-response-checklist</guid>
      <description>A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 21 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace Super Admin Compromised: Admin Log Checks</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-admin-role-sso-abuse</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-admin-role-sso-abuse</guid>
      <description>If a Google Workspace super admin is compromised: Admin log events for new admins, role grants, SSO changes, delegation, mail routing and compliance rules.</description>
      <author>Florian Amette</author>
      <pubDate>Fri, 18 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Drive Mass Download Detection and Takeout Exports</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-drive-mass-download-exfiltration</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-drive-mass-download-exfiltration</guid>
      <description>Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.</description>
      <author>Florian Amette</author>
      <pubDate>Wed, 16 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Domain-Wide Delegation Security Risks in Google Workspace</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-domain-wide-delegation-risks</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-domain-wide-delegation-risks</guid>
      <description>Domain-wide delegation security risks: how an API client can impersonate every user, the Admin log events that record it, DeleFriend and what to review.</description>
      <author>Florian Amette</author>
      <pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Suspicious OAuth App in Google Workspace: How to Investigate</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/suspicious-oauth-app-google-workspace</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/suspicious-oauth-app-google-workspace</guid>
      <description>Investigate a suspicious OAuth app in Google Workspace: read token log authorize and activity events, judge Gmail and Drive scopes, revoke and block the app.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Gmail Forwarding Rule Hacker: Find BEC Filters and Forwards</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/gmail-forwarding-rule-hacker</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/gmail-forwarding-rule-hacker</guid>
      <description>How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace Suspicious Login and 2SV Changes: A Guide</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-suspicious-login-2sv</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-suspicious-login-2sv</guid>
      <description>Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Analyze Google Workspace Audit Logs Step by Step</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/analyze-google-workspace-audit-logs</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/analyze-google-workspace-audit-logs</guid>
      <description>Step by step: load Google Workspace audit exports into a free in-browser analyzer, read the verdict and evidence, build a timeline, work the remediation list.</description>
      <author>Florian Amette</author>
      <pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>How to Export Google Workspace Audit Logs: Console, API, GAM</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/export-google-workspace-audit-logs</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/export-google-workspace-audit-logs</guid>
      <description>Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.</description>
      <author>Florian Amette</author>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Google Workspace Account Compromised? Investigation Guide</title>
      <link>https://www.googleworkspaceforensics.com/en/blog/google-workspace-compromise-investigation</link>
      <guid isPermaLink="true">https://www.googleworkspaceforensics.com/en/blog/google-workspace-compromise-investigation</guid>
      <description>How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.</description>
      <author>Florian Amette</author>
      <pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>