Glossary
Plain-language definitions of the Google Workspace logging and incident-response terms used in our guides.
- Adversary-in-the-middle (AiTM) phishing
- Phishing through a reverse proxy that relays the real sign-in page, capturing the password, the 2SV step and the resulting session.
- Business email compromise (BEC)
- Fraud that uses a real or impersonated business mailbox to redirect payments or steal data, usually after an email account takeover.
- Domain-wide delegation
- A Google Workspace setting that lets a service account or API client act as any user in the domain for listed scopes, without user consent.
- Email hiding rule
- A mailbox filter that archives, deletes, marks as read or moves messages so the real user never sees them; a hallmark of BEC.
- External auto-forwarding
- A mailbox setting or filter that automatically copies incoming mail to an address outside the organization.
- Google Takeout
- Google's self-service export of an account's data (mail, Drive, calendar…) as downloadable archives; a fast exfiltration path.
- Hosting ASN
- An autonomous system belonging to a cloud or VPS provider; user sign-ins from one often indicate a proxy such as an AiTM phishing kit.
- Illicit consent grant
- A phishing technique in which the victim is tricked into authorizing an attacker's OAuth app, which then accesses their data with a token.
- Impossible travel
- Two sign-ins by the same account from locations too far apart for the time between them, suggesting that one session is not the user.
- OAuth scope
- A named permission an app requests on a Google account, such as reading Gmail or all of Drive; the scope list defines what a token can do.
- Reports API (Admin SDK)
- The Admin SDK API that returns Google Workspace audit log events (login, token, Gmail, Drive, admin…) as JSON with full parameters.
- Sign-in cookies reset
- An admin action that signs a Google Workspace user out of all browser sessions, evicting stolen sessions after an account takeover.
- Super administrator
- The Google Workspace role with unrestricted rights over the organization's settings, users and data, including delegation and SSO.
- 2-Step Verification (2SV)
- Google's name for multi-factor authentication: a second step after the password, from codes and prompts to security keys and passkeys.