Series
Google Workspace attack techniques in the logs
6 posts in this series. Read them in order or jump to any one.
- Google Workspace Suspicious Login and 2SV Changes: A Guide
Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.
- Gmail Forwarding Rule Hacker: Find BEC Filters and Forwards
How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.
- Suspicious OAuth App in Google Workspace: How to Investigate
Investigate a suspicious OAuth app in Google Workspace: read token log authorize and activity events, judge Gmail and Drive scopes, revoke and block the app.
- Domain-Wide Delegation Security Risks in Google Workspace
Domain-wide delegation security risks: how an API client can impersonate every user, the Admin log events that record it, DeleFriend and what to review.
- Google Drive Mass Download Detection and Takeout Exports
Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.
- Google Workspace Super Admin Compromised: Admin Log Checks
If a Google Workspace super admin is compromised: Admin log events for new admins, role grants, SSO changes, delegation, mail routing and compliance rules.