Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Series

Google Workspace attack techniques in the logs

6 posts in this series. Read them in order or jump to any one.

  1. Google Workspace Suspicious Login and 2SV Changes: A Guide

    Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.

  2. Gmail Forwarding Rule Hacker: Find BEC Filters and Forwards

    How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.

  3. Suspicious OAuth App in Google Workspace: How to Investigate

    Investigate a suspicious OAuth app in Google Workspace: read token log authorize and activity events, judge Gmail and Drive scopes, revoke and block the app.

  4. Domain-Wide Delegation Security Risks in Google Workspace

    Domain-wide delegation security risks: how an API client can impersonate every user, the Admin log events that record it, DeleFriend and what to review.

  5. Google Drive Mass Download Detection and Takeout Exports

    Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.

  6. Google Workspace Super Admin Compromised: Admin Log Checks

    If a Google Workspace super admin is compromised: Admin log events for new admins, role grants, SSO changes, delegation, mail routing and compliance rules.

All posts in this series

Investigate a Google Workspace suspicious login: is_suspicious, hosting ASNs, new countries, impossible travel, failed-login bursts, 2SV and recovery changes.
How to find the Gmail forwarding rule or hidden filter a hacker left in a Workspace mailbox: the log events, the Gmail settings to export and what to delete.
Investigate a suspicious OAuth app in Google Workspace: read token log authorize and activity events, judge Gmail and Drive scopes, revoke and block the app.
Domain-wide delegation security risks: how an API client can impersonate every user, the Admin log events that record it, DeleFriend and what to review.
Detect data theft in Google Workspace: Drive mass download bursts, external sharing, public links, owner transfers and Google Takeout exports in audit logs.
If a Google Workspace super admin is compromised: Admin log events for new admins, role grants, SSO changes, delegation, mail routing and compliance rules.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.