Series
Investigating a Google Workspace compromise
6 posts in this series. Read them in order or jump to any one.
- Google Workspace Account Compromised? Investigation Guide
How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.
- Google Workspace Incident Response Checklist: First Hour
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.
- How to Export Google Workspace Audit Logs: Console, API, GAM
Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.
- Analyze Google Workspace Audit Logs Step by Step
Step by step: load Google Workspace audit exports into a free in-browser analyzer, read the verdict and evidence, build a timeline, work the remediation list.
- Google Workspace BEC Investigation Example (Fictional Case)
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
- Google Workspace Audit Log Retention and Other Limits
What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.