Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Series

Investigating a Google Workspace compromise

6 posts in this series. Read them in order or jump to any one.

  1. Google Workspace Account Compromised? Investigation Guide

    How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.

  2. Google Workspace Incident Response Checklist: First Hour

    A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.

  3. How to Export Google Workspace Audit Logs: Console, API, GAM

    Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.

  4. Analyze Google Workspace Audit Logs Step by Step

    Step by step: load Google Workspace audit exports into a free in-browser analyzer, read the verdict and evidence, build a timeline, work the remediation list.

  5. Google Workspace BEC Investigation Example (Fictional Case)

    A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.

  6. Google Workspace Audit Log Retention and Other Limits

    What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.

All posts in this series

How to tell if a Google Workspace account was compromised: which audit logs to pull, the event names that matter, how to correlate them and what to rule out.
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.
Export Google Workspace audit logs for an investigation: Admin console CSV, the Reports API (activities.list), GAM reports and Gmail settings, with limits.
Step by step: load Google Workspace audit exports into a free in-browser analyzer, read the verdict and evidence, build a timeline, work the remediation list.
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.