Skip to the card

Card 305 of 9842026-09-28 issue

Observed arrival · 2026-09-28

Google Workspace Forensics

googleworkspaceforensics.com Visit website
Editorial interest 84/100 Selection signal · not a rating of the site

A browser-based analyzer reads Google Workspace audit exports and assembles suspicious activity into a timeline with remediation guidance.

Landing page captured for the 2026-09-28 issue.
For
Google Workspace admins investigating suspected account compromise
Worth noticing
It accepts mixed log sources, including ZIP and .gz files, and warns that Gmail filters and forwarding settings are not in audit logs.

Field notes

The page gives both Admin console and GAM export routes, including commands that save separate CSV files for login, user accounts, OAuth, Gmail, Drive, and Admin activity. It recommends widening the date range because the console may default to seven days, and notes that access to exports requires a super admin or an administrator with Audit and investigation privileges. A synthetic fictional-business-email-compromise sample is available.

Observed signals

Read the marks

Editorial observations of this landing page, not a rating.

○OpenPublic substance visible
✦PrettyNotable craft visible
●ProPolished or operationally mature
◎NicheUnusually specific use
ƒJavaScriptBrowser-side code central

One card from the complete issue

Regulated by Arithmetic

233,109 arrived 1,000 judged 984 catalogued Enter the complete issue
googleworkspaceforensics.com

Landing page observed 2026-09-28. The live site may have changed.