Observed arrival · 2026-09-28
Google Workspace Forensics
A browser-based analyzer reads Google Workspace audit exports and assembles suspicious activity into a timeline with remediation guidance.
- For
- Google Workspace admins investigating suspected account compromise
- Worth noticing
- It accepts mixed log sources, including ZIP and .gz files, and warns that Gmail filters and forwarding settings are not in audit logs.
Field notes
The page gives both Admin console and GAM export routes, including commands that save separate CSV files for login, user accounts, OAuth, Gmail, Drive, and Admin activity. It recommends widening the date range because the console may default to seven days, and notes that access to exports requires a super admin or an administrator with Audit and investigation privileges. A synthetic fictional-business-email-compromise sample is available.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue