Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.

Independent tool, not affiliated with Google.

Was our Google Workspace compromised?

Drop your Workspace audit log exports and get a verdict in minutes: suspicious sign-ins, forwarding to outside addresses, hidden inbox filters, third-party apps reading mail, mass downloads and admin changes — with a timeline and a remediation checklist. Analysed in your browser with WebAssembly: nothing is uploaded.

  • Login / user
  • OAuth tokens
  • Gmail
  • Drive
  • Admin

Drop your Google Workspace log exports here

Admin console audit CSV exports (Login / User, OAuth, Gmail, Drive, Admin, SAML, Takeout, Groups), Reports API JSON (activities.list, GAM) and Gmail settings JSON. Loose files, folders, ZIP archives and .gz work as-is — add as many sources as you have: the detections correlate across them.

A synthetic export of a fictional business email compromise — invented company, people and addresses.

100% client-side: logs are analysed by WebAssembly in your browser and never uploaded.

Independent tool, not affiliated with Google.

How to get your logs

From nothing to a verdict in a few minutes: export the audit logs from the Admin console (or with GAM), then drop the files in the box above.

  1. Export the logs Admin console or GAM
  2. Drop them here Files, a folder or a ZIP
  3. Stays in your browser Nothing is uploaded

NeedsA super admin, or an admin with the Audit and investigation privilege. Nothing to install.

  1. Sign in to admin.google.com (console language: English) and open Reporting → Audit and investigation → User log events.
  2. Set the date range from 30 days before the suspicious email until today — the default is only the last 7 days. Optionally filter on the user.
  3. In Manage columns, add the IP ASN column if your console offers it: it is what reveals hosting networks.
  4. Click Export all → CSV (or Google Sheets, then File → Download → CSV) and save the file.
  5. Repeat for OAuth log events and Gmail log events (then Drive and Admin if you can), and drop all the CSV files here together.

Gotchas

  • Console exports cover only the date range shown (7 days by default) and at most 100,000 rows: widen the range, and split it by period if you hit the cap.
  • Audit logs are kept for about 6 months (less for some sources) and some events arrive hours late: export now, before cleaning up the account, and again a day later.
  • Keep the Admin console in English with the default column names: other console languages are not mapped yet. Dates without a time zone are read as UTC.

What this tool does

Google Workspace keeps audit logs of every sign-in, OAuth consent, Gmail delivery, Drive action and admin change. After a phishing email, those logs answer the only question that matters: did someone get in, and what did they do?

Drop the exports from the Admin console (or the Reports API / GAM) and the analyzer runs detection rules across all of them: it correlates a risky sign-in with what followed — forwarding to an outside address, filters hiding invoices, a third-party app reading mail, mass downloads, admin changes — and gives an overall verdict, the evidence, a timeline and the remediation steps.

What it detects

  • Sign-ins: Google's suspicious-login and leaked-password events, sign-ins from hosting / VPS networks (adversary-in-the-middle phishing), new countries, impossible travel, failed-login bursts, 2-step verification turned off, recovery email or phone changed.
  • Mail: forwarding to external addresses, Gmail filters that forward or hide invoice / payment mail, delegates and send-as aliases, auto-forwarded messages, finance mail trashed in bulk, outgoing "new bank details" emails.
  • OAuth: third-party apps granted Gmail, Drive or admin scopes (illicit consent grants), apps reading mail at volume, domain-wide delegation and app allow-listing.
  • Drive: mass downloads, bursts of external sharing, public links, ownership transfers, Google Takeout exports.
  • Admin: new super admins and admin roles, SSO / SAML changes, admin password resets, new users, mail routing and email monitors.
  • Each finding carries its MITRE ATT&CK techniques. The rules are plain JSON (crates/gws-wasm/rules/rules.json in the source), so they can be reviewed and reused.

Limitations

  • The verdict is only as good as the logs provided: a clean result on the sign-in log alone says nothing about Drive or OAuth. The tool lists the sources that were missing.
  • Detections are heuristics. Travelling users, VPNs and legitimate apps cause false positives; a careful attacker can stay below the thresholds.
  • Admin console CSV exports depend on the columns you selected and your console language: English column names and event titles are supported; the Reports API JSON is the most complete input.
  • Country and ASN come from Google's network information: without them (some CSV exports), new-country and impossible-travel checks cannot run.
  • Message content, Vault exports and the Security investigation tool's actions (deleting mail) are out of scope.

FAQ

Are my logs uploaded anywhere?

No. The analyzer is Rust compiled to WebAssembly and runs in a Web Worker in your browser. Files are read in chunks from your disk; there is no upload endpoint and no account.

How do I know if a Google Workspace account was compromised?

Look for a sign-in that doesn't fit (hosting network, new country, impossible travel) followed by persistence: forwarding to an outside address, a filter hiding invoice or payment mail, a new third-party app with Gmail access, or 2-step verification turned off. This tool checks those patterns and correlates them per account.

How do I find a Gmail forwarding rule set by an attacker?

The User log records "Out of domain email forwarding enabled" with the destination; the Gmail log shows messages auto-forwarded. Filters themselves are only visible in the user's Gmail settings: export them with the Gmail API or GAM and drop them here.

What is a suspicious OAuth app in Google Workspace?

An app a user authorised that can read or send their mail (https://mail.google.com/, gmail.readonly, gmail.settings…) or access all of Drive, especially right after a risky sign-in or with a lure name like "PDF viewer". Its token keeps working after a password reset until it is revoked.

Why can an attacker get past 2-step verification?

Adversary-in-the-middle phishing kits relay the real Google sign-in page: the victim types the password and approves the prompt, and the kit keeps the session. The sign-in then appears from the kit's server — usually a hosting provider — which this tool flags.

The verdict says compromised. What now?

Follow the remediation tab in order: contain the account (sign out sessions), revoke the app tokens, remove forwarding and filters, reset the password, warn the suppliers or customers who received fraudulent messages and stop pending payments. Then get incident response help to scope what was accessed.

Is this tool affiliated with Google?

No. It is an independent tool that reads the export formats Google documents. Google Workspace and Gmail are trademarks of Google LLC.

What Google Workspace audit logs can't tell you: 6-month retention, lag times, export row caps, CSV vs Reports API fields, license gaps and other blind spots.
A fictional business email compromise in Google Workspace, worked from the audit logs: AiTM sign-in, OAuth grant, hidden filter, fraud mail and Drive theft.
A first-hour checklist for a compromised Google Workspace account: preserve logs, cut sessions and OAuth tokens, remove forwarding and filters, stop payments.

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Workspace, Gmail and Google Drive are trademarks of Google LLC. Other names are trademarks of their respective owners.