GAT Shield is a Chrome extension that allows admins to track and view user behavior in Google Workspace.
Google Workspace Admins can set up real-time alerts based on the behavior of end-users.
In this post, we’ll go through the ‘Downloads’ section of GAT Shield and how it can be used by admins to view and manage all downloads happening across their domain.
There you can see all files downloaded by your users through their Chrome browsers.
You can also view the URL, download date, where the files were downloaded files from, the file format, where it’s stored, its size, when the download started, and when it finished. That’s in addition to seeing who downloaded the file.
How to Manage Domain-Wide Downloads in Google Workspace? #
Start by applying filters #
Let’s use a filter to find a specific set of results.
Using the ‘apply filters’ button, We’ll create a filter to search for a specific OU.
Navigate to Shield → Audit → Downloads → Apply custom filter
In this example:
- Domain – enter the domain name
- User org. unit – enter the org. unit needed
- MIME – enter the mime type (image/png) – as example
View details #
On the right-side under action click on the “eye” icon to view all the details pertaining to that download.
Here you will have access to the GAT shield instance details. the GAT Shield UUID is a unique ID given to every user per device.
Find the device that the file was downloaded on #
We’ll go ahead and copy this UUID and go to the user device geo reporting section. We can create a filter using the Shield UUID filter and paste it into the ID.
Now we have received information about:
- Shield version
- the user was running
- the serial number if they are using a Chromebook and the OS of the device.
- Also, get their public IP private IP and geolocation information such as city and country.
This example can help you find what device the file was downloaded on.
You can also take proactive measures to curb the downloading of files you deem unsafe.
Set up an Alert rule for Downloads #
To do this, select the alert rules section.
Navigate to Shield → Configuration → Alert Rules → +Add a rule
- Add a rule for Downloads – File download
- Alert rule name – enter a name for the rule
- Active – enable or disable the rule
- File extension – enter the extension type, such as an exe, pdf, doc, png, mov – separate by semicolon
- File size – enter the size of files
- Cancel/delete download – enable or disable the option to prevent the downloads of the files
- If selected (enabled) the file will be downloaded and removed from the users’ account
- If unselected (disabled) only alert will be generated, the downloads will not be canceled
- Report file name – enable or disable the view of the file name
- Scope – enter where the rules are to be active to which users, if blank the rule will be applied to all Shield users
- Screen/Webcam capture – You can check the report file name, screen capture, and webcam capture to see who downloaded the file and what their screen and webcam were capturing at the time of the download.
- Site exclusion – enter the sites where the rule will not be applied to.