{"id":17171,"date":"2026-06-08T09:29:32","date_gmt":"2026-06-08T08:29:32","guid":{"rendered":"https:\/\/gatlabs.com\/knowledge\/?post_type=docs&#038;p=17171"},"modified":"2026-06-08T13:12:30","modified_gmt":"2026-06-08T12:12:30","password":"","slug":"investigate-google-workspace-account-compromise-with-gat","status":"publish","type":"docs","link":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/","title":{"rendered":"Investigate Google Workspace Account Compromise with GAT+"},"content":{"rendered":"<h2 data-path-to-node=\"1\">Introduction<\/h2>\n<p id=\"p-rc_24df62a24ffccb87-26\" data-path-to-node=\"2\"><span class=\"citation-13 citation-end-13 interactive-span-hovered\">When a Google Workspace account is suspected of being compromised, security teams must act quickly to determine the scope and impact of the breach.<\/span> While standard Google alerts provide basic notifications for unusual sign-ins, conducting a thorough forensic investigation requires deeper domain-wide visibility<\/p>\n<p data-path-to-node=\"3\">GAT+ serves as a powerful investigation tool, enabling administrators to trace malicious activity, perform blast-radius analysis, and answer critical incident-response questions. This article covers how to investigate an account compromise using GAT+ across four essential areas:<\/p>\n<ol>\n<li data-path-to-node=\"4,0,0\">Pinpointing the first suspicious login<\/li>\n<li data-path-to-node=\"4,1,0\">Determining the total duration of attacker access<\/li>\n<li data-path-to-node=\"4,2,0\">Tracking key actions performed during the compromise<\/li>\n<li data-path-to-node=\"4,3,0\">Identifying other users, files, or systems that may be affected<\/li>\n<\/ol>\n<h2 data-path-to-node=\"6\">Pinpointing the First Suspicious Login<\/h2>\n<p id=\"p-rc_24df62a24ffccb87-27\" data-path-to-node=\"7\">Identifying the exact moment an attacker gained unauthorized access is crucial for establishing an incident timeline. <span class=\"citation-12 citation-end-12\">Attackers often utilize compromised credentials from unexpected geographic locations or via known VPN\/proxy networks.<\/span><\/p>\n<p data-path-to-node=\"9,0,0\">Navigate to <b data-path-to-node=\"9,0,0\" data-index-in-node=\"12\">GAT+ &gt; Audit &amp; Management &gt; Users Logins<\/b>.<\/p>\n<p>\u00a0<img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone wp-image-17246 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1.png\" alt=\"User login events page\" width=\"1578\" height=\"1199\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1.png 1578w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1-300x228.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1-1024x778.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1-768x584.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1-1536x1167.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-04-19_48_02-1-360x274.png 360w\" sizes=\"(max-width: 1578px) 100vw, 1578px\" \/><\/p>\n<p data-path-to-node=\"9,2,0\">Click the <b data-path-to-node=\"9,2,0\" data-index-in-node=\"10\">Apply custom filter<\/b> button to isolate anomalous activity:<\/p>\n<ul>\n<li data-path-to-node=\"9,2,1,0,0\">Set a filter such as <strong>&#8216;ISO region (from Google) not equal to (Your ISO Region)&#8217; <\/strong>or &#8216;<strong>Country not equal to (Country name)&#8217;<\/strong>.<\/li>\n<li data-path-to-node=\"9,2,1,1,0\">Filter by Event equal to &#8216;<strong>OK<\/strong>&#8216; OR &#8216;<strong>Risky action allowed<\/strong>&#8216; OR &#8216;<strong>Suspicious login<\/strong>&#8216;\u00a0to see successful logins from these anomalous locations.<\/li>\n<li data-path-to-node=\"9,2,1,1,0\">Look for a cluster of &#8216;<strong>Login failure<\/strong>&#8216; events immediately followed by a successful login (<strong>Event equal to OK<\/strong>), which frequently indicates a successful brute-force or credential-stuffing attempt.<\/li>\n<\/ul>\n<p><img decoding=\"async\" class=\"alignnone wp-image-17247 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54.png\" alt=\"Applying a filter for ISO region and events for the user logins events page.\" width=\"1570\" height=\"927\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54.png 1570w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54-300x177.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54-1024x605.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54-768x453.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54-1536x907.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-16_44_54-360x213.png 360w\" sizes=\"(max-width: 1570px) 100vw, 1570px\" \/><\/p>\n<p>Note the <b data-path-to-node=\"9,3,0\" data-index-in-node=\"9\">Date<\/b>, <b data-path-to-node=\"9,3,0\" data-index-in-node=\"15\">Time<\/b>, <b data-path-to-node=\"9,3,0\" data-index-in-node=\"21\">IP Address<\/b>, and <b data-path-to-node=\"9,3,0\" data-index-in-node=\"37\">Location<\/b> of the earliest unauthorized successful login. This marks the starting point of the compromise.<\/p>\n<h2 data-path-to-node=\"11\">Determining the Duration of Attacker Access<\/h2>\n<p data-path-to-node=\"12\">To understand how much time the attacker had to exfiltrate data or alter configurations, you must calculate the window of exposure, the time between the initial entry and the final remediation step.<\/p>\n<p data-path-to-node=\"14,0,0\">Remaining in <b data-path-to-node=\"14,0,0\" data-index-in-node=\"13\">GAT+ &gt; Audit &amp; Management &gt; Users Logins<\/b>, use the <b data-path-to-node=\"14,0,0\" data-index-in-node=\"63\">Apply custom filter<\/b> tool to create a filter using the specific malicious <b data-path-to-node=\"14,1,0\" data-index-in-node=\"45\">IP Address<\/b> or unique <b data-path-to-node=\"14,1,0\" data-index-in-node=\"66\">Location<\/b> identified during the first suspicious login step.<\/p>\n<p data-path-to-node=\"14,2,0\"><img decoding=\"async\" class=\"alignnone wp-image-17201 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03.png\" alt=\"Filtering by IP in the user logins event page\" width=\"1483\" height=\"745\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03.png 1483w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03-300x151.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03-1024x514.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03-768x386.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_22_03-360x181.png 360w\" sizes=\"(max-width: 1483px) 100vw, 1483px\" \/><\/p>\n<p data-path-to-node=\"14,2,0\">Review the login events to see all subsequent sessions established by the attacker. The duration of access is defined as the time elapsed from the first successful suspicious login timestamp to the final recorded attacker event, such as a logout.<\/p>\n<p data-path-to-node=\"14,2,0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17200 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43.png\" alt=\"User login events results\" width=\"1487\" height=\"884\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43.png 1487w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-300x178.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-1024x609.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-768x457.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-360x214.png 360w\" sizes=\"(max-width: 1487px) 100vw, 1487px\" \/><\/p>\n<h2 data-path-to-node=\"16\">Tracking Key Actions Performed During the Compromise<\/h2>\n<p id=\"p-rc_24df62a24ffccb87-28\" data-path-to-node=\"17\">Once inside, attackers typically look to exfiltrate data, establish persistence, or move laterally. <span class=\"citation-11 citation-end-11\">GAT+ allows you to audit specific actions taken across Google Drive and Gmail during the window of compromise.<\/span><\/p>\n<p data-path-to-node=\"17\">We will first check whether the compromised account has set up any email auto-forwarding or email delegate access. Navigate to <b data-path-to-node=\"28,0,0\" data-index-in-node=\"17\">GAT+ &gt; Audit &amp; Management &gt; <\/b><strong>Users &gt; Email Info <\/strong>and filter for that user&#8217;s account.<\/p>\n<p data-path-to-node=\"17\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17219 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1.png\" alt=\"Filtering in Users &gt;Email Info\" width=\"1546\" height=\"939\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1.png 1546w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1-300x182.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1-1024x622.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1-768x466.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1-1536x933.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_37_34-1-360x219.png 360w\" sizes=\"(max-width: 1546px) 100vw, 1546px\" \/><\/p>\n<p data-path-to-node=\"17\">You can then delete the email delegates for any user by clicking the\u00a0<strong>x<\/strong> (1) icon beside the email address. You are also able to <strong>delete auto forwarding<\/strong> (2) setup by clicking the dropdown on the right.<\/p>\n<p data-path-to-node=\"17\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17220 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17.png\" alt=\"Removing email delegates or delete auto forwarding in the users section of GAT+\" width=\"1557\" height=\"638\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17.png 1557w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17-300x123.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17-1024x420.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17-768x315.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17-1536x629.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_45_17-360x148.png 360w\" sizes=\"(max-width: 1557px) 100vw, 1557px\" \/><\/p>\n<p data-path-to-node=\"17\">We will now check whether the compromised account made any changes to Drive files. In the <b data-path-to-node=\"30,0,0\" data-index-in-node=\"7\">Drive &gt; Events<\/b> audit area, adjust the date &amp; time to show all files modified or shared during the compromise window.<\/p>\n<p data-path-to-node=\"17\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17225 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1.png\" alt=\"Drive events results in GAT+\" width=\"1548\" height=\"909\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1.png 1548w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-300x176.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-1024x601.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-768x451.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-1536x902.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-360x211.png 360w\" sizes=\"(max-width: 1548px) 100vw, 1548px\" \/><\/p>\n<h2 data-path-to-node=\"24\">Identifying Other Affected Users, Files, or Systems<\/h2>\n<p data-path-to-node=\"25\">An investigation is incomplete without understanding the full scale. Attackers often try to reuse credentials across multiple accounts or use a compromised account to infect other systems and files.<\/p>\n<h3 data-path-to-node=\"25\">Impact on Other Users<\/h3>\n<p data-path-to-node=\"28,0,0\">Navigate back to <b data-path-to-node=\"28,0,0\" data-index-in-node=\"17\">GAT+ &gt; Audit &amp; Management &gt; Users Logins<\/b>. Apply a custom filter searching for the malicious <b data-path-to-node=\"28,1,0\" data-index-in-node=\"50\">IP Address<\/b> identified in your initial discovery. This will allow you to check whether the same IP address attempted or successfully logged in to <i data-path-to-node=\"28,2,0\" data-index-in-node=\"77\">other<\/i> user accounts across your Google Workspace domain.<\/p>\n<p data-path-to-node=\"28,0,0\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17200 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43.png\" alt=\"User login events results\" width=\"1487\" height=\"884\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43.png 1487w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-300x178.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-1024x609.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-768x457.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-14_11_43-360x214.png 360w\" sizes=\"(max-width: 1487px) 100vw, 1487px\" \/><\/p>\n<h3 data-path-to-node=\"28,0,0\">Impact on Files<\/h3>\n<p>In the <b data-path-to-node=\"30,0,0\" data-index-in-node=\"7\">Drive &gt; Events<\/b> audit area, adjust the date &amp; time to show all files modified or shared during the compromise window as shown above in step 3.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17225 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1.png\" alt=\"Drive events results\" width=\"1548\" height=\"909\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1.png 1548w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-300x176.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-1024x601.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-768x451.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-1536x902.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_07_35-1-360x211.png 360w\" sizes=\"(max-width: 1548px) 100vw, 1548px\" \/><\/p>\n<h3 data-path-to-node=\"28,0,0\">Impact on Emails<\/h3>\n<p>In the <strong>Email &gt; User Statistics\u00a0<\/strong>audit area, adjust the user (3), date (4), and click &#8216;Filter data&#8217; (5). This will show results of all emails sent and received for both external and internal users. You can then click any of the numbers below, and this will redirect you to the Emails section to investigate further.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17267 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2.png\" alt=\"Email user statistics\" width=\"1554\" height=\"774\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2.png 1554w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2-300x149.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2-1024x510.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2-768x383.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2-1536x765.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_26_11-2-360x179.png 360w\" sizes=\"(max-width: 1554px) 100vw, 1554px\" \/><\/p>\n<h3>Impact on Applications<\/h3>\n<p>Navigate to <b data-path-to-node=\"32,0,0\" data-index-in-node=\"12\">GAT+ &gt; Audit &amp; Management &gt; Applications.\u00a0<\/b>Search for any new third-party applications or OAuth API scopes authorized by the compromised user during the breach window by sorting by <strong>&#8216;Since&#8217; <\/strong>(3).<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17228 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33.png\" alt=\"Application scopes in GAT+\" width=\"1549\" height=\"909\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33.png 1549w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33-300x176.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33-1024x601.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33-768x451.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33-1536x901.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_12_33-360x211.png 360w\" sizes=\"(max-width: 1549px) 100vw, 1549px\" \/><\/p>\n<p>Attackers often authorize malicious apps to maintain a backdoor into the workspace, even after their primary login session is terminated. <span class=\"citation-7 citation-end-7\">If any unrecognized apps with extensive read\/write permissions are found, ban this application through the GAT+ interface.<\/span><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-17229 size-full\" src=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15.png\" alt=\"Creating a ban policy for applications in GAT+\" width=\"1547\" height=\"781\" srcset=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15.png 1547w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15-300x151.png 300w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15-1024x517.png 1024w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15-768x388.png 768w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15-1536x775.png 1536w, https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2026\/06\/2026-06-05-15_19_15-360x182.png 360w\" sizes=\"(max-width: 1547px) 100vw, 1547px\" \/><\/p>\n<h2>Related Posts<\/h2>\n<ul>\n<li><a href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/how-to-set-up-gmail-alerts-for-google-workspace-users\/\" target=\"_blank\" rel=\"noopener\">Set Up Gmail Alerts for Google Workspace Users with GAT+<\/a><\/li>\n<li><a href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/alert-when-2fa-is-disabled-for-any-user-in-your-google-domain\/\" target=\"_blank\" rel=\"noopener\">Alert when 2FA is disabled for any user in your Google domain with GAT+<\/a><\/li>\n<li><a href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/how-to-set-up-user-security-alerts-gat-plus\/\" target=\"_blank\" rel=\"noopener\">How to Set Up User Security Alerts with GAT+<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Introduction When a Google Workspace account is suspected of being compromised, security teams must act quickly to determine the scope and impact of the breach. While standard Google alerts provide basic notifications for unusual sign-ins, conducting a thorough forensic investigation requires deeper domain-wide visibility GAT+ serves as a powerful investigation tool, enabling administrators to trace [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":4504,"comment_status":"open","ping_status":"closed","template":"","meta":{"footnotes":""},"doc_category":[37,21],"glossaries":[],"doc_tag":[24],"class_list":["post-17171","docs","type-docs","status-publish","has-post-thumbnail","hentry","doc_category-dlp-data-loss-prevention","doc_category-drive-management","doc_tag-gat"],"year_month":"2026-06","word_count":805,"total_views":"15","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"Ryan","author_nicename":"ryan","author_url":"https:\/\/gatlabs.com\/knowledge\/author\/ryan\/"},"doc_category_info":[{"term_name":"DLP (Data Loss Prevention)","term_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips-category\/dlp-data-loss-prevention\/"},{"term_name":"Drive Audit &amp; Management","term_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips-category\/drive-management\/"}],"doc_tag_info":[{"term_name":"GAT+","term_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips-tag\/gat\/"}],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.5 (Yoast SEO v27.5) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Investigate Google Workspace Account Compromise with GAT+ - GAT Knowledge Base<\/title>\n<meta name=\"description\" content=\"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Investigate Google Workspace Account Compromise with GAT+\" \/>\n<meta property=\"og:description\" content=\"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/\" \/>\n<meta property=\"og:site_name\" content=\"GAT Knowledge Base\" \/>\n<meta property=\"article:modified_time\" content=\"2026-06-08T12:12:30+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2022\/08\/GAT.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"600\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/\",\"name\":\"Investigate Google Workspace Account Compromise with GAT+ - GAT Knowledge Base\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/GAT.jpg\",\"datePublished\":\"2026-06-08T08:29:32+00:00\",\"dateModified\":\"2026-06-08T12:12:30+00:00\",\"description\":\"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/#primaryimage\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/GAT.jpg\",\"contentUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2022\\\/08\\\/GAT.jpg\",\"width\":1200,\"height\":600},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/investigate-google-workspace-account-compromise-with-gat\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Tech Tips\",\"item\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/tech-tips\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Investigate Google Workspace Account Compromise with GAT+\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#website\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\",\"name\":\"GAT Knowledge Base\",\"description\":\"Your source of all things GAT\",\"publisher\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#organization\",\"name\":\"GAT Labs Knowledge Base\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Group-1159.svg\",\"contentUrl\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/wp-content\\\/uploads\\\/2021\\\/11\\\/Group-1159.svg\",\"width\":361,\"height\":97,\"caption\":\"GAT Labs Knowledge Base\"},\"image\":{\"@id\":\"https:\\\/\\\/gatlabs.com\\\/knowledge\\\/#\\\/schema\\\/logo\\\/image\\\/\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Investigate Google Workspace Account Compromise with GAT+ - GAT Knowledge Base","description":"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/","og_locale":"en_GB","og_type":"article","og_title":"Investigate Google Workspace Account Compromise with GAT+","og_description":"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.","og_url":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/","og_site_name":"GAT Knowledge Base","article_modified_time":"2026-06-08T12:12:30+00:00","og_image":[{"width":1200,"height":600,"url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2022\/08\/GAT.jpg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_misc":{"Estimated reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/","url":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/","name":"Investigate Google Workspace Account Compromise with GAT+ - GAT Knowledge Base","isPartOf":{"@id":"https:\/\/gatlabs.com\/knowledge\/#website"},"primaryImageOfPage":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/#primaryimage"},"image":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/#primaryimage"},"thumbnailUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2022\/08\/GAT.jpg","datePublished":"2026-06-08T08:29:32+00:00","dateModified":"2026-06-08T12:12:30+00:00","description":"Trace malicious activity, perform blast-radius analysis, and take critical actions. Investigate an account compromise using GAT+.","breadcrumb":{"@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/#primaryimage","url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2022\/08\/GAT.jpg","contentUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2022\/08\/GAT.jpg","width":1200,"height":600},{"@type":"BreadcrumbList","@id":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/investigate-google-workspace-account-compromise-with-gat\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/gatlabs.com\/knowledge\/"},{"@type":"ListItem","position":2,"name":"Tech Tips","item":"https:\/\/gatlabs.com\/knowledge\/tech-tips\/"},{"@type":"ListItem","position":3,"name":"Investigate Google Workspace Account Compromise with GAT+"}]},{"@type":"WebSite","@id":"https:\/\/gatlabs.com\/knowledge\/#website","url":"https:\/\/gatlabs.com\/knowledge\/","name":"GAT Knowledge Base","description":"Your source of all things GAT","publisher":{"@id":"https:\/\/gatlabs.com\/knowledge\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/gatlabs.com\/knowledge\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/gatlabs.com\/knowledge\/#organization","name":"GAT Labs Knowledge Base","url":"https:\/\/gatlabs.com\/knowledge\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/gatlabs.com\/knowledge\/#\/schema\/logo\/image\/","url":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2021\/11\/Group-1159.svg","contentUrl":"https:\/\/gatlabs.com\/knowledge\/wp-content\/uploads\/2021\/11\/Group-1159.svg","width":361,"height":97,"caption":"GAT Labs Knowledge Base"},"image":{"@id":"https:\/\/gatlabs.com\/knowledge\/#\/schema\/logo\/image\/"}}]}},"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/17171","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/comments?post=17171"}],"version-history":[{"count":11,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/17171\/revisions"}],"predecessor-version":[{"id":17269,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/docs\/17171\/revisions\/17269"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/media\/4504"}],"wp:attachment":[{"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/media?parent=17171"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/doc_category?post=17171"},{"taxonomy":"glossaries","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/glossaries?post=17171"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/gatlabs.com\/knowledge\/wp-json\/wp\/v2\/doc_tag?post=17171"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}