Files
rb/sec-google-evidence.md
T
igodwin b2d2a42a9a Add sec-google-evidence runbook: account state capture + re-entry check
Numbered field checklist for a consumer Google account, usable in two
situations: capturing state before touching anything, and verifying
nobody regained access after a password reset.

Deliberately terse -- steps only, no rationale prose. This is worked
standing up in someone's office, where explanatory text between steps
makes the next action harder to find.

Covers ground sec-google-compromise.md Phase 0 does not: the Takeout
export history, which is the bulk-exfiltration path for a Google account
and produces affirmative evidence in an account tier with no audit log;
recovering Google's own security mail from Trash and Spam via
in:anywhere; pending-but-unconfirmed forwarding addresses; the native
filter XML export instead of a screenshot; and attacker-enrolled
passkeys.

Also records that Gmail keeps only ~10 recent-activity entries, so
signing out and back in destroys evidence -- capture in one sitting.

Placeholders only.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 15:17:28 -07:00

3.9 KiB

Runbook: Google account — evidence capture + re-entry check

Applies to: A consumer Google/Gmail account, before or after containment. No Workspace admin console required. Use it for: (a) capturing account state before you change anything, and (b) checking whether anyone got back in after a password reset. Companion: sec-google-compromise.md — full containment procedure.

Placeholders:

Placeholder Meaning
<ACCOUNT> The Google account under review
<RESET_TIME> Date/time of the password reset — the re-entry baseline
<COMPROMISE_START> Earliest known date of compromise
<EVIDENCE_DIR> Folder for screenshots, e.g. Desktop\Account Records

Rules:

  • Sign in once. Gmail keeps ~10 recent-activity entries; re-authenticating pushes older ones off.
  • Screenshot everything, including empty results.
  • Change nothing until Part C.
  • Anything dated after <RESET_TIME> that isn't you = they got back in.

Part A — do first

1. gmail.com → bottom of inbox → "Last account activity" → Details → screenshot 01-signin-list (scroll, second shot if needed) → Look for: access after <RESET_TIME>.

2. myaccount.google.com → Security → Recent security activity → See all → screenshot 02-security-activity → Look for: anything after <RESET_TIME>.

3. Security → Your devices → Manage all devices → screenshot 03-devices → Look for: any session you didn't sign in.


Part B — export check

4. takeout.google.com → Your exports / Manage exports → screenshot 04-takeout — screenshot it even if empty. → Takeout copies the whole mailbox in one archive. It is the bulk-exfiltration path.

5. Gmail search: in:anywhere from:google.com → screenshot results 05-google-alerts → open + screenshot each: Security alert · New sign-in · password changed · "Your data is ready to download" → in:anywhere includes Trash and Spam, where these are usually deleted to.

6. Gmail search: in:anywhere after:<RESET_TIME date> → screenshot 06-since-reset

Don't delete anything. Don't empty Trash.


Part C — persistence

7. myaccount.google.com/permissions → screenshot list 07-oauth → open each grant → screenshot name + scopes + date authorized 07b… → then remove every grant you cannot positively attribute. → Authorized on/after <COMPROMISE_START> = attacker-created. → OAuth grants survive password resets and session revocation.

8. Gmail → gear → See all settings:

  • Forwarding and POP/IMAP → screenshot 08-forwarding — note any pending/unconfirmed address
  • Filters and Blocked Addresses → screenshot 09-filters → select all → Export → save the XML
  • Accounts and Import → screenshot 10-accounts — Send mail as · Grant access to your account

9. myaccount.google.com/signinoptions/passkeys → screenshot 11-passkeys → Any passkey you didn't enroll → remove.

10. Security → 2-Step Verification → screenshot 12-2sv → Recovery phone + recovery email → screenshot 13-recovery

11. myaccount.google.com/apppasswords → screenshot 14-apppasswords → revoke all. App passwords bypass 2-Step Verification.


Before you leave

  • Nothing deleted, Trash not emptied
  • <EVIDENCE_DIR> left on the machine
  • Time finished written down
  • Screenshots not emailed

Results

Step Finding Screenshot
1
2
3
4
5
6
7 name / scopes / authorized date:
8
9
10
11

Menu wording drifts; the myaccount.google.com/... links are the durable part. If a path doesn't match, navigate from myaccount.google.com → Security and record the path you used.