Hey
@Lids Although I can't answer you specific question on the recovery of deleted emails, I have used the "Takeout" feature a couple times on account takeovers during warrants. So here are a couple things to keep in mind.
As with anything in DFIR, you want to test this feature prior to needing it and have detailed instructions with you at the scene. When using Takeout, you have several options on where to download the data, including:
- Send download via link (emailed to the account holders email account)
- GDrive (for the logged in account)
- Dropbox
- OneDrive
Since Google gives generous amounts of space, especially business accounts, you will have to be sure you have enough storage to use DropBox or OneDrive. This is why GDrive is often you best option. You can store everything on the accounts Gdrive and then download when completed.
For large accounts, remember that it can take a long time to process if you select ALL the items that Takeout offers like Email, Documents, Calendar, Locations, etc. This can easily take hours for large accounts.
@JLowery : What are your concerns with using Takeout as the main collection tool?
What do the other software products you mentioned offer to make their purchase worth the investment?