
Summary
Detects when a single source IP issues a high volume of Vertex AI GenerateContent or StreamGenerateContent audit calls against the same model resource within a 60-minute lookback window. The detector aggregates by source IP, model resource (gcp.vertexai.audit.resource_name), and project, triggering when Esql.event_count reaches 100 in the current 10-minute interval. This pattern is consistent with model extraction, automated scraping, or a compromised caller burning prediction quotas. The rule relies on Vertex AI audit logs (aiplatform.googleapis.com) and surfaces the IP, resource, project, event_count, first_seen/last_seen, and the mix of actions (GenerateContent vs StreamGenerateContent). It maps to MITRE ATT&CK (Collection) and MITRE ATLAS (Denial of AI Service and Exfiltration via AI Inference API with Extract AI Model). Severity is medium with a risk score of 47.
Categories
- Cloud
Data Sources
- Cloud Service
ATT&CK Techniques
- T0024
- T0024.002
- T0029
- T1530
Created: 2026-10-02