heroui logo

GCP Vertex AI Prompt or Response Containing Credentials

Elastic Detection Rules

View Source
Summary
Detects credential leakage in GCP Vertex AI prompt/response exchanges by scanning both user prompts and model replies for known credential patterns (e.g., AWS access keys, GitHub tokens, PEM private keys) or for assistant responses that warn about exposed keys and revocation. The rule relies on BigQuery-exported Vertex AI prompt_response_logs (gcp.vertexai.prompt_response_logs) and uses a comprehensive set of regex patterns to identify live secrets in request and response text, including patterns like AKIA/ASIA keys, GitHub personal access tokens, PEM blocks, various token prefixes (xoxb, xoxp, github_pat_, glpat_, sk_live_,AIza...), and related phrases indicating security concerns. It collects context fields such as model, API method, timestamps, and the full prompt/response text to aid triage. If a credential is detected in either the prompt or the model’s completion, the alert is raised for investigation. The rule explicitly notes that secrets in these logs are visible to anyone with BigQuery export access and Elastic. It maps to MITRE ATT&CK Unsecured Credentials (T1552) under Credential Access and to MITRE ATLAS techniques AML.T0055 (Unsecured Credentials) and AML.T0057 (LLM Data Leakage) under Exfiltration. The detection setup requires the GCP Vertex AI integration to collect prompt_response_logs. The rule includes investigation steps (verifying live secrets vs placeholders, correlating with GenerateContent events, and assessing egress), false-positive guidance (example keys in documentation), and remediation guidance (rotate/revoke live secrets, fix input/output filtering and sensitive-data policies to prevent logging secrets). Severity is high with a risk score of 73.
Categories
  • Cloud
  • GCP
Data Sources
  • Cloud Service
ATT&CK Techniques
  • T0055
  • T0057
  • T1552
Created: 2026-10-02