
First Time GCP Vertex AI Agent Engine Sandbox Code Execution by User and Source ASN
Elastic Detection Rules
View SourceSummary
Detects the first-time occurrence of a combination of a user email (client.user.email) and a source ASN (source.as.number) on a successful Vertex AI Agent Engine Sandbox code execution (ExecuteSandboxEnvironment) within Vertex AI audit logs. The rule watches for new pairs in the history window (now-14d) and in the active stream (now-60m) to flag potential new workloads, suspicious credential use from unusual networks, or early abuse of the Agent Engine before sandbox reuse is established. It is informational and intended to aid triage, not proof of hijacking. Investigation typically focuses on who is running sandboxed code and from where, and whether the ASN matches approved offices, VPNs, or cloud egress. It also encourages correlating with CreateSandboxEnvironment events and additional ExecuteSandboxEnvironment entries, and, when available, reviewing application traces since the logs do not include submitted Python code.
Categories
- Cloud
- GCP
Data Sources
- Application Log
- Cloud Service
ATT&CK Techniques
- T0053
- T0110
- T0110.002
- T1059
- T1059.006
Created: 2026-10-02