heroui logo

GCP Vertex AI Caller Impossible Travel

Elastic Detection Rules

View Source
Summary
This ES|QL rule detects suspicious Vertex AI activity where the same authenticated caller (client.user.email) generates aiplatform audit events from geographically distant source IPs within a short time window, indicating impossible travel. It targets content-generation related Vertex AI actions (PredictionService.GenerateContent, PredictionService.StreamGenerateContent, CountTokens) and relies on audit logs that expose client.user.email, source.ip, and geolocation. The detector aggregates events by user, computes first/last geolocations, and calculates distance and inferred travel speed to flag rapid, multi-regional access. A trigger occurs when the observed distance between first and last sources is at least 500 km and the inferred speed is at least 800 km/h within the lookback window. The rule maps to credential-access and initial-access techniques and correlates to token-based abuse of valid cloud accounts, including valid-accounts and application-access-token scenarios. It also leverages MITRE ATLAS mappings to AML.T0012 (Valid Accounts) and AML.T0091.000 (Application Access Token), along with T1528 (Steal Application Access Token) and T1078 (Valid Accounts) to frame the threat. The rule includes mitigation guidance, triage steps, and cross-reference with related Vertex AI activity across multiple countries, plus a setup prerequisite to enable Vertex AI audit logs with IP and geolocation data. False positives cover shared service accounts across regions and VPN/geolocation anomalies; recommended actions include credential rotation, per-region identities, and IAM binding reviews.
Categories
  • Cloud
  • GCP
Data Sources
  • Cloud Service
ATT&CK Techniques
  • T0012
  • T0091
  • T0091.000
  • T1528
  • T1078
  • T1078.004
Created: 2026-10-02