
Summary
Detects modifications to Vertex AI publisher model configuration via SetPublisherModelConfig, focusing on changes to logging destinations (e.g., BigQuery) or sampling settings. Unauthorized changes can disable or redirect security-relevant logging and potentially expose or block sensitive prompt data. The rule watches Vertex AI audit logs (logs-gcp_vertexai.auditlogs-*) for SetPublisherModelConfig actions with non-error status and surfaces key fields to aid investigation, including @timestamp, event.action, source.ip, client.user.email, gcp.vertexai.audit.resource_name, and user_agent.original. It ties to MITRE ATT&CK as Defense Evasion (T1562.008 Disable or Modify Cloud Logs) and to MITRE Atlas as AML.T0015 (Evade AI Model). The setup requires a Cloud Audit Logs sink for aiplatform.googleapis.com. False positives include approved platform engineering changes; investigators should verify tickets and actor legitimacy. Remediation involves reverting unauthorized config to the known-good logging destination and sampling, and tightening IAM permissions on SetPublisherModelConfig, with credential rotation if compromise is suspected. This rule enables rapid detection of configuration drift that could undermine monitoring and data integrity in Vertex AI publisher workflows.
Categories
- Cloud
- GCP
Data Sources
- Cloud Service
ATT&CK Techniques
- T0015
- T1562
- T1562.008
Created: 2026-10-02