heroui logo

GCP Vertex AI Caller Activity From High Number of Countries

Elastic Detection Rules

View Source
Summary
This rule detects potentially stolen or misused credentials for Google Cloud Vertex AI by analyzing authenticated calls from a single user (client.user.email) across multiple geographic locations. It monitors Vertex AI audit logs for specific Prediction service activities (PredictionService.GenerateContent, PredictionService.StreamGenerateContent, PredictionService.CountTokens) and aggregates activity by user email. The detection triggers when the same user email is observed from at least three distinct countries and at least three distinct source IP addresses within a four-hour window. The query collects the number of unique countries (Esql.country_count), unique IPs (Esql.source_ip_count), unique user agents (Esql.user_agent_count), and total events (Esql.event_count), along with the values of event actions, source IPs, geographic fields, ASN organization, and user agent strings, reporting first/last seen timestamps. This pattern can indicate credential reuse across VPNs or multi-region automation using stolen credentials, including scenarios where the first and last locations are geographically close due to return trips. The rule maps to MITRE ATT&CK techniques T1528 (Steal Application Access Token) and T1078 (Valid Accounts, Cloud Accounts) and MITRE ATLAS AML.T0012 (Valid Accounts) and AML.T0091.000 (Application Access Token) with related tactics such as Initial Access and Lateral Movement. Triage guidance encourages escalation when geographic diversity is coupled with differing user agents or privileged actions from distant IPs, or when IAM key activity occurs near the distant regions. False positives include legitimate multi-region automation using shared service accounts; such cases should be mitigated with region-scoped identities and allowlists. Remediation guidance recommends rotating credentials, revoking active sessions, reviewing IAM bindings, and confirming VPN or automation expectations with the owning team. The setup requires Vertex AI audit logs containing source.ip, source.geo.location, source.geo.country_name, client.user.email, and preferably user_agent.original.
Categories
  • Cloud
Data Sources
  • Cloud Service
ATT&CK Techniques
  • T0012
  • T0091
  • T0091.000
  • T1528
  • T1078
  • T1078.004
Created: 2026-10-05