Back to results

GCP Vertex AI Prompt or Response Containing Credentials

Detects a GCP Vertex AI GenerateContent exchange whose prompt or model reply contains a known credential pattern (AWS access keys, GitHub tokens, PEM private keys, and similar), or whose assistant reply warns about…

Description

Detects a GCP Vertex AI GenerateContent exchange whose prompt or model reply contains a known credential pattern (AWS access keys, GitHub tokens, PEM private keys, and similar), or whose assistant reply warns about exposed keys and revocation. Secrets in prompt/response logs are visible to anyone with access to BigQuery prompt-response export and Elastic.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Known benign triggers

  • Documentation and unit tests that paste example keys (for example an AWS access key ending in EXAMPLE) match the token patterns. Confirm the value is live before rotating it.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice