GCP Vertex AI Safety Filters Set to BLOCK_NONE
Detects Vertex AI GenerateContent requests that set safety_settings.threshold to BLOCK_NONE. That threshold disables category blocking for the listed harm categories when clients explicitly send safetySettings.…
Description
Detects Vertex AI GenerateContent requests that set safety_settings.threshold to BLOCK_NONE. That threshold disables category blocking for the listed harm categories when clients explicitly send safetySettings. Attackers and careless apps use BLOCK_NONE to weaken built-in Gemini filters.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
Known benign triggers
- Approved research projects that document BLOCK_NONE for evaluation. Prefer labeled service accounts and exclude those principals.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| cloud.google.com/vertex-ai/generative-ai/docs/multimodal/configure-safety-filters | Only this detection cites it |
| www.elastic.co/docs/reference/integrations/gcp_vertexai | 9 |
From the source
- At source
- Open at source
- Upstream identifier
- 08244b2a-6017-48f2-bfc5-ec4d2d0fe7c5
- Tagged by the source as
- Mitre Atlas: AML.T0015Data Source: GCPData Source: GCP Vertex AIData Source: Google Cloud PlatformDomain: CloudDomain: GenAIPlatform: GCPResources: Investigation GuideRule Type: ES|QLService: GCP Vertex AITactic: Defense EvasionThreat: Unauthorized AI UsageUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 8, 2026
- Version
- 1