Back to results

GCP Vertex AI Safety Filters Set to BLOCK_NONE

Detects Vertex AI GenerateContent requests that set safety_settings.threshold to BLOCK_NONE. That threshold disables category blocking for the listed harm categories when clients explicitly send safetySettings.…

Description

Detects Vertex AI GenerateContent requests that set safety_settings.threshold to BLOCK_NONE. That threshold disables category blocking for the listed harm categories when clients explicitly send safetySettings. Attackers and careless apps use BLOCK_NONE to weaken built-in Gemini filters.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteWindows

The rule states no platform. This is derived from the ATT&CK technique it maps to.

Known benign triggers

  • Approved research projects that document BLOCK_NONE for evaluation. Prefer labeled service accounts and exclude those principals.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice