First Time GCP Vertex AI Agent Engine Sandbox Code Execution by User and Source ASN
Description
Detects the first time a Vertex AI Agent Engine caller executes code in a sandboxEnvironment from a given source autonomous system. First-time sandbox execution by a user and source ASN can indicate a new workload, stolen credentials used from an unusual network, or early Agent Engine abuse before broader sandbox reuse is visible.
Query · kuery
data_stream.dataset:gcp_vertexai.auditlogs and event.action:*SandboxEnvironmentExecutionService.ExecuteSandboxEnvironment* and gcp.vertexai.audit.resource_name:*/sandboxEnvironments/* and gcp.vertexai.audit.service_name:aiplatform.googleapis.com and client.user.email:* and source.as.number:* and gcp.vertexai.audit.status.code:(0 or not *)
Investigation fields
Pivot points the source recommends for triage.
client.user.emailsource.as.numbersource.as.organization.namesource.ipgcp.vertexai.audit.resource_nameuser_agent.originalevent.action
Implementation guide
Requires GCP Vertex AI auditlogs for aiplatform.googleapis.com, including
SandboxEnvironmentExecutionService.ExecuteSandboxEnvironment, with client.user.email and source.as.number
populated. Submitted code is not present in these events; obtain application code records or traces separately when
available.
Known false positives
- Developers, notebooks, and CI service accounts execute sandbox code from new offices, home ISPs, or cloud egress ASNs until baselined. Exclude known build and research identities after review.
Analyst notes
Investigating First Time GCP Vertex AI Agent Engine Sandbox Code Execution by User and Source ASN
This new-terms rule alerts when client.user.email combined with source.as.number first appears on a successful
Agent Engine ExecuteSandboxEnvironment call in the history window. It is an informational starting point for
reviewing who is running code in sandboxes and from where, not proof of hijacking.
Possible investigation steps
- Review
client.user.email,source.ip,source.as.number,source.as.organization.name, andgcp.vertexai.audit.resource_name(sandbox path). - Confirm whether the principal is expected to use Agent Engine and whether the ASN matches approved office, VPN, or cloud egress.
- Hunt nearby CreateSandboxEnvironment and additional ExecuteSandboxEnvironment events for the same sandbox or principal. Inspect application traces or captured code when available; audit logs omit submitted Python.
False positive analysis
- First-time legitimate developers, CI service accounts, and research projects commonly match until identities and ASNs are baselined.
- Shared automation identities that rotate egress networks can create recurring first-seen pairs; prefer principal-scoped exceptions after ownership review.
Response and remediation
- If the principal or ASN is unexpected: restrict or rotate credentials, review IAM grants, and inspect recent sandbox activity for unauthorized code execution.
- Prefer separate sandboxes across users or tenants and treat tool output as untrusted input to the agent.