EchoLeak - M365 Copilot Zero-Click LLM Prompt Injection
Detects potential zero-click LLM prompt injection attacks against Microsoft 365 Copilot. The rule correlates Microsoft 365 Copilot activity involving external/untrusted URLs or domains with recent inbound email activity to the same user. This pattern is designed to identify scenarios where an attacker leverages an inbound email to trigger a Copilot interaction with malicious external content, potentially leading to unauthorized data access or exfiltration.
Microsoft Sentinel (KQL)

