MITRE ATLAS Mapped 2026 Top AI Chatbot Abuse Detection – Prompt Infiltration via Public-Facing Application (AML.T0093)

Detects systematic and high-frequency probing of internet-exposed LLM chatbot or API gateway endpoints. The rule monitors for sequences of requests, use of known prompt-infiltration or jailbreak testing toolkits, and varied path access indicative of automated reconnaissance or adversarial prompt engineering attempts.