Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
1 detection
Filters
Last updated
All Time
Detection languages
1
Contributors
1
Categories
1
1
1
Platforms
1
1
1
Products / Services
1
1
1
MITRE Techniques
1
1
1
1
1
CVEs
68
68
60
58
50
Detects potential zero-click LLM prompt injection attacks against Microsoft 365 Copilot. The rule correlates Microsoft 365 Copilot activity involving external/untrusted URLs or domains with recent inbound email activity to the same user. This pattern is designed to identify scenarios where an attacker leverages an inbound email to trigger a Copilot interaction with malicious external content, potentially leading to unauthorized data access or exfiltration.
