Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
3
3
Platforms
3
Products / Services
3
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.
This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.
This rule detects anomalous behavior in AI agent tool invocations, specifically monitoring for high volumes of tool calls, high costs associated with token consumption, or suspicious tool interactions following a flagged indirect prompt injection. This behavior is indicative of potential resource exhaustion (denial of service) or abusive agent behavior as defined by the MITRE ATLAS framework for AI security.
