AML.T0129 + AML.T0051.001 Multimodal Prompt Injection → Tool Execution
Detects potential multimodal prompt injection attacks where an AI agent process ingests a file (PDF, image, etc.) from a browser or mail client and subsequently performs suspicious downstream activity, such as spawning a shell with execution primitives or making network connections to rare, non-reputable external domains. Covers T1204, T1059, T1105
Microsoft Sentinel (KQL)

