AI Series: Most Significant TTP – Prompt-Injection Attempt Against Enterprise AI
This rule detects potential prompt injection attacks against internal AI-powered assistants, agents, or LLM gateways. It monitors network HTTP requests for common patterns used to override system instructions, bypass safety filters, or force the model to adopt a privileged, unauthorized persona (e.g., administrator or debug mode). These techniques are often used in social engineering to manipulate the AI's output or security posture.
YARA-L

