Top 2026 LLM-Based Attack Detection: In-Session Thread Injection Hijacking Agent
Detects malicious prompt injection attempts within an LLM conversation session. The rule monitors for ingested content containing common instruction-override keywords (e.g., 'ignore previous instructions', 'system prompt override'), followed immediately by the agent process executing unauthorized actions such as process launch, network connections, or file creation within the same session/user context.
YARA-L

