MITRE ATLAS Mapped 2026 Top AI Prompt Injection Detection – Direct LLM Prompt Injection (AML.T0051)

Detects direct prompt-injection attempts submitted to an LLM or AI gateway. The rule monitors HTTP POST requests for common adversarial techniques such as attempting to override system instructions, reassign model roles, bypass safety guidelines, or initiate jailbreak modes (e.g., DAN). It includes stateful tracking to flag users who perform multiple such attempts within a 10-minute window, increasing the risk score for persistent malicious behavior.