Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

3 detections

Detects direct prompt-injection attempts submitted to an LLM or AI gateway. The rule monitors HTTP POST requests for common adversarial techniques such as attempting to override system instructions, reassign model roles, bypass safety guidelines, or initiate jailbreak modes (e.g., DAN). It includes stateful tracking to flag users who perform multiple such attempts within a 10-minute window, increasing the risk score for persistent malicious behavior.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
6 days ago
002
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
11 days ago
002