Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
2
1
Contributors
3
Categories
3
2
1
Platforms
3
Products / Services
3
MITRE Techniques
18,034
15,417
12,647
8,188
6,021
Detects direct prompt-injection attempts submitted to an LLM or AI gateway. The rule monitors HTTP POST requests for common adversarial techniques such as attempting to override system instructions, reassign model roles, bypass safety guidelines, or initiate jailbreak modes (e.g., DAN). It includes stateful tracking to flag users who perform multiple such attempts within a 10-minute window, increasing the risk score for persistent malicious behavior.
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
Detects LLM input containing known instruction-override patterns (e.g., 'ignore previous instructions', 'DAN' jailbreak) paired with requests for privileged system operations, indicating a malicious attempt to bypass guardrails and gain unauthorized control over the LLM model.
