Add rule for LLM agent indirect prompt injection detection - #6108
Add rule for LLM agent indirect prompt injection detection#6108Batina-Jennifer wants to merge 1 commit into
Conversation
This Sigma rule detects potential indirect prompt injection manipulation and data exfiltration attempts by monitoring specific command line patterns and parent images in a Linux environment.
There was a problem hiding this comment.
Welcome @Batina-Jennifer 👋
It looks like this is your first pull request on the Sigma rules repository!
Please make sure to read the SigmaHQ conventions to make sure your contribution is adhering to best practices and has all the necessary elements in place for a successful approval.
Thanks again, and welcome to the Sigma community! 😃
If you want to engage more with the community for official support, general discussions or announcements:
|
Closing this as it looks like AI slop. It also does not adher to the spec nor the conventions defined in the spec repo. Also please provide an actual log sample of what you are detecting if you plan to re-open this PR, So that we can easily asses the validity and logic/intent. Thanks. |
This Sigma rule detects potential indirect prompt injection manipulation and data exfiltration attempts by monitoring specific command line patterns and parent images in a Linux environment.
Summary of the Pull Request
Changelog
Example Log Event
Fixed Issues
SigmaHQ Rule Creation Conventions