Query Details

Pivot In Every Prompt Injection Detection For Investigation

Query

// Prompt-injection detections over the last 30 days, including details
let lookback = 30d;
EmailEvents
| where Timestamp > ago(lookback)
| where DetectionMethods has "Prompt injection"
| project Timestamp, NetworkMessageId, SenderFromAddress, RecipientEmailAddress,
          Subject, DeliveryAction, DeliveryLocation, DetectionMethods
| sort by Timestamp desc

About this query

Pivot in every prompt-injection detection for investigation

Description

This query helps investigate further, once you've run [https://github.com/cyb3rmik3/KQL-threat-hunting-queries/blob/main/Defender%20for%20Office365/uncover-every-prompt-injection-detection-and-its-disposition.md](Uncover every prompt-injection detection and its disposition).

Microsoft Defender XDR

Versioning

VersionDateComments
1.008/10/2026Initial publish

Explanation

This query is designed to help investigate prompt-injection detections in email communications over the past 30 days. It is intended to be used after running a specific query that uncovers every prompt-injection detection and its disposition. Here's a simple breakdown of what the query does:

  1. Time Frame: It looks at email events from the last 30 days.
  2. Filter: It specifically filters for email events where the detection method includes "Prompt injection".
  3. Data Selection: It selects and displays specific details from these events, including:
    • The timestamp of the event.
    • The network message ID.
    • The sender's email address.
    • The recipient's email address.
    • The subject of the email.
    • The delivery action taken.
    • The delivery location.
    • The detection methods used.
  4. Sorting: The results are sorted by the timestamp in descending order, meaning the most recent events appear first.

This query is part of a broader investigation process using Microsoft Defender XDR to analyze and respond to potential security threats related to prompt injections in emails.