Pivot In Every Prompt Injection Detection For Investigation
Query
// Prompt-injection detections over the last 30 days, including details
let lookback = 30d;
EmailEvents
| where Timestamp > ago(lookback)
| where DetectionMethods has "Prompt injection"
| project Timestamp, NetworkMessageId, SenderFromAddress, RecipientEmailAddress,
Subject, DeliveryAction, DeliveryLocation, DetectionMethods
| sort by Timestamp descAbout this query
Pivot in every prompt-injection detection for investigation
Description
This query helps investigate further, once you've run [https://github.com/cyb3rmik3/KQL-threat-hunting-queries/blob/main/Defender%20for%20Office365/uncover-every-prompt-injection-detection-and-its-disposition.md](Uncover every prompt-injection detection and its disposition).
Microsoft Defender XDR
Versioning
| Version | Date | Comments |
|---|---|---|
| 1.0 | 08/10/2026 | Initial publish |
Explanation
This query is designed to help investigate prompt-injection detections in email communications over the past 30 days. It is intended to be used after running a specific query that uncovers every prompt-injection detection and its disposition. Here's a simple breakdown of what the query does:
- Time Frame: It looks at email events from the last 30 days.
- Filter: It specifically filters for email events where the detection method includes "Prompt injection".
- Data Selection: It selects and displays specific details from these events, including:
- The timestamp of the event.
- The network message ID.
- The sender's email address.
- The recipient's email address.
- The subject of the email.
- The delivery action taken.
- The delivery location.
- The detection methods used.
- Sorting: The results are sorted by the timestamp in descending order, meaning the most recent events appear first.
This query is part of a broader investigation process using Microsoft Defender XDR to analyze and respond to potential security threats related to prompt injections in emails.