Uncover Every Prompt Injection Detection And Its Disposition
Query
// Prompt-injection detections over the last 30 days, by disposition
let lookback = 30d;
EmailEvents
| where Timestamp > ago(lookback)
| where DetectionMethods has "Prompt injection"
| summarize Messages = count() by DeliveryAction, DeliveryLocation, bin(Timestamp, 1d)
| sort by Timestamp descAbout this query
Uncover every prompt-injection detection and its disposition
Description
This query helps answer with regards to prompt-injection emails, how much is MDO catching, and is any of it still reaching mailboxes rather than quarantine?
Microsoft Defender XDR
Versioning
| Version | Date | Comments |
|---|---|---|
| 1.0 | 08/10/2026 | Initial publish |
Explanation
This query is designed to analyze email events related to prompt-injection detections over the past 30 days. It aims to determine how many such emails are being detected by Microsoft Defender for Office (MDO) and whether any of these emails are still being delivered to mailboxes instead of being quarantined. Here's a breakdown of what the query does:
- Time Frame: It looks at email events from the last 30 days.
- Filter: It specifically filters for emails that have been detected using the "Prompt injection" detection method.
- Summarization: It counts the number of detected emails and groups them by:
- DeliveryAction: What action was taken on the email (e.g., delivered, quarantined).
- DeliveryLocation: Where the email ended up (e.g., mailbox, quarantine).
- Timestamp: The date the detection occurred, grouped by day.
- Sorting: The results are sorted by the most recent detections first.
This query helps to understand the effectiveness of the detection system in identifying and handling prompt-injection emails, providing insights into whether any of these potentially harmful emails are bypassing security measures and reaching user mailboxes.