Query Details

Uncover Every Prompt Injection Detection And Its Disposition

Query

// Prompt-injection detections over the last 30 days, by disposition
let lookback = 30d;
EmailEvents
| where Timestamp > ago(lookback)
| where DetectionMethods has "Prompt injection"
| summarize Messages = count() by DeliveryAction, DeliveryLocation, bin(Timestamp, 1d)
| sort by Timestamp desc

About this query

Uncover every prompt-injection detection and its disposition

Description

This query helps answer with regards to prompt-injection emails, how much is MDO catching, and is any of it still reaching mailboxes rather than quarantine?

Microsoft Defender XDR

Versioning

VersionDateComments
1.008/10/2026Initial publish

Explanation

This query is designed to analyze email events related to prompt-injection detections over the past 30 days. It aims to determine how many such emails are being detected by Microsoft Defender for Office (MDO) and whether any of these emails are still being delivered to mailboxes instead of being quarantined. Here's a breakdown of what the query does:

  1. Time Frame: It looks at email events from the last 30 days.
  2. Filter: It specifically filters for emails that have been detected using the "Prompt injection" detection method.
  3. Summarization: It counts the number of detected emails and groups them by:
    • DeliveryAction: What action was taken on the email (e.g., delivered, quarantined).
    • DeliveryLocation: Where the email ended up (e.g., mailbox, quarantine).
    • Timestamp: The date the detection occurred, grouped by day.
  4. Sorting: The results are sorted by the most recent detections first.

This query helps to understand the effectiveness of the detection system in identifying and handling prompt-injection emails, providing insights into whether any of these potentially harmful emails are bypassing security measures and reaching user mailboxes.