Potential prompt injection attack in body HTML
Detects messages containing references to major AI tools (like Gemini, Copilot, ChatGPT, or Claude) in non-standard HTML elements.
Sublime rule (View on GitHub)
1name: "Potential prompt injection attack in body HTML"
2description: "Detects messages containing references to major AI tools (like Gemini, Copilot, ChatGPT, or Claude) in non-standard HTML elements."
3type: "rule"
4severity: "high"
5source: |
6 type.inbound
7 and length(filter(html.xpath(body.html, "//*[local-name() = 'admin']").nodes,
8 length(.display_text) > 0
9 and strings.ilike(.display_text,
10 '*gemini*',
11 '*copilot*',
12 '*chatgpt*',
13 '*claude*'
14 )
15 )
16 ) > 0
17
18 // negate highly trusted sender domains unless they fail DMARC authentication
19 and not (
20 sender.email.domain.root_domain in $high_trust_sender_root_domains
21 and coalesce(headers.auth_summary.dmarc.pass, false)
22 )
23attack_types:
24 - "Callback Phishing"
25 - "Credential Phishing"
26 - "Extortion"
27 - "Malware/Ransomware"
28 - "Spam"
29 - "BEC/Fraud"
30tactics_and_techniques:
31 - "Evasion"
32 - "Social engineering"
33detection_methods:
34 - "Header analysis"
35 - "HTML analysis"
36 - "Content analysis"
37id: "5fb24736-df8a-5a3a-84da-a2d5560d73d1"