
Summary
This rule detects bursts of three or more completed assistant refusals from the same client (identified by source IP), API Management subscription, and model within a 15-minute window, indicating potential prompt abuse or defense-evasion activity against a GenAI service. It targets responses where the model returns a refusal (finish_reason stop or content_filter) with phrases such as “I can’t (or cannot) [fulfill/answer]” and pairs these with the corresponding prompts. The detection aggregates on source IP, user agent, API Management subscription, API, operation, model, gateway, and the URL requested, and requires the prompt and assistant messages to be logged (backend request/response bodies) to enable matching. True positives typically involve scripted or automated clients attempting disallowed prompts at scale; false positives can occur during legitimate evaluations or when many users share one NAT behind a single subscription. Alert grouping and suppression are configured to minimize noise within a 15-minute window, and samples of prompts and replies are included for triage. The rule is aligned with MITRE ATLAS techniques AML.T0051 (LLM Prompt Injection) and AML.T0054 (LLM Jailbreak), mapped to ATT&CK/TA0005 (Defense Evasion) as applicable. The rule requires the Microsoft Foundry integration to ingest GatewayLogs and backend bodies, and activation of diagnostics to capture the prompt and assistant response; recommended remediation includes rotating or disabling problematic API keys, blocking suspicious IPs, and reviewing prompts for sensitive information.
Categories
- Cloud
- Web
- Application
- Infrastructure
- Cloud
Data Sources
- Cloud Service
ATT&CK Techniques
- T0051
- T0054
- T1562
Created: 2026-10-01