heroui logo

Microsoft Foundry High Request and Token Volume

Elastic Detection Rules

View Source
Summary
This rule detects anomalous activity in Microsoft Foundry by identifying a single caller IP that issues a high number of requests and consumes a large amount of tokens against the same Foundry deployment/operation within a 9-minute lookback. It uses Foundry RequestResponse logs (prompt tokens, completion tokens, and counts) and does not require prompt text. The detection thresholds require at least 100 events and a total token sum of at least 10,000, balancing sensitivity and noise. The rule is tunable by adjusting the request count and token sum. When triggered, it surfaces the caller IP, deployment, operation, and resource context to aid rapid triage. The setup requires enabling the Microsoft Foundry integration to forward RequestResponse diagnostics; prompt/responses themselves are not required. False positives can arise from approved batch jobs or multi-tenant prefixes masked by Foundry. The rule includes investigation steps, handling of false positives, and remediation guidance, along with relevant references and risk context.
Categories
  • Cloud
  • Application
Data Sources
  • Application Log
ATT&CK Techniques
  • T0029
  • T1496
Created: 2026-10-01