Microsoft Foundry Prompt or Completion Containing Credentials
Detects a Microsoft Foundry chat, sent through API Management, whose prompt or assistant reply contains a known credential pattern or an email address together with a password assignment. The model often refuses the…
Description
Detects a Microsoft Foundry chat, sent through API Management, whose prompt or assistant reply contains a known credential pattern or an email address together with a password assignment. The model often refuses the request and Azure content filters stay clear, so the secret is only visible in the logged message text.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the ATT&CK technique it maps to.
Known benign triggers
- A prompt that contains both an email address and a sentence such as "the password is required" matches the password assignment pattern. Read the message and drop test subscriptions that intentionally send fake secrets.
- Documentation and unit tests that paste example keys, such as an AWS access key ending in EXAMPLE, match the token patterns. Confirm the value is live before rotating it.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| genai.owasp.org/llmrisk/llm06-sensitive-information-disclosure | Only this detection cites it |
| learn.microsoft.com/en-us/azure/api-management/diagnostic-logs-reference | 3 |
| www.elastic.co/docs/reference/integrations/azure_ai_foundry | 5 |
From the source
- At source
- Open at source
- Upstream identifier
- cbaa94d2-1b4d-4198-9882-fafc9e813a5a
- Tagged by the source as
- Mitre Atlas: AML.T0055Mitre Atlas: AML.T0057Data Source: Microsoft FoundryDomain: CloudDomain: GenAIPlatform: AzureResources: Investigation GuideRule Type: ES|QLService: Azure API ManagementTactic: Credential AccessUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Oct 6, 2026
- Version
- 1