Skip to content

Introduce malicious LLM Prompts to STIX Standard as Observable Object to be used as Indicator pattern for IOCs#170

Open
avwsolutions wants to merge 3 commits intooasis-open:masterfrom
avwsolutions:master
Open

Introduce malicious LLM Prompts to STIX Standard as Observable Object to be used as Indicator pattern for IOCs#170
avwsolutions wants to merge 3 commits intooasis-open:masterfrom
avwsolutions:master

Conversation

@avwsolutions
Copy link
Copy Markdown

Using this PR I like to propose the discussion introducing LLM Prompts as pattern type for Indicators. Many domain experts see the growth of evil prompts. From solely LLM, MCP towards AI Agents. Within the world of LLM Observability we already match undesired prompts and many Security analysts are debating for this type of IOC, like https://novahunting.ai/.

Let's support the community detecting adversarial prompts using matching IOCs !

Would be great to have such object introduced in the STIX standard.

Defines the LLM Prompt Object schema for natural language instructions.
@CLAassistant
Copy link
Copy Markdown

CLAassistant commented Nov 5, 2025

CLA assistant check
All committers have signed the CLA.

@adulau
Copy link
Copy Markdown
Contributor

adulau commented Nov 5, 2025

Thanks a lot for the contribution. We will review it at the next TC.

@adulau adulau self-assigned this Nov 5, 2025
@fr0gger
Copy link
Copy Markdown

fr0gger commented Nov 5, 2025

I recommend checking https://promptintel.novahunting.ai/ too for a full Adversarial Prompts Taxonomy and feed. :)

@avwsolutions
Copy link
Copy Markdown
Author

It's a while ago, but we see traction in adoption by the cybersecurity community.

https://www.dogesec.com/blog/modelling_nova_rules_structured_cti/

Already discussed during the TC?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants