Skip to content

validate(SAFE-T1103): Sigma detection rule, MITRE correction, SAFE-M references - #198

Merged
arjunastha merged 1 commit into
secure-agentic-framework:mainfrom
bishnubista:validate/SAFE-T1103
Apr 29, 2026
Merged

arjunastha merged 1 commit into
secure-agentic-framework:mainfrom
bishnubista:validate/SAFE-T1103

Conversation

@bishnubista

Copy link
Copy Markdown
Member

Summary

Validation pass on SAFE-T1103 (Fake Tool Invocation / Function Spoofing) closing the missing-detection-rule gap, attaching SAFE-M cross-references on detective controls, and correcting an inaccurate MITRE ATT&CK mapping. This pass is intentionally minimal-scope — broader structural drift (the file's custom ## Technique Overview, missing ## Attack Vectors, custom impact classification, etc.) is left to a future restructure.

Changes

  • Author techniques/SAFE-T1103/detection-rule.yml (Sigma format, UUID c6b5f97b-89e6-4f36-b5a9-9959a5550727, author: SAFE-MCP Team) covering suspicious tool-name keywords (admin / sudo / escalate / bypass / system_ / shell / eval / session_escalate) and suspicious argument flags (bypass_acl / bypass_restrictions / elevated / unrestricted / sudo) for tools/call events. Mirror inline as a ### Detection Rules subsection in README.md between Network Monitoring and Behavioral Analysis. The rule is explicit about being a flat-pattern first pass; full coverage requires SIEM-side correlation matching tools/call against prior tools/list registrations from the same server_id.
  • Add [SAFE-M-11: Behavioral Monitoring](../../mitigations/SAFE-M-11/README.md) references at the end of Runtime Detection, Network Monitoring, and Behavioral Analysis subsections.
  • Add [SAFE-M-12: Audit Logging](../../mitigations/SAFE-M-12/README.md) reference at the end of Log Analysis Patterns subsection.
  • Replace MITRE ATT&CK mapping T1574 (Hijack Execution Flow) with T1565 (Data Manipulation) primary + T1190 (Exploit Public-Facing Application). T1574 covers DLL search-order hijacking and library injection, which is unrelated to JSON-RPC tool-invocation message forgery. Updated in both the Overview block and the References section.
  • Remove a Mermaid diagram added in v1.1 that depicted Indirect Prompt Injection flow ("Poisoned Third-Party Content → MCP Retrieval/Browse Tool → LLM Context → Behavior Deviation") rather than this file's stated scope (Fake Tool Invocation / JSON-RPC forgery). Replace with a <!-- TODO --> comment explaining the removal; do not author a replacement diagram (would constitute redesign).
  • Add <!-- TODO --> comment at top of file flagging that SAFE-T1102 cross-references this technique as "Indirect Prompt Injection - Specific subset focusing on third-party data" while this file's own title is "Fake Tool Invocation (Function Spoofing)". The two scopes are distinct techniques; resolution is deferred to original authors.
  • Add Version 1.2 entry.

Open items

  • Identity / cross-reference question (<!-- TODO --> at top of README.md): SAFE-T1102/README.md line 160 references SAFE-T1103 as "Indirect Prompt Injection", while this file's title and content describe "Fake Tool Invocation". Original authors (Bo Redfearn, Shekhar Chaudhary) should reconcile — either update T1102's cross-reference to match this file's actual scope, or restructure T1103 to cover Indirect Prompt Injection and assign Fake Tool Invocation to a new technique ID.
  • Replacement workflow diagram (<!-- TODO --> at the former Mermaid location): once the identity question resolves, an accurate workflow diagram for the chosen scope should be authored.
  • No SAFE-M references on Preventive Controls: none of the existing 45 mitigations cleanly cover tool-registry validation, JSON-RPC message authentication, or MCP transport-layer security. Authoring those mitigations is corpus-level follow-up.
  • Wholesale structural alignment with TEMPLATE.md (custom ## Technique Overview, missing ## Attack Vectors, custom Immediate/Extended/Business impact classification instead of CIA + Scope, ~110-line ## Testing section, ## Compliance Mapping table unique in the corpus, trailing duplicate metadata block) is intentionally out of scope for this PR and warrants a separate restructure pass.
  • CVE / real-world incident citations: this technique is currently cited only against framework specs (MITRE, JSON-RPC, MCP, OWASP, CWE). Real-world incidents or CVEs would strengthen the evidence base; none are added in this pass.

…, attach SAFE-M references

- author detection-rule.yml + inline Sigma rule covering suspicious tool-name
  keywords and argument flags for tools/call events (UUID c6b5f97b-...)
- replace MITRE T1574 (Hijack Execution Flow, poor fit for JSON-RPC message
  forgery) with T1565 (Data Manipulation, primary) + T1190 (Exploit
  Public-Facing Application)
- add SAFE-M-11 (Behavioral Monitoring) references on Runtime Detection,
  Network Monitoring, and Behavioral Analysis subsections; SAFE-M-12 (Audit
  Logging) on Log Analysis Patterns
- remove wrongly-imported Mermaid diagram that depicted Indirect Prompt
  Injection flow rather than Fake Tool Invocation; TODO comment explains
- TODO comment at top flags cross-reference identity question between this
  file's title and SAFE-T1102's reference to SAFE-T1103, for original-author
  resolution
- add Version 1.2 entry

Signed-off-by: bishnubista <[email protected]>
@arjunastha
arjunastha merged commit 46d739f into secure-agentic-framework:main Apr 29, 2026
1 check passed
@bishnubista
bishnubista deleted the validate/SAFE-T1103 branch May 1, 2026 21:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants