
PowerShell-based detection and remediation toolkit for CVE-2025-32711 (EchoLeak), a critical zero-click AI command injection vulnerability in Microsoft 365 Copilot. Scans email patterns, audit logs, and security configurations to identify and mitigate prompt injection attacks.
CVE-2025-32711, nicknamed "EchoLeak," is a critical zero-click vulnerability in Microsoft 365 Copilot that allowed attackers to exfiltrate sensitive organizational data without any user interaction. This repository contains detection and remediation tools to help organizations assess their exposure and implement protective measures.
PowerShell-based detection and remediation tool demonstration
The vulnerability exploits how Microsoft 365 Copilot processes and retrieves data:
cve-2025-32711-detection/
├── README.md # This file
├── detect.ps1 # PowerShell detection script
├── remediate.ps1 # PowerShell remediation script
├── tests/
│ ├── test_detection.ps1 # Detection script test suite
│ └── test_remediation.ps1 # Remediation script test suite
└── logs/ # Directory for log files
ExchangeOnlineManagementMicrosoft.GraphAzureAD or AzureAD.Standard.Previewgit clone https://github.com/daryllundy/cve-2025-32711-detection.git
cd cve-2025-32711-detection
Install-Module -Name ExchangeOnlineManagement -Force
Install-Module -Name Microsoft.Graph -Force
Install-Module -Name AzureAD -Force
Connect-ExchangeOnline
Connect-MgGraph -Scopes "User.Read.All", "Directory.Read.All", "SecurityEvents.Read.All"
Connect-AzureAD
The detection script checks for:
Run the detection script:
.\detect.ps1 -OutputPath ".\logs\detection_report.json"
Parameters:
-OutputPath: Path for the detection report (default: .\logs\detection_report.json)-IncludeEmailAnalysis: Perform deep email analysis (may take longer)-Days: Number of days to look back in audit logs (default: 30)The remediation script implements:
Run the remediation script:
.\remediate.ps1 -ConfigPath ".\config\remediation_config.json" -WhatIf
Parameters:
-ConfigPath: Path to remediation configuration file-WhatIf: Preview changes without applying them-Force: Apply changes without confirmation promptsRun the test suites to verify script functionality:
# Test detection capabilities
.\tests\test_detection.ps1
# Test remediation functions
.\tests\test_remediation.ps1
The tool looks for the following indicators of potential exploitation:
Email Patterns:
Behavioral Anomalies:
Configuration Weaknesses:
The remediation script performs the following actions:
Email Security:
Data Loss Prevention:
Audit and Monitoring:
Access Controls:
-WhatIf parameter before applying remediationFor issues, questions, or contributions:
This tool is provided as-is for security assessment purposes. Use at your own risk and ensure compliance with your organization's security policies.