2_ds_openai_chatgpt.md

May 13, 2026 · View on GitHub

Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Compromised Credentialsapp-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
T1078 - Valid Accounts
T1133 - External Remote Services
  • 39 Rules
  • 24 Models
Data Accessapp-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
T1078 - Valid Accounts
  • 19 Rules
  • 11 Models
Data Leakapp-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
T1114 - Email Collection
T1114.003 - Email Collection: Email Forwarding Rule
  • 3 Rules
Privilege Abuseaccount-deleted
openai-chatgpt-json-user-delete-clp
openai-chatgpt-json-user-delete-clp

app-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall

app-activity-failed
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall

member-added
openai-chatgpt-json-app-activity-clp-catchall

member-removed
openai-chatgpt-json-app-activity-clp-catchall
T1078 - Valid Accounts
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1531 - Account Access Removal
  • 31 Rules
  • 14 Models
Privilege Escalationapp-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
  • 3 Rules
  • 1 Models
Privileged Activityapp-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall

app-activity-failed
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
T1078 - Valid Accounts
  • 2 Rules
  • 1 Models