Vendor: OpenAI

May 13, 2026 · View on GitHub

Product: ChatGPT

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
8137855
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Abnormal Authentication & Accessaccount-deleted
openai-chatgpt-json-user-delete-clp
openai-chatgpt-json-user-delete-clp

app-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall

member-added
openai-chatgpt-json-app-activity-clp-catchall

member-removed
openai-chatgpt-json-app-activity-clp-catchall
T1078 - Valid Accounts
T1133 - External Remote Services
  • 12 Rules
  • 4 Models
Account Manipulationaccount-deleted
openai-chatgpt-json-user-delete-clp
openai-chatgpt-json-user-delete-clp

app-activity
openai-chatgpt-json-ai-agent-request-response-clp
openai-chatgpt-json-ai-agent-request-response-compliance
openai-chatgpt-json-ai-conversation-share-clp
openai-chatgpt-json-ai-conversation-delete-clp
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall
openai-chatgpt-json-app-activity-clp-catchall

member-added
openai-chatgpt-json-app-activity-clp-catchall

member-removed
openai-chatgpt-json-app-activity-clp-catchall
T1098 - Account Manipulation
T1098.002 - Account Manipulation: Exchange Email Delegate Permissions
T1136 - Create Account
T1531 - Account Access Removal
  • 29 Rules
  • 13 Models
Next Page -->>

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
External Remote Services

Valid Accounts

Create Account

External Remote Services

Valid Accounts

Account Manipulation

Account Manipulation: Exchange Email Delegate Permissions

Valid Accounts

Valid Accounts

Email Collection

Email Collection: Email Forwarding Rule

Account Access Removal