Rules by Product and UseCase

April 15, 2026 · View on GitHub

Vendor: StealthBits

Product: StealthIntercept

Use-Case: Privilege Abuse

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
22110
Event TypeRulesModels
ds-accessT1484 - Group Policy Modification
DS-APRIV: Non-Privileged user accessing privileged directory service attribute
DS-UA: First access to attribute for privileged user
DS-UA: Attributes per privileged user
DS-APRIV: Privileged user attributes