Vendor: StealthBits

April 15, 2026 · View on GitHub

Product: StealthIntercept

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
4217520
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Account Manipulationds-access
stealthbits-s-leef-ds-object-activity-attrnewvalue

failed-ds-access
stealthbits-s-leef-ds-object-activity-attrnewvalue
T1207 - Rogue Domain Controller
T1484 - Group Policy Modification
  • 35 Rules
  • 16 Models
Compromised Credentialsds-access
stealthbits-s-leef-ds-object-activity-attrnewvalue
T1003 - OS Credential Dumping
T1003.006 - OS Credential Dumping: DCSync
T1207 - Rogue Domain Controller
T1558 - Steal or Forge Kerberos Tickets
  • 7 Rules
  • 1 Models
Privilege Abuseds-access
stealthbits-s-leef-ds-object-activity-attrnewvalue
T1484 - Group Policy Modification
  • 2 Rules
  • 2 Models
Privileged Activityds-access
stealthbits-s-leef-ds-object-activity-attrnewvalue
T1003 - OS Credential Dumping
T1003.006 - OS Credential Dumping: DCSync
T1207 - Rogue Domain Controller
T1484 - Group Policy Modification
  • 7 Rules
  • 2 Models

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Group Policy Modification

Group Policy Modification

Rogue Domain Controller

OS Credential Dumping

Steal or Forge Kerberos Tickets

OS Credential Dumping: DCSync