Loading interactive filters…
1200KM / index
Telemetry Library
Detection inputs, common providers, configuration guidance, synthetic event examples and links to relevant simulations, tools and detection workspaces.
Complete reference directory
- Active Directory Credential Request
- Active Directory Object Access
- Active Directory Object Creation
- Active Directory Object Deletion
- Active Directory Object Modification
- Active DNS
- API Calls
- Application Assets
- Application Log Content
- Application Permission
- Application State
- Asset availability monitoring
- Asset Inventory
- Authorized lab packet capture
- Business impact records
- Certificate Registration
- Cloud Service Disable
- Cloud Service Enumeration
- Cloud Service Metadata
- Cloud Service Modification
- Cloud Storage Access
- Cloud Storage Creation
- Cloud Storage Deletion
- Cloud Storage Enumeration
- Cloud Storage Metadata
- Cloud Storage Modification
- Command Execution
- Container Creation
- Container Enumeration
- Container Start
- Control-command acknowledgements
- Controller communication health
- Controller setpoint and configuration audit
- Device Alarm
- Device-to-destination connection fan-out
- Domain Registration
- Drive Access
- Drive Creation
- Drive Modification
- Driver Load
- Driver Metadata
- Egress and transfer records
- Equipment condition measurements
- External intelligence (context only)
- File Access
- File Creation
- File Deletion
- File Metadata
- File Modification
- Firewall Disable
- Firewall Rule Modification
- Firmware Modification
- Group Enumeration
- Group Metadata
- Group Modification
- Historian data freshness
- HMI and historian value comparison
- HMI communication health
- Host Status
- Image Creation
- Image Metadata
- Image Modification
- Independent physical process measurements
- Instance Creation
- Instance Deletion
- Instance Enumeration
- Instance Metadata
- Instance Modification
- Instance Start
- Instance Stop
- Instrumented Android filesystem changes
- Kernel Module Load
- Lab gateway network flows
- Logon Session Creation
- Logon Session Metadata
- Malware Content
- Malware Metadata
- Media inventory comparison
- Module Load
- Named Pipe Metadata
- Network Communication
- Network Connection Creation
- Network Share Access
- Network Traffic Content
- Network Traffic Flow
- Operational document access audit
- OS API Execution
- Outbound transfer volume and destination context
- Passive DNS
- Permissions Request
- Physical inspection and incident records
- Pod Creation
- Pod Enumeration
- Process Access
- Process Creation
- Process History/Live Data
- Process Metadata
- Process Modification
- Process Termination
- Process/Event Alarm
- Production service health
- Production throughput and downtime
- Protected Configuration
- Protection-system diagnostics
- Protocol-aware egress monitoring
- Provider-side audit (if lawfully available)
- Response Content
- Response Metadata
- Safety-system diagnostics
- Scheduled Job Creation
- Scheduled Job Metadata
- Scheduled Job Modification
- Script Execution
- Service Creation
- Service Metadata
- Service Modification
- Snapshot Creation
- Snapshot Deletion
- Snapshot Metadata
- Snapshot Modification
- Social Media
- Software
- System Notifications
- System Settings
- User Account Authentication
- User Account Creation
- User Account Deletion
- User Account Metadata
- User Account Modification
- Volume Creation
- Volume Deletion
- Volume Modification
- Web Credential Creation
- Web Credential Usage
- Windows Registry Key Access
- Windows Registry Key Creation
- Windows Registry Key Deletion
- Windows Registry Key Modification
- WMI Creation
Connected ecosystem references
Explore the three modules
Attack Tools · Attack Simulations · Detection Rules · Telemetry · Tags
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.