1200KM / telemetry
WMI Creation — Detection Telemetry
Creation of WMI objects relevant to event subscriptions or other instrumented WMI activity.
Collection and providers
For permanent subscriptions, collect Sysmon WmiEvent 19–21 and retain filter, consumer and binding information; this is not comprehensive auditing of every WMI operation.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- Keep this Windows-specific source separate from other operating systems; there is no direct cross-platform event-ID equivalence.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0008",
"collector": "illustrative-lab-collector",
"observation": {
"object_kind": "event_filter",
"namespace": "root/subscription",
"object_name": "LabFilter",
"action": "create"
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1027.011 · Fileless Storage · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.003 · Windows Management Instrumentation Event Subscription · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.