1200KM / telemetry
Module Load — Detection Telemetry
A module or library being loaded into a running process.
Collection and providers
Scope Sysmon ImageLoad (7) to lab processes/paths; retain module hash, signer and destination process. Inventory alone does not prove a module loaded.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
- Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
- Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0016",
"collector": "illustrative-lab-collector",
"observation": {
"process_id": 4200,
"image_loaded": "C:\\Lab\\demo.dll",
"signed": false,
"action": "load"
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1014 · Rootkit · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1027.007 · Dynamic API Resolution · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.014 · Polymorphic Code · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1055.005 · Thread Local Storage · Detection rules & anomalies
- T1055.014 · VDSO Hijacking · Detection rules & anomalies
- T1056.004 · Credential API Hooking · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127 · Trusted Developer Utilities Proxy Execution · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1127.002 · ClickOnce · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1137.002 · Office Test · Detection rules & anomalies
- T1137.003 · Outlook Forms · Detection rules & anomalies
- T1137.004 · Outlook Home Page · Detection rules & anomalies
- T1137.005 · Outlook Rules · Detection rules & anomalies
- T1185 · Browser Session Hijacking · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1195.003 · Compromise Hardware Supply Chain · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1205.002 · Socket Filters · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1211 · Exploitation for Stealth · Detection rules & anomalies
- T1216 · System Script Proxy Execution · Detection rules & anomalies
- T1216.001 · PubPrn · Detection rules & anomalies
- T1216.002 · SyncAppvPublishingServer · Detection rules & anomalies
- T1218 · System Binary Proxy Execution · Detection rules & anomalies
- T1218.001 · Compiled HTML File · Detection rules & anomalies
- T1218.002 · Control Panel · Detection rules & anomalies
- T1218.004 · InstallUtil · Detection rules & anomalies
- T1218.007 · Msiexec · Detection rules & anomalies
- T1218.008 · Odbcconf · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.010 · Regsvr32 · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1218.012 · Verclsid · Detection rules & anomalies
- T1218.013 · Mavinject · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1218.015 · Electron Applications · Detection rules & anomalies
- T1220 · XSL Script Processing · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1497 · Virtualization/Sandbox Evasion · Detection rules & anomalies
- T1497.001 · System Checks · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1505.001 · SQL Stored Procedures · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.004 · IIS Components · Detection rules & anomalies
- T1505.005 · Terminal Services DLL · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1546.003 · Windows Management Instrumentation Event Subscription · Detection rules & anomalies
- T1546.006 · LC_LOAD_DYLIB Addition · Detection rules & anomalies
- T1546.007 · Netsh Helper DLL · Detection rules & anomalies
- T1546.009 · AppCert DLLs · Detection rules & anomalies
- T1546.010 · AppInit DLLs · Detection rules & anomalies
- T1546.011 · Application Shimming · Detection rules & anomalies
- T1546.015 · Component Object Model Hijacking · Detection rules & anomalies
- T1547.002 · Authentication Package · Detection rules & anomalies
- T1547.003 · Time Providers · Detection rules & anomalies
- T1547.004 · Winlogon Helper DLL · Detection rules & anomalies
- T1547.005 · Security Support Provider · Detection rules & anomalies
- T1547.008 · LSASS Driver · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.012 · Print Processors · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1550.003 · Pass the Ticket · Detection rules & anomalies
- T1553.002 · Code Signing · Detection rules & anomalies
- T1553.003 · SIP and Trust Provider Hijacking · Detection rules & anomalies
- T1554 · Compromise Host Software Binary · Detection rules & anomalies
- T1556 · Modify Authentication Process · Detection rules & anomalies
- T1556.001 · Domain Controller Authentication · Detection rules & anomalies
- T1556.002 · Password Filter DLL · Detection rules & anomalies
- T1556.007 · Hybrid Identity · Detection rules & anomalies
- T1556.008 · Network Provider DLL · Detection rules & anomalies
- T1559.001 · Component Object Model · Detection rules & anomalies
- T1559.002 · Dynamic Data Exchange · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1560.002 · Archive via Library · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1574 · Hijack Execution Flow · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.004 · Dylib Hijacking · Detection rules & anomalies
- T1574.005 · Executable Installer File Permissions Weakness · Detection rules & anomalies
- T1574.006 · Dynamic Linker Hijacking · Detection rules & anomalies
- T1574.012 · COR_PROFILER · Detection rules & anomalies
- T1574.014 · AppDomainManager · Detection rules & anomalies
- T1600 · Weaken Encryption · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1678 · Delay Execution · Detection rules & anomalies
- T0823 · Graphical User Interface · Detection rules & anomalies
- T0853 · Scripting · Detection rules & anomalies
- T0886 · Remote Services · Detection rules & anomalies
- T1406 · Obfuscated Files or Information · Detection rules & anomalies
- T1406.002 · Software Packing · Detection rules & anomalies
- T1407 · Download New Code at Runtime · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- AsyncRAT · S1087
- BloodHound · S0521
- Brute Ratel C4 · S1063
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Diskpart · S9002
- Donut · S0695
- dsquery · S0105
- Empire · S0363
- evilginx2 · S9003
- FlexiSpy · S0408
- FRP · S1144
- gsecdump · S0008
- Havij · S0224
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- IronNetInjector · S0581
- Koadic · S0250
- LaZagne · S0349
- MCMD · S0500
- Mimikatz · S0002
- Mythic · S0699
- Net · S0039
- netsh · S0108
- Nltest · S0359
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Rclone · S1040
- Remcos · S0332
- RemoteUtilities · S0592
- Rubeus · S1071
- Ruler · S0358
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- sqlmap · S0225
- Tasklist · S0057
- Tor · S0183
- UACMe · S0116
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.