1200KM / telemetry
OS API Execution — Detection Telemetry
Instrumented operating-system API calls and their return values.
Collection and providers
Use an approved EDR trace or instrument the owned lab process at selected APIs. Define API name, caller, sanitized arguments and return status.
- Application audit logs: First-party service events and request/result fields; schema is application-specific.
- OpenTelemetry-compatible log pipelines: Transport and normalization of emitted records; do not create missing audit instrumentation.
Configuration
- Enable the application audit category or instrument the owned lab application at the authorization/action boundary.
- Define a schema with timestamp, service, actor, object, action, result and correlation ID. Export structured records through an authenticated collector.
- Redact secrets and personal content, separate audit from debug logs, set retention and verify delivery during rotation/restart.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0021",
"collector": "illustrative-lab-collector",
"observation": {
"process_id": 4200,
"api": "CreateFileW",
"path": "C:\\Lab\\demo.txt",
"result": "success"
}
}Visibility and validation
Debug output is not necessarily a durable audit trail. Application developers must emit the relevant event; installing a log pipeline does not make an absent event exist.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.007 · Dynamic API Resolution · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1036.009 · Break Process Trees · Detection rules & anomalies
- T1036.012 · Browser Fingerprint · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.003 · Thread Execution Hijacking · Detection rules & anomalies
- T1055.004 · Asynchronous Procedure Call · Detection rules & anomalies
- T1055.005 · Thread Local Storage · Detection rules & anomalies
- T1055.008 · Ptrace System Calls · Detection rules & anomalies
- T1055.009 · Proc Memory · Detection rules & anomalies
- T1055.011 · Extra Window Memory Injection · Detection rules & anomalies
- T1055.012 · Process Hollowing · Detection rules & anomalies
- T1055.013 · Process Doppelgänging · Detection rules & anomalies
- T1055.014 · VDSO Hijacking · Detection rules & anomalies
- T1055.015 · ListPlanting · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1111 · Multi-Factor Authentication Interception · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1134.001 · Token Impersonation/Theft · Detection rules & anomalies
- T1134.002 · Create Process with Token · Detection rules & anomalies
- T1134.003 · Make and Impersonate Token · Detection rules & anomalies
- T1134.004 · Parent PID Spoofing · Detection rules & anomalies
- T1134.005 · SID-History Injection · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1480.002 · Mutual Exclusion · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1542.004 · ROMMONkit · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.015 · Login Items · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1548.004 · Elevated Execution with Prompt · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.001 · Keychain · Detection rules & anomalies
- T1564.004 · NTFS File Attributes · Detection rules & anomalies
- T1564.013 · Bind Mounts · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1565.002 · Transmitted Data Manipulation · Detection rules & anomalies
- T1565.003 · Runtime Data Manipulation · Detection rules & anomalies
- T1574.013 · KernelCallbackTable · Detection rules & anomalies
- T1611 · Escape to Host · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
- T1614.001 · System Language Discovery · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1622 · Debugger Evasion · Detection rules & anomalies
- T0834 · Native API · Detection rules & anomalies
- T0840 · Network Connection Enumeration · Detection rules & anomalies
- T0852 · Screen Capture · Detection rules & anomalies
- T0871 · Execution through API · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T0874 · Hooking · Detection rules & anomalies
- T0881 · Service Stop · Detection rules & anomalies
- T0893 · Data from Local System · Detection rules & anomalies
- T1404 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1406 · Obfuscated Files or Information · Detection rules & anomalies
- T1406.002 · Software Packing · Detection rules & anomalies
- T1407 · Download New Code at Runtime · Detection rules & anomalies
- T1409 · Stored Application Data · Detection rules & anomalies
- T1414 · Clipboard Data · Detection rules & anomalies
- T1417 · Input Capture · Detection rules & anomalies
- T1417.001 · Keylogging · Detection rules & anomalies
- T1417.002 · GUI Input Capture · Detection rules & anomalies
- T1418 · Software Discovery · Detection rules & anomalies
- T1418.001 · Security Software Discovery · Detection rules & anomalies
- T1420 · File and Directory Discovery · Detection rules & anomalies
- T1421 · System Network Connections Discovery · Detection rules & anomalies
- T1424 · Process Discovery · Detection rules & anomalies
- T1426 · System Information Discovery · Detection rules & anomalies
- T1429 · Audio Capture · Detection rules & anomalies
- T1430 · Location Tracking · Detection rules & anomalies
- T1437 · Application Layer Protocol · Detection rules & anomalies
- T1451 · SIM Card Swap · Detection rules & anomalies
- T1453 · Abuse Accessibility Features · Detection rules & anomalies
- T1456 · Drive-By Compromise · Detection rules & anomalies
- T1458 · Replication Through Removable Media · Detection rules & anomalies
- T1464 · Network Denial of Service · Detection rules & anomalies
- T1471 · Data Encrypted for Impact · Detection rules & anomalies
- T1474 · Supply Chain Compromise · Detection rules & anomalies
- T1474.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1474.002 · Compromise Hardware Supply Chain · Detection rules & anomalies
- T1474.003 · Compromise Software Supply Chain · Detection rules & anomalies
- T1481 · Web Service · Detection rules & anomalies
- T1481.001 · Dead Drop Resolver · Detection rules & anomalies
- T1481.002 · Bidirectional Communication · Detection rules & anomalies
- T1509 · Non-Standard Port · Detection rules & anomalies
- T1512 · Video Capture · Detection rules & anomalies
- T1513 · Screen Capture · Detection rules & anomalies
- T1516 · Input Injection · Detection rules & anomalies
- T1517 · Access Notifications · Detection rules & anomalies
- T1521 · Encrypted Channel · Detection rules & anomalies
- T1521.001 · Symmetric Cryptography · Detection rules & anomalies
- T1521.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1521.003 · SSL Pinning · Detection rules & anomalies
- T1532 · Archive Collected Data · Detection rules & anomalies
- T1533 · Data from Local System · Detection rules & anomalies
- T1541 · Foreground Persistence · Detection rules & anomalies
- T1544 · Ingress Tool Transfer · Detection rules & anomalies
- T1575 · Native API · Detection rules & anomalies
- T1577 · Compromise Application Executable · Detection rules & anomalies
- T1582 · SMS Control · Detection rules & anomalies
- T1603 · Scheduled Task/Job · Detection rules & anomalies
- T1604 · Proxy Through Victim · Detection rules & anomalies
- T1616 · Call Control · Detection rules & anomalies
- T1617 · Hooking · Detection rules & anomalies
- T1624 · Event Triggered Execution · Detection rules & anomalies
- T1624.001 · Broadcast Receivers · Detection rules & anomalies
- T1625 · Hijack Execution Flow · Detection rules & anomalies
- T1625.001 · System Runtime API Hijacking · Detection rules & anomalies
- T1626 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1626.001 · Device Administrator Permissions · Detection rules & anomalies
- T1627 · Execution Guardrails · Detection rules & anomalies
- T1627.001 · Geofencing · Detection rules & anomalies
- T1628.001 · Suppress Application Icon · Detection rules & anomalies
- T1628.002 · User Evasion · Detection rules & anomalies
- T1629 · Impair Defenses · Detection rules & anomalies
- T1629.001 · Prevent Application Removal · Detection rules & anomalies
- T1629.002 · Device Lockout · Detection rules & anomalies
- T1629.003 · Disable or Modify Tools · Detection rules & anomalies
- T1630 · Indicator Removal on Host · Detection rules & anomalies
- T1630.001 · Uninstall Malicious Application · Detection rules & anomalies
- T1630.002 · File Deletion · Detection rules & anomalies
- T1635 · Steal Application Access Token · Detection rules & anomalies
- T1636.001 · Calendar Entries · Detection rules & anomalies
- T1636.002 · Call Log · Detection rules & anomalies
- T1636.003 · Contact List · Detection rules & anomalies
- T1636.005 · Accounts · Detection rules & anomalies
- T1670 · Virtualization Solution · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AsyncRAT · S1087
- BloodHound · S0521
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- Cobalt Strike · S0154
- ConnectWise · S0591
- CrackMapExec · S0488
- DCRAT · S9017
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Expand · S0361
- FlexiSpy · S0408
- FRP · S1144
- HTRAN · S0040
- Imminent Monitor · S0434
- IronNetInjector · S0581
- Koadic · S0250
- LaZagne · S0349
- MCMD · S0500
- Mimikatz · S0002
- NBTscan · S0590
- nbtstat · S0102
- Net · S0039
- netstat · S0104
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- Peirates · S0683
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Remcos · S0332
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- Xbot · S0298
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.