1200KM / telemetry
Process Creation — Detection Telemetry
Creation of a process with executable, command line, parent and security context.
Collection and providers
Collect Sysmon ProcessCreate (1); preserve ProcessGuid and parent identifiers. Security 4688 is an alternative with separate audit/command-line settings.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
- Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
- Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.
<EventFiltering>
<ProcessCreate onmatch="include">
<Image condition="is">C:\Windows\System32\whoami.exe</Image>
</ProcessCreate>
</EventFiltering>This fragment only selects the named process. It is not a complete production policy. Inspect the installed schema with sysmon64 -s; preserve existing rules, then apply the reviewed complete configuration with sysmon64 -c <configuration-file>.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0032",
"collector": "illustrative-lab-collector",
"observation": {
"process_guid": "lab-process-001",
"image": "C:\\Windows\\System32\\whoami.exe",
"parent_image": "C:\\Windows\\System32\\cmd.exe",
"command_line": "whoami",
"user": "LAB\\analyst"
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001 · Data Obfuscation · Detection rules & anomalies
- T1001.001 · Junk Data · Detection rules & anomalies
- T1001.002 · Steganography · Detection rules & anomalies
- T1001.003 · Protocol or Service Impersonation · Detection rules & anomalies
- T1003 · OS Credential Dumping · Detection rules & anomalies
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1003.005 · Cached Domain Credentials · Detection rules & anomalies
- T1003.007 · Proc Filesystem · Detection rules & anomalies
- T1003.008 · /etc/passwd and /etc/shadow · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1006 · Direct Volume Access · Detection rules & anomalies
- T1007 · System Service Discovery · Detection rules & anomalies
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1011.001 · Exfiltration Over Bluetooth · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1014 · Rootkit · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1016.001 · Internet Connection Discovery · Detection rules & anomalies
- T1016.002 · Wi-Fi Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1020 · Automated Exfiltration · Detection rules & anomalies
- T1021 · Remote Services · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1021.002 · SMB/Windows Admin Shares · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1021.005 · VNC · Detection rules & anomalies
- T1021.006 · Windows Remote Management · Detection rules & anomalies
- T1021.008 · Direct Cloud VM Connections · Detection rules & anomalies
- T1025 · Data from Removable Media · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.001 · Binary Padding · Detection rules & anomalies
- T1027.002 · Software Packing · Detection rules & anomalies
- T1027.003 · Steganography · Detection rules & anomalies
- T1027.004 · Compile After Delivery · Detection rules & anomalies
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1027.006 · HTML Smuggling · Detection rules & anomalies
- T1027.007 · Dynamic API Resolution · Detection rules & anomalies
- T1027.008 · Stripped Payloads · Detection rules & anomalies
- T1027.009 · Embedded Payloads · Detection rules & anomalies
- T1027.010 · Command Obfuscation · Detection rules & anomalies
- T1027.012 · LNK Icon Smuggling · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.014 · Polymorphic Code · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1027.016 · Junk Code Insertion · Detection rules & anomalies
- T1027.017 · SVG Smuggling · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1029 · Scheduled Transfer · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1036 · Masquerading · Detection rules & anomalies
- T1036.001 · Invalid Code Signature · Detection rules & anomalies
- T1036.002 · Right-to-Left Override · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1036.004 · Masquerade Task or Service · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.006 · Space after Filename · Detection rules & anomalies
- T1036.007 · Double File Extension · Detection rules & anomalies
- T1036.008 · Masquerade File Type · Detection rules & anomalies
- T1036.009 · Break Process Trees · Detection rules & anomalies
- T1036.012 · Browser Fingerprint · Detection rules & anomalies
- T1037 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1037.001 · Logon Script (Windows) · Detection rules & anomalies
- T1037.002 · Login Hook · Detection rules & anomalies
- T1037.003 · Network Logon Script · Detection rules & anomalies
- T1037.004 · RC Scripts · Detection rules & anomalies
- T1037.005 · Startup Items · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1052 · Exfiltration Over Physical Medium · Detection rules & anomalies
- T1052.001 · Exfiltration over USB · Detection rules & anomalies
- T1053 · Scheduled Task/Job · Detection rules & anomalies
- T1053.002 · At · Detection rules & anomalies
- T1053.003 · Cron · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1053.006 · Systemd Timers · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.001 · Dynamic-link Library Injection · Detection rules & anomalies
- T1055.002 · Portable Executable Injection · Detection rules & anomalies
- T1055.003 · Thread Execution Hijacking · Detection rules & anomalies
- T1055.004 · Asynchronous Procedure Call · Detection rules & anomalies
- T1055.008 · Ptrace System Calls · Detection rules & anomalies
- T1055.011 · Extra Window Memory Injection · Detection rules & anomalies
- T1055.012 · Process Hollowing · Detection rules & anomalies
- T1055.013 · Process Doppelgänging · Detection rules & anomalies
- T1055.014 · VDSO Hijacking · Detection rules & anomalies
- T1055.015 · ListPlanting · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1056.002 · GUI Input Capture · Detection rules & anomalies
- T1056.004 · Credential API Hooking · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059 · Command and Scripting Interpreter · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.002 · AppleScript · Detection rules & anomalies
- T1059.003 · Windows Command Shell · Detection rules & anomalies
- T1059.004 · Unix Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1059.010 · AutoHotKey & AutoIT · Detection rules & anomalies
- T1059.011 · Lua · Detection rules & anomalies
- T1059.013 · Container CLI/API · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1069 · Permission Groups Discovery · Detection rules & anomalies
- T1069.001 · Local Groups · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1070.003 · Clear Command History · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1070.005 · Network Share Connection Removal · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1070.007 · Clear Network Connection History and Configurations · Detection rules & anomalies
- T1070.008 · Clear Mailbox Data · Detection rules & anomalies
- T1070.009 · Clear Persistence · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.003 · Mail Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1071.005 · Publish/Subscribe Protocols · Detection rules & anomalies
- T1072 · Software Deployment Tools · Detection rules & anomalies
- T1074 · Data Staged · Detection rules & anomalies
- T1074.001 · Local Data Staging · Detection rules & anomalies
- T1074.002 · Remote Data Staging · Detection rules & anomalies
- T1078 · Valid Accounts · Detection rules & anomalies
- T1078.002 · Domain Accounts · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087 · Account Discovery · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1087.003 · Email Account · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1090.004 · Domain Fronting · Detection rules & anomalies
- T1091 · Replication Through Removable Media · Detection rules & anomalies
- T1092 · Communication Through Removable Media · Detection rules & anomalies
- T1098 · Account Manipulation · Detection rules & anomalies
- T1098.002 · Additional Email Delegate Permissions · Detection rules & anomalies
- T1098.004 · SSH Authorized Keys · Detection rules & anomalies
- T1102.002 · Bidirectional Communication · Detection rules & anomalies
- T1102.003 · One-Way Communication · Detection rules & anomalies
- T1104 · Multi-Stage Channels · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1106 · Native API · Detection rules & anomalies
- T1110.002 · Password Cracking · Detection rules & anomalies
- T1111 · Multi-Factor Authentication Interception · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1113 · Screen Capture · Detection rules & anomalies
- T1114 · Email Collection · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1114.003 · Email Forwarding Rule · Detection rules & anomalies
- T1115 · Clipboard Data · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1120 · Peripheral Device Discovery · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127 · Trusted Developer Utilities Proxy Execution · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1127.002 · ClickOnce · Detection rules & anomalies
- T1127.003 · JamPlus · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1132.002 · Non-Standard Encoding · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1134.001 · Token Impersonation/Theft · Detection rules & anomalies
- T1134.002 · Create Process with Token · Detection rules & anomalies
- T1134.003 · Make and Impersonate Token · Detection rules & anomalies
- T1134.004 · Parent PID Spoofing · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1136 · Create Account · Detection rules & anomalies
- T1136.001 · Local Account · Detection rules & anomalies
- T1136.002 · Domain Account · Detection rules & anomalies
- T1137 · Office Application Startup · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1137.002 · Office Test · Detection rules & anomalies
- T1137.003 · Outlook Forms · Detection rules & anomalies
- T1137.004 · Outlook Home Page · Detection rules & anomalies
- T1137.005 · Outlook Rules · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1176.002 · IDE Extensions · Detection rules & anomalies
- T1189 · Drive-by Compromise · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1197 · BITS Jobs · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1201 · Password Policy Discovery · Detection rules & anomalies
- T1202 · Indirect Command Execution · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1204.001 · Malicious Link · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1204.003 · Malicious Image · Detection rules & anomalies
- T1204.004 · Malicious Copy and Paste · Detection rules & anomalies
- T1204.005 · Malicious Library · Detection rules & anomalies
- T1205 · Traffic Signaling · Detection rules & anomalies
- T1205.001 · Port Knocking · Detection rules & anomalies
- T1205.002 · Socket Filters · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1211 · Exploitation for Stealth · Detection rules & anomalies
- T1212 · Exploitation for Credential Access · Detection rules & anomalies
- T1213 · Data from Information Repositories · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1216 · System Script Proxy Execution · Detection rules & anomalies
- T1216.001 · PubPrn · Detection rules & anomalies
- T1216.002 · SyncAppvPublishingServer · Detection rules & anomalies
- T1217 · Browser Information Discovery · Detection rules & anomalies
- T1218 · System Binary Proxy Execution · Detection rules & anomalies
- T1218.001 · Compiled HTML File · Detection rules & anomalies
- T1218.002 · Control Panel · Detection rules & anomalies
- T1218.003 · CMSTP · Detection rules & anomalies
- T1218.004 · InstallUtil · Detection rules & anomalies
- T1218.005 · Mshta · Detection rules & anomalies
- T1218.007 · Msiexec · Detection rules & anomalies
- T1218.008 · Odbcconf · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.010 · Regsvr32 · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1218.012 · Verclsid · Detection rules & anomalies
- T1218.013 · Mavinject · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1218.015 · Electron Applications · Detection rules & anomalies
- T1219 · Remote Access Tools · Detection rules & anomalies
- T1219.001 · IDE Tunneling · Detection rules & anomalies
- T1219.002 · Remote Desktop Software · Detection rules & anomalies
- T1220 · XSL Script Processing · Detection rules & anomalies
- T1221 · Template Injection · Detection rules & anomalies
- T1222 · File and Directory Permissions Modification · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1222.002 · Linux and Mac Permissions · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1480.002 · Mutual Exclusion · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1484 · Domain or Tenant Policy Modification · Detection rules & anomalies
- T1484.001 · Group Policy Modification · Detection rules & anomalies
- T1484.002 · Trust Modification · Detection rules & anomalies
- T1485 · Data Destruction · Detection rules & anomalies
- T1486 · Data Encrypted for Impact · Detection rules & anomalies
- T1489 · Service Stop · Detection rules & anomalies
- T1490 · Inhibit System Recovery · Detection rules & anomalies
- T1491 · Defacement · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1491.002 · External Defacement · Detection rules & anomalies
- T1495 · Firmware Corruption · Detection rules & anomalies
- T1496 · Resource Hijacking · Detection rules & anomalies
- T1496.001 · Compute Hijacking · Detection rules & anomalies
- T1496.002 · Bandwidth Hijacking · Detection rules & anomalies
- T1497 · Virtualization/Sandbox Evasion · Detection rules & anomalies
- T1497.001 · System Checks · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1498 · Network Denial of Service · Detection rules & anomalies
- T1498.001 · Direct Network Flood · Detection rules & anomalies
- T1498.002 · Reflection Amplification · Detection rules & anomalies
- T1499 · Endpoint Denial of Service · Detection rules & anomalies
- T1499.001 · OS Exhaustion Flood · Detection rules & anomalies
- T1499.003 · Application Exhaustion Flood · Detection rules & anomalies
- T1499.004 · Application or System Exploitation · Detection rules & anomalies
- T1505 · Server Software Component · Detection rules & anomalies
- T1505.001 · SQL Stored Procedures · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.003 · Web Shell · Detection rules & anomalies
- T1505.004 · IIS Components · Detection rules & anomalies
- T1505.005 · Terminal Services DLL · Detection rules & anomalies
- T1518 · Software Discovery · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1518.002 · Backup Software Discovery · Detection rules & anomalies
- T1529 · System Shutdown/Reboot · Detection rules & anomalies
- T1531 · Account Access Removal · Detection rules & anomalies
- T1534 · Internal Spearphishing · Detection rules & anomalies
- T1539 · Steal Web Session Cookie · Detection rules & anomalies
- T1542 · Pre-OS Boot · Detection rules & anomalies
- T1542.001 · System Firmware · Detection rules & anomalies
- T1543 · Create or Modify System Process · Detection rules & anomalies
- T1543.002 · Systemd Service · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1543.004 · Launch Daemon · Detection rules & anomalies
- T1543.005 · Container Service · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.001 · Change Default File Association · Detection rules & anomalies
- T1546.002 · Screensaver · Detection rules & anomalies
- T1546.003 · Windows Management Instrumentation Event Subscription · Detection rules & anomalies
- T1546.004 · Unix Shell Configuration Modification · Detection rules & anomalies
- T1546.005 · Trap · Detection rules & anomalies
- T1546.007 · Netsh Helper DLL · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1546.009 · AppCert DLLs · Detection rules & anomalies
- T1546.010 · AppInit DLLs · Detection rules & anomalies
- T1546.011 · Application Shimming · Detection rules & anomalies
- T1546.012 · Image File Execution Options Injection · Detection rules & anomalies
- T1546.013 · PowerShell Profile · Detection rules & anomalies
- T1546.014 · Emond · Detection rules & anomalies
- T1546.015 · Component Object Model Hijacking · Detection rules & anomalies
- T1546.016 · Installer Packages · Detection rules & anomalies
- T1546.017 · Udev Rules · Detection rules & anomalies
- T1546.018 · Python Startup Hooks · Detection rules & anomalies
- T1547 · Boot or Logon Autostart Execution · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.003 · Time Providers · Detection rules & anomalies
- T1547.004 · Winlogon Helper DLL · Detection rules & anomalies
- T1547.005 · Security Support Provider · Detection rules & anomalies
- T1547.006 · Kernel Modules and Extensions · Detection rules & anomalies
- T1547.007 · Re-opened Applications · Detection rules & anomalies
- T1547.009 · Shortcut Modification · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.013 · XDG Autostart Entries · Detection rules & anomalies
- T1547.014 · Active Setup · Detection rules & anomalies
- T1547.015 · Login Items · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1548.001 · Setuid and Setgid · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1548.004 · Elevated Execution with Prompt · Detection rules & anomalies
- T1548.006 · TCC Manipulation · Detection rules & anomalies
- T1550 · Use Alternate Authentication Material · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.002 · Credentials in Registry · Detection rules & anomalies
- T1552.003 · Shell History · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1552.006 · Group Policy Preferences · Detection rules & anomalies
- T1552.007 · Container API · Detection rules & anomalies
- T1553 · Subvert Trust Controls · Detection rules & anomalies
- T1553.001 · Gatekeeper Bypass · Detection rules & anomalies
- T1553.002 · Code Signing · Detection rules & anomalies
- T1553.004 · Install Root Certificate · Detection rules & anomalies
- T1553.006 · Code Signing Policy Modification · Detection rules & anomalies
- T1554 · Compromise Host Software Binary · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.001 · Keychain · Detection rules & anomalies
- T1555.002 · Securityd Memory · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1555.004 · Windows Credential Manager · Detection rules & anomalies
- T1555.005 · Password Managers · Detection rules & anomalies
- T1556 · Modify Authentication Process · Detection rules & anomalies
- T1556.003 · Pluggable Authentication Modules · Detection rules & anomalies
- T1556.005 · Reversible Encryption · Detection rules & anomalies
- T1558.004 · AS-REP Roasting · Detection rules & anomalies
- T1558.005 · Ccache Files · Detection rules & anomalies
- T1559 · Inter-Process Communication · Detection rules & anomalies
- T1559.001 · Component Object Model · Detection rules & anomalies
- T1559.002 · Dynamic Data Exchange · Detection rules & anomalies
- T1559.003 · XPC Services · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1560.002 · Archive via Library · Detection rules & anomalies
- T1560.003 · Archive via Custom Method · Detection rules & anomalies
- T1561 · Disk Wipe · Detection rules & anomalies
- T1561.001 · Disk Content Wipe · Detection rules & anomalies
- T1561.002 · Disk Structure Wipe · Detection rules & anomalies
- T1563 · Remote Service Session Hijacking · Detection rules & anomalies
- T1563.001 · SSH Hijacking · Detection rules & anomalies
- T1563.002 · RDP Hijacking · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1564.004 · NTFS File Attributes · Detection rules & anomalies
- T1564.005 · Hidden File System · Detection rules & anomalies
- T1564.006 · Run Virtual Instance · Detection rules & anomalies
- T1564.007 · VBA Stomping · Detection rules & anomalies
- T1564.008 · Email Hiding Rules · Detection rules & anomalies
- T1564.009 · Resource Forking · Detection rules & anomalies
- T1564.010 · Process Argument Spoofing · Detection rules & anomalies
- T1564.011 · Ignore Process Interrupts · Detection rules & anomalies
- T1564.012 · File/Path Exclusions · Detection rules & anomalies
- T1566 · Phishing · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1568.001 · Fast Flux DNS · Detection rules & anomalies
- T1568.002 · Domain Generation Algorithms · Detection rules & anomalies
- T1568.003 · DNS Calculation · Detection rules & anomalies
- T1569 · System Services · Detection rules & anomalies
- T1569.001 · Launchctl · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1569.003 · Systemctl · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1574 · Hijack Execution Flow · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.005 · Executable Installer File Permissions Weakness · Detection rules & anomalies
- T1574.006 · Dynamic Linker Hijacking · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1574.008 · Path Interception by Search Order Hijacking · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1574.010 · Services File Permissions Weakness · Detection rules & anomalies
- T1574.011 · Services Registry Permissions Weakness · Detection rules & anomalies
- T1574.012 · COR_PROFILER · Detection rules & anomalies
- T1574.013 · KernelCallbackTable · Detection rules & anomalies
- T1574.014 · AppDomainManager · Detection rules & anomalies
- T1609 · Container Administration Command · Detection rules & anomalies
- T1610 · Deploy Container · Detection rules & anomalies
- T1611 · Escape to Host · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
- T1614.001 · System Language Discovery · Detection rules & anomalies
- T1615 · Group Policy Discovery · Detection rules & anomalies
- T1620 · Reflective Code Loading · Detection rules & anomalies
- T1622 · Debugger Evasion · Detection rules & anomalies
- T1647 · Plist File Modification · Detection rules & anomalies
- T1651 · Cloud Administration Command · Detection rules & anomalies
- T1652 · Device Driver Discovery · Detection rules & anomalies
- T1653 · Power Settings · Detection rules & anomalies
- T1654 · Log Enumeration · Detection rules & anomalies
- T1657 · Financial Theft · Detection rules & anomalies
- T1659 · Content Injection · Detection rules & anomalies
- T1665 · Hide Infrastructure · Detection rules & anomalies
- T1668 · Exclusive Control · Detection rules & anomalies
- T1673 · Virtual Machine Discovery · Detection rules & anomalies
- T1674 · Input Injection · Detection rules & anomalies
- T1678 · Delay Execution · Detection rules & anomalies
- T1679 · Selective Exclusion · Detection rules & anomalies
- T1680 · Local Storage Discovery · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
- T1685.001 · Disable or Modify Windows Event Log · Detection rules & anomalies
- T1685.003 · Modify or Spoof Tool UI · Detection rules & anomalies
- T1685.005 · Clear Windows Event Logs · Detection rules & anomalies
- T1685.006 · Clear Linux or Mac System Logs · Detection rules & anomalies
- T1686 · Disable or Modify System Firewall · Detection rules & anomalies
- T1686.003 · Windows Host Firewall · Detection rules & anomalies
- T1687 · Exploitation for Defense Impairment · Detection rules & anomalies
- T1688 · Safe Mode Boot · Detection rules & anomalies
- T1689 · Downgrade Attack · Detection rules & anomalies
- T1690 · Prevent Command History Logging · Detection rules & anomalies
- T0807 · Command-Line Interface · Detection rules & anomalies
- T0809 · Data Destruction · Detection rules & anomalies
- T0817 · Drive-by Compromise · Detection rules & anomalies
- T0823 · Graphical User Interface · Detection rules & anomalies
- T0830 · Adversary-in-the-Middle · Detection rules & anomalies
- T0840 · Network Connection Enumeration · Detection rules & anomalies
- T0842 · Network Sniffing · Detection rules & anomalies
- T0846 · Remote System Discovery · Detection rules & anomalies
- T0846.001 · Port Scan · Detection rules & anomalies
- T0847 · Replication Through Removable Media · Detection rules & anomalies
- T0853 · Scripting · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0865 · Spearphishing Attachment · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T0881 · Service Stop · Detection rules & anomalies
- T0886 · Remote Services · Detection rules & anomalies
- T0888 · Remote System Information Discovery · Detection rules & anomalies
- T0893 · Data from Local System · Detection rules & anomalies
- T0894 · System Binary Proxy Execution · Detection rules & anomalies
- T0895 · Autorun Image · Detection rules & anomalies
- T1398 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1404 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1406.002 · Software Packing · Detection rules & anomalies
- T1417.002 · GUI Input Capture · Detection rules & anomalies
- T1424 · Process Discovery · Detection rules & anomalies
- T1429 · Audio Capture · Detection rules & anomalies
- T1456 · Drive-By Compromise · Detection rules & anomalies
- T1458 · Replication Through Removable Media · Detection rules & anomalies
- T1623 · Command and Scripting Interpreter · Detection rules & anomalies
- T1623.001 · Unix Shell · Detection rules & anomalies
- T1625 · Hijack Execution Flow · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- Aircrack-ng · aircrack-ng
- Arp · S0099
- AsyncRAT · S1087
- at · S0110
- attrib · S1176
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- Cachedump · S0119
- CARROTBALL · S0465
- certutil · S0160
- cipher.exe · S1205
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Diskpart · S9002
- Donut · S0695
- dsquery · S0105
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Expand · S0361
- Fgdump · S0120
- FlexiSpy · S0408
- Forfiles · S0193
- FRP · S1144
- ftp · S0095
- gsecdump · S0008
- Hashcat · hashcat
- Havij · S0224
- HTRAN · S0040
- ifconfig · S0101
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- ipconfig · S0100
- IronNetInjector · S0581
- John the Ripper · john-the-ripper
- Koadic · S0250
- LaZagne · S0349
- Lslsass · S0121
- MailSniper · S0413
- MCMD · S0500
- meek · S0175
- Mimikatz · S0002
- MimiPenguin · S0179
- Mythic · S0699
- NBTscan · S0590
- nbtstat · S0102
- Net · S0039
- netsh · S0108
- netstat · S0104
- ngrok · S0508
- Nltest · S0359
- Nmap · nmap
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- Pass-The-Hash Toolkit · S0122
- PcShare · S1050
- Peirates · S0683
- Ping · S0097
- PoshC2 · S0378
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- pwdump · S0006
- QuasarRAT · S0262
- Quick Assist · S1209
- RawDisk · S0364
- Rclone · S1040
- Reg · S0075
- Remcos · S0332
- RemoteUtilities · S0592
- Responder · S0174
- ROADTools · S0684
- route · S0103
- Rubeus · S1071
- Ruler · S0358
- schtasks · S0111
- SDelete · S0195
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- sqlmap · S0225
- Systeminfo · S0096
- Tasklist · S0057
- Tor · S0183
- TruffleHog · S9009
- UACMe · S0116
- Wevtutil · S0645
- Windows Credential Editor · S0005
- Winexe · S0191
- Xbot · S0298
- xCmd · S0123
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.