1200KM / telemetry
Process Metadata — Detection Telemetry
Point-in-time process properties such as owner, executable and start time.
Collection and providers
Collect read-only process inventory with PID plus start time/stable identity, command line and collection time; restrict access to potentially sensitive arguments.
- osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
- Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.
Configuration
- Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
- Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
- Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0034",
"collector": "illustrative-lab-collector",
"observation": {
"process_id": 4200,
"image": "/usr/bin/sleep",
"owner_uid": 1000,
"started_at": "2026-09-27T11:59:00Z"
}
}Visibility and validation
Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001.003 · Protocol or Service Impersonation · Detection rules & anomalies
- T1003 · OS Credential Dumping · Detection rules & anomalies
- T1027.014 · Polymorphic Code · Detection rules & anomalies
- T1036 · Masquerading · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.011 · Overwrite Process Arguments · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.008 · Ptrace System Calls · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127 · Trusted Developer Utilities Proxy Execution · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1127.002 · ClickOnce · Detection rules & anomalies
- T1127.003 · JamPlus · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1134.004 · Parent PID Spoofing · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1548.001 · Setuid and Setgid · Detection rules & anomalies
- T1548.003 · Sudo and Sudo Caching · Detection rules & anomalies
- T1552.003 · Shell History · Detection rules & anomalies
- T1563.001 · SSH Hijacking · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1564.013 · Bind Mounts · Detection rules & anomalies
- T1574.006 · Dynamic Linker Hijacking · Detection rules & anomalies
- T1687 · Exploitation for Defense Impairment · Detection rules & anomalies
- T1689 · Downgrade Attack · Detection rules & anomalies
- T0849 · Masquerading · Detection rules & anomalies
- T0853 · Scripting · Detection rules & anomalies
- T0874 · Hooking · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AsyncRAT · S1087
- BloodHound · S0521
- Brute Ratel C4 · S1063
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- DCRAT · S9017
- Donut · S0695
- Empire · S0363
- HTRAN · S0040
- Imminent Monitor · S0434
- IronNetInjector · S0581
- Koadic · S0250
- MCMD · S0500
- Mimikatz · S0002
- Net · S0039
- NPPSPY · S1131
- PcShare · S1050
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Remcos · S0332
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- Tasklist · S0057
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.