1200KM / telemetry
Application Log Content — Detection Telemetry
Application-emitted audit or operational event content.
Collection and providers
Select the application event family required by the detection and document its native schema before normalization.
- Application audit logs: First-party service events and request/result fields; schema is application-specific.
- OpenTelemetry-compatible log pipelines: Transport and normalization of emitted records; do not create missing audit instrumentation.
Configuration
- Enable the application audit category or instrument the owned lab application at the authorization/action boundary.
- Define a schema with timestamp, service, actor, object, action, result and correlation ID. Export structured records through an authenticated collector.
- Redact secrets and personal content, separate audit from debug logs, set retention and verify delivery during rotation/restart.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0038",
"collector": "illustrative-lab-collector",
"observation": {
"service": "lab-portal",
"action": "export_requested",
"actor": "lab-reader",
"record_count": 3,
"result": "authorized"
}
}Visibility and validation
Debug output is not necessarily a durable audit trail. Application developers must emit the relevant event; installing a log pipeline does not make an absent event exist.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.008 · Clear Mailbox Data · Detection rules & anomalies
- T1072 · Software Deployment Tools · Detection rules & anomalies
- T1087.003 · Email Account · Detection rules & anomalies
- T1087.004 · Cloud Account · Detection rules & anomalies
- T1098.002 · Additional Email Delegate Permissions · Detection rules & anomalies
- T1098.005 · Device Registration · Detection rules & anomalies
- T1114 · Email Collection · Detection rules & anomalies
- T1114.002 · Remote Email Collection · Detection rules & anomalies
- T1114.003 · Email Forwarding Rule · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1132.002 · Non-Standard Encoding · Detection rules & anomalies
- T1133 · External Remote Services · Detection rules & anomalies
- T1137 · Office Application Startup · Detection rules & anomalies
- T1137.003 · Outlook Forms · Detection rules & anomalies
- T1137.004 · Outlook Home Page · Detection rules & anomalies
- T1137.005 · Outlook Rules · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1189 · Drive-by Compromise · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1199 · Trusted Relationship · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1211 · Exploitation for Stealth · Detection rules & anomalies
- T1212 · Exploitation for Credential Access · Detection rules & anomalies
- T1213 · Data from Information Repositories · Detection rules & anomalies
- T1213.001 · Confluence · Detection rules & anomalies
- T1213.002 · Sharepoint · Detection rules & anomalies
- T1213.003 · Code Repositories · Detection rules & anomalies
- T1213.004 · Customer Relationship Management Software · Detection rules & anomalies
- T1213.005 · Messaging Applications · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1484 · Domain or Tenant Policy Modification · Detection rules & anomalies
- T1484.002 · Trust Modification · Detection rules & anomalies
- T1491 · Defacement · Detection rules & anomalies
- T1496 · Resource Hijacking · Detection rules & anomalies
- T1496.003 · SMS Pumping · Detection rules & anomalies
- T1496.004 · Cloud Service Hijacking · Detection rules & anomalies
- T1499 · Endpoint Denial of Service · Detection rules & anomalies
- T1499.002 · Service Exhaustion Flood · Detection rules & anomalies
- T1499.003 · Application Exhaustion Flood · Detection rules & anomalies
- T1499.004 · Application or System Exploitation · Detection rules & anomalies
- T1505 · Server Software Component · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.004 · IIS Components · Detection rules & anomalies
- T1505.006 · vSphere Installation Bundles · Detection rules & anomalies
- T1518 · Software Discovery · Detection rules & anomalies
- T1528 · Steal Application Access Token · Detection rules & anomalies
- T1534 · Internal Spearphishing · Detection rules & anomalies
- T1537 · Transfer Data to Cloud Account · Detection rules & anomalies
- T1538 · Cloud Service Dashboard · Detection rules & anomalies
- T1539 · Steal Web Session Cookie · Detection rules & anomalies
- T1548.005 · Temporary Elevated Cloud Access · Detection rules & anomalies
- T1550 · Use Alternate Authentication Material · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.007 · Container API · Detection rules & anomalies
- T1552.008 · Chat Messages · Detection rules & anomalies
- T1556.006 · Multi-Factor Authentication · Detection rules & anomalies
- T1556.007 · Hybrid Identity · Detection rules & anomalies
- T1556.009 · Conditional Access Policies · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1557.003 · DHCP Spoofing · Detection rules & anomalies
- T1557.004 · Evil Twin · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.008 · Email Hiding Rules · Detection rules & anomalies
- T1566 · Phishing · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1566.004 · Spearphishing Voice · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1594 · Search Victim-Owned Websites · Detection rules & anomalies
- T1598 · Phishing for Information · Detection rules & anomalies
- T1598.001 · Spearphishing Service · Detection rules & anomalies
- T1598.002 · Spearphishing Attachment · Detection rules & anomalies
- T1598.003 · Spearphishing Link · Detection rules & anomalies
- T1598.004 · Spearphishing Voice · Detection rules & anomalies
- T1610 · Deploy Container · Detection rules & anomalies
- T1621 · Multi-Factor Authentication Request Generation · Detection rules & anomalies
- T1648 · Serverless Execution · Detection rules & anomalies
- T1649 · Steal or Forge Authentication Certificates · Detection rules & anomalies
- T1657 · Financial Theft · Detection rules & anomalies
- T1667 · Email Bombing · Detection rules & anomalies
- T1671 · Cloud Application Integration · Detection rules & anomalies
- T1675 · ESXi Administration Command · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T1684.001 · Impersonation · Detection rules & anomalies
- T1684.002 · Email Spoofing · Detection rules & anomalies
- T1685.001 · Disable or Modify Windows Event Log · Detection rules & anomalies
- T1685.005 · Clear Windows Event Logs · Detection rules & anomalies
- T1687 · Exploitation for Defense Impairment · Detection rules & anomalies
- T0800 · Activate Firmware Update Mode · Detection rules & anomalies
- T0801 · Monitor Process State · Detection rules & anomalies
- T0806 · Brute Force I/O · Detection rules & anomalies
- T0807 · Command-Line Interface · Detection rules & anomalies
- T0811 · Data from Information Repositories · Detection rules & anomalies
- T0814 · Denial of Service · Detection rules & anomalies
- T0816 · Device Restart/Shutdown · Detection rules & anomalies
- T0817 · Drive-by Compromise · Detection rules & anomalies
- T0819 · Exploit Public-Facing Application · Detection rules & anomalies
- T0820 · Exploitation for Evasion · Detection rules & anomalies
- T0821 · Modify Controller Tasking · Detection rules & anomalies
- T0822 · External Remote Services · Detection rules & anomalies
- T0830 · Adversary-in-the-Middle · Detection rules & anomalies
- T0836 · Modify Parameter · Detection rules & anomalies
- T0838 · Modify Alarm Settings · Detection rules & anomalies
- T0843 · Program Download · Detection rules & anomalies
- T0843.001 · Download All · Detection rules & anomalies
- T0843.002 · Online Edit · Detection rules & anomalies
- T0843.003 · Program Append · Detection rules & anomalies
- T0845 · Program Upload · Detection rules & anomalies
- T0848 · Rogue Master · Detection rules & anomalies
- T0858 · Change Operating Mode · Detection rules & anomalies
- T0860 · Wireless Compromise · Detection rules & anomalies
- T0861 · Point & Tag Identification · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0864 · Transient Cyber Asset · Detection rules & anomalies
- T0865 · Spearphishing Attachment · Detection rules & anomalies
- T0866 · Exploitation of Remote Services · Detection rules & anomalies
- T0889 · Modify Program · Detection rules & anomalies
- T0890 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1691 · Block Operational Technology Message · Detection rules & anomalies
- T1691.001 · Command Message · Detection rules & anomalies
- T1691.002 · Reporting Message · Detection rules & anomalies
- T1692.001 · Command Message · Detection rules & anomalies
- T1693 · Modify Firmware · Detection rules & anomalies
- T1693.001 · System Firmware · Detection rules & anomalies
- T1693.002 · Module Firmware · Detection rules & anomalies
- T1695 · Block Communications · Detection rules & anomalies
- T1695.001 · Serial COM · Detection rules & anomalies
- T1695.002 · Ethernet · Detection rules & anomalies
- T1695.003 · Wi-Fi · Detection rules & anomalies
- T1409 · Stored Application Data · Detection rules & anomalies
- T1414 · Clipboard Data · Detection rules & anomalies
- T1417 · Input Capture · Detection rules & anomalies
- T1417.001 · Keylogging · Detection rules & anomalies
- T1417.002 · GUI Input Capture · Detection rules & anomalies
- T1418 · Software Discovery · Detection rules & anomalies
- T1418.001 · Security Software Discovery · Detection rules & anomalies
- T1420 · File and Directory Discovery · Detection rules & anomalies
- T1424 · Process Discovery · Detection rules & anomalies
- T1635 · Steal Application Access Token · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AsyncRAT · S1087
- Brute Ratel C4 · S1063
- Cobalt Strike · S0154
- Covenant · S1155
- CSPY Downloader · S0527
- DCRAT · S9017
- Donut · S0695
- Empire · S0363
- evilginx2 · S9003
- FlexiSpy · S0408
- FRP · S1144
- Havij · S0224
- Koadic · S0250
- MailSniper · S0413
- Mimikatz · S0002
- Mythic · S0699
- ngrok · S0508
- NPPSPY · S1131
- Pacu · S1091
- Peirates · S0683
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Remcos · S0332
- ROADTools · S0684
- Ruler · S0358
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- spwebmember · S0227
- sqlmap · S0225
- Tor · S0183
- TruffleHog · S9009
- Wevtutil · S0645
- Xbot · S0298
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.