1200KM / telemetry
File Creation — Detection Telemetry
Creation or overwrite of a file at an observed path.
Collection and providers
Scope Sysmon FileCreate (11) to the lab directory; retain the process and file path. Differentiate creation/overwrite if the sensor can.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
- Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
- Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0039",
"collector": "illustrative-lab-collector",
"observation": {
"process_id": 4200,
"path": "C:\\Lab\\demo.txt",
"action": "create",
"size_bytes": 64
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001.002 · Steganography · Detection rules & anomalies
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1011.001 · Exfiltration Over Bluetooth · Detection rules & anomalies
- T1014 · Rootkit · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.001 · Binary Padding · Detection rules & anomalies
- T1027.004 · Compile After Delivery · Detection rules & anomalies
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1027.006 · HTML Smuggling · Detection rules & anomalies
- T1027.008 · Stripped Payloads · Detection rules & anomalies
- T1027.009 · Embedded Payloads · Detection rules & anomalies
- T1027.011 · Fileless Storage · Detection rules & anomalies
- T1027.014 · Polymorphic Code · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1027.016 · Junk Code Insertion · Detection rules & anomalies
- T1027.017 · SVG Smuggling · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.007 · Double File Extension · Detection rules & anomalies
- T1036.008 · Masquerade File Type · Detection rules & anomalies
- T1037.004 · RC Scripts · Detection rules & anomalies
- T1037.005 · Startup Items · Detection rules & anomalies
- T1039 · Data from Network Shared Drive · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1052 · Exfiltration Over Physical Medium · Detection rules & anomalies
- T1052.001 · Exfiltration over USB · Detection rules & anomalies
- T1053 · Scheduled Task/Job · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1053.006 · Systemd Timers · Detection rules & anomalies
- T1055.002 · Portable Executable Injection · Detection rules & anomalies
- T1055.013 · Process Doppelgänging · Detection rules & anomalies
- T1056.003 · Web Portal Capture · Detection rules & anomalies
- T1059.010 · AutoHotKey & AutoIT · Detection rules & anomalies
- T1059.011 · Lua · Detection rules & anomalies
- T1070.010 · Relocate Malware · Detection rules & anomalies
- T1074 · Data Staged · Detection rules & anomalies
- T1074.001 · Local Data Staging · Detection rules & anomalies
- T1074.002 · Remote Data Staging · Detection rules & anomalies
- T1080 · Taint Shared Content · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1091 · Replication Through Removable Media · Detection rules & anomalies
- T1092 · Communication Through Removable Media · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1110.002 · Password Cracking · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127 · Trusted Developer Utilities Proxy Execution · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1127.003 · JamPlus · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1137 · Office Application Startup · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1137.002 · Office Test · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1176.002 · IDE Extensions · Detection rules & anomalies
- T1187 · Forced Authentication · Detection rules & anomalies
- T1189 · Drive-by Compromise · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1202 · Indirect Command Execution · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1204.001 · Malicious Link · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1204.004 · Malicious Copy and Paste · Detection rules & anomalies
- T1204.005 · Malicious Library · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1216 · System Script Proxy Execution · Detection rules & anomalies
- T1217 · Browser Information Discovery · Detection rules & anomalies
- T1218.001 · Compiled HTML File · Detection rules & anomalies
- T1218.002 · Control Panel · Detection rules & anomalies
- T1218.003 · CMSTP · Detection rules & anomalies
- T1218.004 · InstallUtil · Detection rules & anomalies
- T1218.005 · Mshta · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1218.013 · Mavinject · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1218.015 · Electron Applications · Detection rules & anomalies
- T1219 · Remote Access Tools · Detection rules & anomalies
- T1219.001 · IDE Tunneling · Detection rules & anomalies
- T1219.002 · Remote Desktop Software · Detection rules & anomalies
- T1222 · File and Directory Permissions Modification · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.002 · Mutual Exclusion · Detection rules & anomalies
- T1484.001 · Group Policy Modification · Detection rules & anomalies
- T1485 · Data Destruction · Detection rules & anomalies
- T1486 · Data Encrypted for Impact · Detection rules & anomalies
- T1491 · Defacement · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1491.002 · External Defacement · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.003 · Web Shell · Detection rules & anomalies
- T1505.004 · IIS Components · Detection rules & anomalies
- T1505.005 · Terminal Services DLL · Detection rules & anomalies
- T1518.002 · Backup Software Discovery · Detection rules & anomalies
- T1542 · Pre-OS Boot · Detection rules & anomalies
- T1542.001 · System Firmware · Detection rules & anomalies
- T1542.003 · Bootkit · Detection rules & anomalies
- T1543.001 · Launch Agent · Detection rules & anomalies
- T1543.002 · Systemd Service · Detection rules & anomalies
- T1543.004 · Launch Daemon · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1546.011 · Application Shimming · Detection rules & anomalies
- T1546.013 · PowerShell Profile · Detection rules & anomalies
- T1546.014 · Emond · Detection rules & anomalies
- T1546.016 · Installer Packages · Detection rules & anomalies
- T1547 · Boot or Logon Autostart Execution · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.003 · Time Providers · Detection rules & anomalies
- T1547.006 · Kernel Modules and Extensions · Detection rules & anomalies
- T1547.008 · LSASS Driver · Detection rules & anomalies
- T1547.009 · Shortcut Modification · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.012 · Print Processors · Detection rules & anomalies
- T1547.013 · XDG Autostart Entries · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.003 · Shell History · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1552.006 · Group Policy Preferences · Detection rules & anomalies
- T1553 · Subvert Trust Controls · Detection rules & anomalies
- T1553.005 · Mark-of-the-Web Bypass · Detection rules & anomalies
- T1554 · Compromise Host Software Binary · Detection rules & anomalies
- T1556.002 · Password Filter DLL · Detection rules & anomalies
- T1556.008 · Network Provider DLL · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1560.002 · Archive via Library · Detection rules & anomalies
- T1560.003 · Archive via Custom Method · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1564.004 · NTFS File Attributes · Detection rules & anomalies
- T1564.006 · Run Virtual Instance · Detection rules & anomalies
- T1564.007 · VBA Stomping · Detection rules & anomalies
- T1564.012 · File/Path Exclusions · Detection rules & anomalies
- T1564.013 · Bind Mounts · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1565.001 · Stored Data Manipulation · Detection rules & anomalies
- T1565.003 · Runtime Data Manipulation · Detection rules & anomalies
- T1566 · Phishing · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
- T1574 · Hijack Execution Flow · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.004 · Dylib Hijacking · Detection rules & anomalies
- T1574.005 · Executable Installer File Permissions Weakness · Detection rules & anomalies
- T1574.006 · Dynamic Linker Hijacking · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1574.008 · Path Interception by Search Order Hijacking · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1574.010 · Services File Permissions Weakness · Detection rules & anomalies
- T1574.012 · COR_PROFILER · Detection rules & anomalies
- T1574.014 · AppDomainManager · Detection rules & anomalies
- T1606.001 · Web Cookies · Detection rules & anomalies
- T1611 · Escape to Host · Detection rules & anomalies
- T1659 · Content Injection · Detection rules & anomalies
- T1667 · Email Bombing · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T0817 · Drive-by Compromise · Detection rules & anomalies
- T0847 · Replication Through Removable Media · Detection rules & anomalies
- T0865 · Spearphishing Attachment · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T1406 · Obfuscated Files or Information · Detection rules & anomalies
- T1406.001 · Steganography · Detection rules & anomalies
- T1406.002 · Software Packing · Detection rules & anomalies
- T1407 · Download New Code at Runtime · Detection rules & anomalies
- T1409 · Stored Application Data · Detection rules & anomalies
- T1414 · Clipboard Data · Detection rules & anomalies
- T1417 · Input Capture · Detection rules & anomalies
- T1417.001 · Keylogging · Detection rules & anomalies
- T1417.002 · GUI Input Capture · Detection rules & anomalies
- T1418 · Software Discovery · Detection rules & anomalies
- T1418.001 · Security Software Discovery · Detection rules & anomalies
- T1456 · Drive-By Compromise · Detection rules & anomalies
- T1458 · Replication Through Removable Media · Detection rules & anomalies
- T1474.003 · Compromise Software Supply Chain · Detection rules & anomalies
- T1481 · Web Service · Detection rules & anomalies
- T1481.002 · Bidirectional Communication · Detection rules & anomalies
- T1512 · Video Capture · Detection rules & anomalies
- T1521 · Encrypted Channel · Detection rules & anomalies
- T1521.001 · Symmetric Cryptography · Detection rules & anomalies
- T1521.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1532 · Archive Collected Data · Detection rules & anomalies
- T1544 · Ingress Tool Transfer · Detection rules & anomalies
- T1577 · Compromise Application Executable · Detection rules & anomalies
- T1629.003 · Disable or Modify Tools · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- Aircrack-ng · aircrack-ng
- AsyncRAT · S1087
- attrib · S1176
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- Diskpart · S9002
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Expand · S0361
- Fgdump · S0120
- FlexiSpy · S0408
- Forfiles · S0193
- ftp · S0095
- gsecdump · S0008
- Hashcat · hashcat
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- IronNetInjector · S0581
- John the Ripper · john-the-ripper
- Koadic · S0250
- LaZagne · S0349
- Lslsass · S0121
- MCMD · S0500
- Mimikatz · S0002
- Mythic · S0699
- Net · S0039
- ngrok · S0508
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- Peirates · S0683
- PoshC2 · S0378
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- pwdump · S0006
- QuasarRAT · S0262
- Quick Assist · S1209
- RawDisk · S0364
- Rclone · S1040
- Remcos · S0332
- RemoteUtilities · S0592
- ROADTools · S0684
- schtasks · S0111
- SDelete · S0195
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- TruffleHog · S9009
- Wevtutil · S0645
- Windows Credential Editor · S0005
- Xbot · S0298
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.