1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / telemetry

Drive Creation — Detection Telemetry

Appearance or creation of a drive/device mapping on a host.

Collection and providers

Collect OS device/mount events plus read-only volume inventory; distinguish physical attachment, partition creation and logical mapping.

  • osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
  • Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.

Configuration

  • Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
  • Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
  • Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.

Synthetic event example

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0042",
  "collector": "illustrative-lab-collector",
  "observation": {
    "device_id": "lab-disk-2",
    "mount_point": "/mnt/lab",
    "action": "attach"
  }
}

Visibility and validation

Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.

  • Record the lab scope, collector version, effective configuration and expected source fields before testing.
  • Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
  • Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
  • Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.

Primary sources

Connected ecosystem references

Linked tags

Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.

Attack tools through shared TTPs

These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.

No reviewed association in this snapshot.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.