1200KM / telemetry
Drive Creation — Detection Telemetry
Appearance or creation of a drive/device mapping on a host.
Collection and providers
Collect OS device/mount events plus read-only volume inventory; distinguish physical attachment, partition creation and logical mapping.
- osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
- Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.
Configuration
- Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
- Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
- Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0042",
"collector": "illustrative-lab-collector",
"observation": {
"device_id": "lab-disk-2",
"mount_point": "/mnt/lab",
"action": "attach"
}
}Visibility and validation
Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1025 · Data from Removable Media · Detection rules & anomalies
- T1052 · Exfiltration Over Physical Medium · Detection rules & anomalies
- T1052.001 · Exfiltration over USB · Detection rules & anomalies
- T1091 · Replication Through Removable Media · Detection rules & anomalies
- T1092 · Communication Through Removable Media · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1219.003 · Remote Access Hardware · Detection rules & anomalies
- T1674 · Input Injection · Detection rules & anomalies
- T0847 · Replication Through Removable Media · Detection rules & anomalies
- T0895 · Autorun Image · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
No reviewed association in this snapshot.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.