1200KM / telemetry
File Access — Detection Telemetry
Access to file objects with user, process and access-right context.
Collection and providers
Enable Audit File System plus a narrow SACL on a lab directory; on Linux select path/syscall rules and join associated Audit records.
- Windows Security auditing: Policy-dependent account, object, task and logon records on the host that performs the operation.
Configuration
- Use a lab-only GPO under Computer Configuration → Windows Settings → Security Settings → Advanced Audit Policy Configuration. Enable the specific subcategory named below.
- For object-level auditing, configure a narrow system access control list (SACL) on the test object in addition to policy. Do not audit an entire production directory by default.
- Forward Security events from the responsible host or controller; retain subject and target identities, object identifiers, result and original XML. Confirm effective policy with auditpol /get /category:*.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0055",
"collector": "illustrative-lab-collector",
"observation": {
"path": "C:\\Lab\\demo.txt",
"access": "read",
"actor": "LAB\\analyst",
"result": "success"
}
}Visibility and validation
A policy checkbox alone does not guarantee an event. Host role, SACL, success/failure selection and audit policy precedence matter. Directory changes may arrive as multiple records.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1003 · OS Credential Dumping · Detection rules & anomalies
- T1003.005 · Cached Domain Credentials · Detection rules & anomalies
- T1003.007 · Proc Filesystem · Detection rules & anomalies
- T1003.008 · /etc/passwd and /etc/shadow · Detection rules & anomalies
- T1005 · Data from Local System · Detection rules & anomalies
- T1011.001 · Exfiltration Over Bluetooth · Detection rules & anomalies
- T1016.002 · Wi-Fi Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1021.007 · Cloud Services · Detection rules & anomalies
- T1025 · Data from Removable Media · Detection rules & anomalies
- T1027.001 · Binary Padding · Detection rules & anomalies
- T1027.003 · Steganography · Detection rules & anomalies
- T1027.009 · Embedded Payloads · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1036.002 · Right-to-Left Override · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.006 · Space after Filename · Detection rules & anomalies
- T1037 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1037.001 · Logon Script (Windows) · Detection rules & anomalies
- T1039 · Data from Network Shared Drive · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1052 · Exfiltration Over Physical Medium · Detection rules & anomalies
- T1052.001 · Exfiltration over USB · Detection rules & anomalies
- T1055 · Process Injection · Detection rules & anomalies
- T1055.009 · Proc Memory · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1056.004 · Credential API Hooking · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1074 · Data Staged · Detection rules & anomalies
- T1074.001 · Local Data Staging · Detection rules & anomalies
- T1074.002 · Remote Data Staging · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087 · Account Discovery · Detection rules & anomalies
- T1087.001 · Local Account · Detection rules & anomalies
- T1091 · Replication Through Removable Media · Detection rules & anomalies
- T1110.002 · Password Cracking · Detection rules & anomalies
- T1114 · Email Collection · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1119 · Automated Collection · Detection rules & anomalies
- T1120 · Peripheral Device Discovery · Detection rules & anomalies
- T1123 · Audio Capture · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1213 · Data from Information Repositories · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1217 · Browser Information Discovery · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1480.002 · Mutual Exclusion · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1518.002 · Backup Software Discovery · Detection rules & anomalies
- T1528 · Steal Application Access Token · Detection rules & anomalies
- T1539 · Steal Web Session Cookie · Detection rules & anomalies
- T1546.005 · Trap · Detection rules & anomalies
- T1547.013 · XDG Autostart Entries · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.003 · Shell History · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1553.005 · Mark-of-the-Web Bypass · Detection rules & anomalies
- T1555 · Credentials from Password Stores · Detection rules & anomalies
- T1555.001 · Keychain · Detection rules & anomalies
- T1555.002 · Securityd Memory · Detection rules & anomalies
- T1555.003 · Credentials from Web Browsers · Detection rules & anomalies
- T1555.005 · Password Managers · Detection rules & anomalies
- T1558 · Steal or Forge Kerberos Tickets · Detection rules & anomalies
- T1558.005 · Ccache Files · Detection rules & anomalies
- T1559 · Inter-Process Communication · Detection rules & anomalies
- T1564.012 · File/Path Exclusions · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1606 · Forge Web Credentials · Detection rules & anomalies
- T1606.001 · Web Cookies · Detection rules & anomalies
- T1622 · Debugger Evasion · Detection rules & anomalies
- T1649 · Steal or Forge Authentication Certificates · Detection rules & anomalies
- T1652 · Device Driver Discovery · Detection rules & anomalies
- T1654 · Log Enumeration · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T0802 · Automated Collection · Detection rules & anomalies
- T0846 · Remote System Discovery · Detection rules & anomalies
- T0847 · Replication Through Removable Media · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0888 · Remote System Information Discovery · Detection rules & anomalies
- T0893 · Data from Local System · Detection rules & anomalies
- T1409 · Stored Application Data · Detection rules & anomalies
- T1420 · File and Directory Discovery · Detection rules & anomalies
- T1424 · Process Discovery · Detection rules & anomalies
- T1533 · Data from Local System · Detection rules & anomalies
- T1625 · Hijack Execution Flow · Detection rules & anomalies
- T1635 · Steal Application Access Token · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- Aircrack-ng · aircrack-ng
- Arp · S0099
- AsyncRAT · S1087
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- Cachedump · S0119
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Diskpart · S9002
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- FlexiSpy · S0408
- Forfiles · S0193
- ftp · S0095
- Hashcat · hashcat
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- IronNetInjector · S0581
- John the Ripper · john-the-ripper
- Koadic · S0250
- LaZagne · S0349
- MCMD · S0500
- Mimikatz · S0002
- MimiPenguin · S0179
- Mythic · S0699
- NBTscan · S0590
- Net · S0039
- ngrok · S0508
- Nltest · S0359
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- Peirates · S0683
- Ping · S0097
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Rclone · S1040
- Remcos · S0332
- RemoteUtilities · S0592
- ROADTools · S0684
- SDelete · S0195
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- Tasklist · S0057
- TruffleHog · S9009
- Wevtutil · S0645
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.