1200KM / telemetry
File Metadata — Detection Telemetry
File attributes such as path, size, timestamps, ownership and cryptographic hash.
Collection and providers
Collect scoped file inventory/FIM metadata with hash algorithm and observation time; preserve original timestamps separately from collector time.
- osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
- Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.
Configuration
- Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
- Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
- Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0059",
"collector": "illustrative-lab-collector",
"observation": {
"path": "/opt/lab/demo.txt",
"size_bytes": 64,
"sha256": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"owner_uid": 1000
}
}Visibility and validation
Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001.002 · Steganography · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.005 · Indicator Removal from Tools · Detection rules & anomalies
- T1027.006 · HTML Smuggling · Detection rules & anomalies
- T1027.008 · Stripped Payloads · Detection rules & anomalies
- T1027.009 · Embedded Payloads · Detection rules & anomalies
- T1027.011 · Fileless Storage · Detection rules & anomalies
- T1027.012 · LNK Icon Smuggling · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1036 · Masquerading · Detection rules & anomalies
- T1036.001 · Invalid Code Signature · Detection rules & anomalies
- T1036.002 · Right-to-Left Override · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1036.005 · Match Legitimate Resource Name or Location · Detection rules & anomalies
- T1036.006 · Space after Filename · Detection rules & anomalies
- T1036.008 · Masquerade File Type · Detection rules & anomalies
- T1037 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1059.011 · Lua · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1195.003 · Compromise Hardware Supply Chain · Detection rules & anomalies
- T1204.002 · Malicious File · Detection rules & anomalies
- T1204.005 · Malicious Library · Detection rules & anomalies
- T1222 · File and Directory Permissions Modification · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1222.002 · Linux and Mac Permissions · Detection rules & anomalies
- T1497.003 · Time Based Checks · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.006 · LC_LOAD_DYLIB Addition · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1546.018 · Python Startup Hooks · Detection rules & anomalies
- T1547.007 · Re-opened Applications · Detection rules & anomalies
- T1547.009 · Shortcut Modification · Detection rules & anomalies
- T1547.013 · XDG Autostart Entries · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1553 · Subvert Trust Controls · Detection rules & anomalies
- T1553.001 · Gatekeeper Bypass · Detection rules & anomalies
- T1553.002 · Code Signing · Detection rules & anomalies
- T1553.005 · Mark-of-the-Web Bypass · Detection rules & anomalies
- T1555.004 · Windows Credential Manager · Detection rules & anomalies
- T1555.005 · Password Managers · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1564.004 · NTFS File Attributes · Detection rules & anomalies
- T1564.007 · VBA Stomping · Detection rules & anomalies
- T1564.009 · Resource Forking · Detection rules & anomalies
- T1564.012 · File/Path Exclusions · Detection rules & anomalies
- T1564.014 · Extended Attributes · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1565.001 · Stored Data Manipulation · Detection rules & anomalies
- T1565.002 · Transmitted Data Manipulation · Detection rules & anomalies
- T1565.003 · Runtime Data Manipulation · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.005 · Executable Installer File Permissions Weakness · Detection rules & anomalies
- T1574.008 · Path Interception by Search Order Hijacking · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1574.010 · Services File Permissions Weakness · Detection rules & anomalies
- T1601.002 · Downgrade System Image · Detection rules & anomalies
- T1677 · Poisoned Pipeline Execution · Detection rules & anomalies
- T0849 · Masquerading · Detection rules & anomalies
- T0862 · Supply Chain Compromise · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T1398 · Boot or Logon Initialization Scripts · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AsyncRAT · S1087
- attrib · S1176
- BITSAdmin · S0190
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- cmd · S0106
- Cobalt Strike · S0154
- CSPY Downloader · S0527
- Diskpart · S9002
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Expand · S0361
- ftp · S0095
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- LaZagne · S0349
- MCMD · S0500
- Mimikatz · S0002
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- QuasarRAT · S0262
- Remcos · S0332
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.