1200KM / telemetry
File Modification — Detection Telemetry
Changes to file data or attributes.
Collection and providers
Use file-integrity monitoring or scoped OS file-write auditing for general changes. Sysmon 2 records creation-time changes; it is not a general file-write event.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
- Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
- Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0061",
"collector": "illustrative-lab-collector",
"observation": {
"path": "C:\\Lab\\demo.txt",
"attribute": "content_hash",
"before": "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
"after": "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb"
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1003.003 · NTDS · Detection rules & anomalies
- T1003.004 · LSA Secrets · Detection rules & anomalies
- T1003.007 · Proc Filesystem · Detection rules & anomalies
- T1014 · Rootkit · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.008 · Stripped Payloads · Detection rules & anomalies
- T1027.009 · Embedded Payloads · Detection rules & anomalies
- T1027.014 · Polymorphic Code · Detection rules & anomalies
- T1027.015 · Compression · Detection rules & anomalies
- T1027.017 · SVG Smuggling · Detection rules & anomalies
- T1036 · Masquerading · Detection rules & anomalies
- T1036.001 · Invalid Code Signature · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1037 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1037.002 · Login Hook · Detection rules & anomalies
- T1037.004 · RC Scripts · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1053 · Scheduled Task/Job · Detection rules & anomalies
- T1053.002 · At · Detection rules & anomalies
- T1053.003 · Cron · Detection rules & anomalies
- T1055.009 · Proc Memory · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.003 · Web Portal Capture · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.003 · Clear Command History · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1070.007 · Clear Network Connection History and Configurations · Detection rules & anomalies
- T1070.008 · Clear Mailbox Data · Detection rules & anomalies
- T1070.010 · Relocate Malware · Detection rules & anomalies
- T1080 · Taint Shared Content · Detection rules & anomalies
- T1098 · Account Manipulation · Detection rules & anomalies
- T1098.004 · SSH Authorized Keys · Detection rules & anomalies
- T1114.003 · Email Forwarding Rule · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1136 · Create Account · Detection rules & anomalies
- T1136.001 · Local Account · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1187 · Forced Authentication · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1222.002 · Linux and Mac Permissions · Detection rules & anomalies
- T1484 · Domain or Tenant Policy Modification · Detection rules & anomalies
- T1484.001 · Group Policy Modification · Detection rules & anomalies
- T1486 · Data Encrypted for Impact · Detection rules & anomalies
- T1491 · Defacement · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1491.002 · External Defacement · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.003 · Web Shell · Detection rules & anomalies
- T1505.004 · IIS Components · Detection rules & anomalies
- T1505.006 · vSphere Installation Bundles · Detection rules & anomalies
- T1539 · Steal Web Session Cookie · Detection rules & anomalies
- T1542 · Pre-OS Boot · Detection rules & anomalies
- T1542.003 · Bootkit · Detection rules & anomalies
- T1543 · Create or Modify System Process · Detection rules & anomalies
- T1543.001 · Launch Agent · Detection rules & anomalies
- T1543.002 · Systemd Service · Detection rules & anomalies
- T1543.004 · Launch Daemon · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.004 · Unix Shell Configuration Modification · Detection rules & anomalies
- T1546.005 · Trap · Detection rules & anomalies
- T1546.006 · LC_LOAD_DYLIB Addition · Detection rules & anomalies
- T1546.013 · PowerShell Profile · Detection rules & anomalies
- T1546.014 · Emond · Detection rules & anomalies
- T1546.017 · Udev Rules · Detection rules & anomalies
- T1546.018 · Python Startup Hooks · Detection rules & anomalies
- T1547 · Boot or Logon Autostart Execution · Detection rules & anomalies
- T1547.006 · Kernel Modules and Extensions · Detection rules & anomalies
- T1547.007 · Re-opened Applications · Detection rules & anomalies
- T1547.008 · LSASS Driver · Detection rules & anomalies
- T1547.009 · Shortcut Modification · Detection rules & anomalies
- T1547.015 · Login Items · Detection rules & anomalies
- T1548.003 · Sudo and Sudo Caching · Detection rules & anomalies
- T1548.006 · TCC Manipulation · Detection rules & anomalies
- T1553.001 · Gatekeeper Bypass · Detection rules & anomalies
- T1553.003 · SIP and Trust Provider Hijacking · Detection rules & anomalies
- T1553.004 · Install Root Certificate · Detection rules & anomalies
- T1554 · Compromise Host Software Binary · Detection rules & anomalies
- T1556 · Modify Authentication Process · Detection rules & anomalies
- T1556.001 · Domain Controller Authentication · Detection rules & anomalies
- T1556.003 · Pluggable Authentication Modules · Detection rules & anomalies
- T1556.004 · Network Device Authentication · Detection rules & anomalies
- T1556.006 · Multi-Factor Authentication · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1564.002 · Hidden Users · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1564.005 · Hidden File System · Detection rules & anomalies
- T1564.006 · Run Virtual Instance · Detection rules & anomalies
- T1564.008 · Email Hiding Rules · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1565.001 · Stored Data Manipulation · Detection rules & anomalies
- T1565.003 · Runtime Data Manipulation · Detection rules & anomalies
- T1569 · System Services · Detection rules & anomalies
- T1569.001 · Launchctl · Detection rules & anomalies
- T1569.003 · Systemctl · Detection rules & anomalies
- T1574 · Hijack Execution Flow · Detection rules & anomalies
- T1574.004 · Dylib Hijacking · Detection rules & anomalies
- T1574.006 · Dynamic Linker Hijacking · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1600 · Weaken Encryption · Detection rules & anomalies
- T1600.001 · Reduce Key Space · Detection rules & anomalies
- T1600.002 · Disable Crypto Hardware · Detection rules & anomalies
- T1601 · Modify System Image · Detection rules & anomalies
- T1601.001 · Patch System Image · Detection rules & anomalies
- T1601.002 · Downgrade System Image · Detection rules & anomalies
- T1602.001 · SNMP (MIB Dump) · Detection rules & anomalies
- T1647 · Plist File Modification · Detection rules & anomalies
- T1653 · Power Settings · Detection rules & anomalies
- T1657 · Financial Theft · Detection rules & anomalies
- T1679 · Selective Exclusion · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T1685.004 · Disable or Modify Linux Audit System Log · Detection rules & anomalies
- T1685.006 · Clear Linux or Mac System Logs · Detection rules & anomalies
- T0809 · Data Destruction · Detection rules & anomalies
- T0849 · Masquerading · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T0873 · Project File Infection · Detection rules & anomalies
- T0873.001 · Siemens Project File Format · Detection rules & anomalies
- T0881 · Service Stop · Detection rules & anomalies
- T1398 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1406.001 · Steganography · Detection rules & anomalies
- T1582 · SMS Control · Detection rules & anomalies
- T1616 · Call Control · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AsyncRAT · S1087
- at · S0110
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- CrackMapExec · S0488
- CSPY Downloader · S0527
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Fgdump · S0120
- gsecdump · S0008
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- Koadic · S0250
- LaZagne · S0349
- MCMD · S0500
- Mimikatz · S0002
- MimiPenguin · S0179
- Net · S0039
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- PowerSploit · S0194
- Pupy · S0192
- pwdump · S0006
- QuasarRAT · S0262
- Remcos · S0332
- SDelete · S0195
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.