1200KM / telemetry
Windows Registry Key Modification — Detection Telemetry
Registry value changes or registry object renames.
Collection and providers
Use RegistryEvent 13 for value-set and 14 for rename; compare against intended policy and keep original type/value where available.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- Keep this Windows-specific source separate from other operating systems; there is no direct cross-platform event-ID equivalence.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0063",
"collector": "illustrative-lab-collector",
"observation": {
"registry_path": "HKCU\\Software\\Lab\\Mode",
"event_type": "SetValue",
"value_type": "DWORD",
"value": 1
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1003.001 · LSASS Memory · Detection rules & anomalies
- T1003.002 · Security Account Manager · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1027.011 · Fileless Storage · Detection rules & anomalies
- T1037 · Boot or Logon Initialization Scripts · Detection rules & anomalies
- T1053.005 · Scheduled Task · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1070 · Indicator Removal · Detection rules & anomalies
- T1070.007 · Clear Network Connection History and Configurations · Detection rules & anomalies
- T1070.009 · Clear Persistence · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1111 · Multi-Factor Authentication Interception · Detection rules & anomalies
- T1112 · Modify Registry · Detection rules & anomalies
- T1137 · Office Application Startup · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1137.002 · Office Test · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1218.003 · CMSTP · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.012 · Verclsid · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1219 · Remote Access Tools · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1490 · Inhibit System Recovery · Detection rules & anomalies
- T1505.005 · Terminal Services DLL · Detection rules & anomalies
- T1518.002 · Backup Software Discovery · Detection rules & anomalies
- T1543 · Create or Modify System Process · Detection rules & anomalies
- T1543.003 · Windows Service · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.001 · Change Default File Association · Detection rules & anomalies
- T1546.002 · Screensaver · Detection rules & anomalies
- T1546.007 · Netsh Helper DLL · Detection rules & anomalies
- T1546.008 · Accessibility Features · Detection rules & anomalies
- T1546.009 · AppCert DLLs · Detection rules & anomalies
- T1546.010 · AppInit DLLs · Detection rules & anomalies
- T1546.011 · Application Shimming · Detection rules & anomalies
- T1546.012 · Image File Execution Options Injection · Detection rules & anomalies
- T1546.015 · Component Object Model Hijacking · Detection rules & anomalies
- T1547 · Boot or Logon Autostart Execution · Detection rules & anomalies
- T1547.001 · Registry Run Keys / Startup Folder · Detection rules & anomalies
- T1547.002 · Authentication Package · Detection rules & anomalies
- T1547.003 · Time Providers · Detection rules & anomalies
- T1547.004 · Winlogon Helper DLL · Detection rules & anomalies
- T1547.005 · Security Support Provider · Detection rules & anomalies
- T1547.008 · LSASS Driver · Detection rules & anomalies
- T1547.010 · Port Monitors · Detection rules & anomalies
- T1547.012 · Print Processors · Detection rules & anomalies
- T1547.014 · Active Setup · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.002 · Credentials in Registry · Detection rules & anomalies
- T1553 · Subvert Trust Controls · Detection rules & anomalies
- T1553.003 · SIP and Trust Provider Hijacking · Detection rules & anomalies
- T1553.004 · Install Root Certificate · Detection rules & anomalies
- T1553.006 · Code Signing Policy Modification · Detection rules & anomalies
- T1556 · Modify Authentication Process · Detection rules & anomalies
- T1556.002 · Password Filter DLL · Detection rules & anomalies
- T1556.008 · Network Provider DLL · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.002 · Hidden Users · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1564.005 · Hidden File System · Detection rules & anomalies
- T1564.006 · Run Virtual Instance · Detection rules & anomalies
- T1565.003 · Runtime Data Manipulation · Detection rules & anomalies
- T1569 · System Services · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1574 · Hijack Execution Flow · Detection rules & anomalies
- T1574.001 · DLL · Detection rules & anomalies
- T1574.007 · Path Interception by PATH Environment Variable · Detection rules & anomalies
- T1574.009 · Path Interception by Unquoted Path · Detection rules & anomalies
- T1574.011 · Services Registry Permissions Weakness · Detection rules & anomalies
- T1574.012 · COR_PROFILER · Detection rules & anomalies
- T1652 · Device Driver Discovery · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
- T1685.001 · Disable or Modify Windows Event Log · Detection rules & anomalies
- T1686 · Disable or Modify System Firewall · Detection rules & anomalies
- T1686.003 · Windows Host Firewall · Detection rules & anomalies
- T1688 · Safe Mode Boot · Detection rules & anomalies
- T1689 · Downgrade Attack · Detection rules & anomalies
- T0830 · Adversary-in-the-Middle · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T0881 · Service Stop · Detection rules & anomalies
- T1692.002 · Reporting Message · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AsyncRAT · S1087
- Brute Ratel C4 · S1063
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Diskpart · S9002
- Donut · S0695
- dsquery · S0105
- Empire · S0363
- evilginx2 · S9003
- Fgdump · S0120
- gsecdump · S0008
- Imminent Monitor · S0434
- Impacket · S0357
- IronNetInjector · S0581
- Koadic · S0250
- LaZagne · S0349
- Lslsass · S0121
- MCMD · S0500
- Mimikatz · S0002
- Net · S0039
- netsh · S0108
- NPPSPY · S1131
- Pacu · S1091
- PcShare · S1050
- PoshC2 · S0378
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- pwdump · S0006
- QuasarRAT · S0262
- Reg · S0075
- Remcos · S0332
- Responder · S0174
- schtasks · S0111
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- Systeminfo · S0096
- UACMe · S0116
- Wevtutil · S0645
- Windows Credential Editor · S0005
- Winexe · S0191
- xCmd · S0123
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.