1200KM / telemetry
Command Execution — Detection Telemetry
Execution of a command and its interpreter or parent context.
Collection and providers
Collect process command lines and relevant shell/interpreter audit; shell history alone is neither complete nor tamper-resistant.
- PowerShell Script Block Logging: Script content via event 4104 when configured; channel depends on PowerShell edition.
- Sysmon process events: Interpreter launch and parent context, not full script content.
- Linux Audit: execve-family execution context; shell built-ins need additional instrumentation.
Configuration
- Enable Script Block Logging through the policy/configuration for the installed edition. Forward Microsoft-Windows-PowerShell/Operational for Windows PowerShell, or PowerShellCore/Operational for PowerShell 7.
- Retain script-block ID and fragment ordering alongside process creation. Protect access to collected script text; secrets may be included.
- On Linux, use narrowly scoped Audit execution rules for the lab account and supported architectures, and retain joined SYSCALL/EXECVE/PATH records.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0064",
"collector": "illustrative-lab-collector",
"observation": {
"interpreter": "/bin/sh",
"command_line": "printf LAB_TELEMETRY_CHECK",
"actor_uid": 1000,
"session_id": "lab-session-1"
}
}Visibility and validation
Script content and process command lines are different signals. Logging may be partial, fragmented, filtered or disabled; never assume a command line reveals everything executed.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1005 · Data from Local System · Detection rules & anomalies
- T1006 · Direct Volume Access · Detection rules & anomalies
- T1007 · System Service Discovery · Detection rules & anomalies
- T1010 · Application Window Discovery · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1011.001 · Exfiltration Over Bluetooth · Detection rules & anomalies
- T1012 · Query Registry · Detection rules & anomalies
- T1016 · System Network Configuration Discovery · Detection rules & anomalies
- T1016.001 · Internet Connection Discovery · Detection rules & anomalies
- T1016.002 · Wi-Fi Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1021 · Remote Services · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1021.007 · Cloud Services · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.010 · Command Obfuscation · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1033 · System Owner/User Discovery · Detection rules & anomalies
- T1036 · Masquerading · Detection rules & anomalies
- T1036.001 · Invalid Code Signature · Detection rules & anomalies
- T1036.002 · Right-to-Left Override · Detection rules & anomalies
- T1036.003 · Rename Legitimate Utilities · Detection rules & anomalies
- T1037.004 · RC Scripts · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1052 · Exfiltration Over Physical Medium · Detection rules & anomalies
- T1053 · Scheduled Task/Job · Detection rules & anomalies
- T1053.002 · At · Detection rules & anomalies
- T1056.002 · GUI Input Capture · Detection rules & anomalies
- T1057 · Process Discovery · Detection rules & anomalies
- T1059 · Command and Scripting Interpreter · Detection rules & anomalies
- T1059.001 · PowerShell · Detection rules & anomalies
- T1059.004 · Unix Shell · Detection rules & anomalies
- T1059.005 · Visual Basic · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.007 · JavaScript · Detection rules & anomalies
- T1059.008 · Network Device CLI · Detection rules & anomalies
- T1059.009 · Cloud API · Detection rules & anomalies
- T1059.011 · Lua · Detection rules & anomalies
- T1059.012 · Hypervisor CLI · Detection rules & anomalies
- T1059.013 · Container CLI/API · Detection rules & anomalies
- T1069 · Permission Groups Discovery · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1069.003 · Cloud Groups · Detection rules & anomalies
- T1070.003 · Clear Command History · Detection rules & anomalies
- T1070.004 · File Deletion · Detection rules & anomalies
- T1070.005 · Network Share Connection Removal · Detection rules & anomalies
- T1070.006 · Timestomp · Detection rules & anomalies
- T1070.007 · Clear Network Connection History and Configurations · Detection rules & anomalies
- T1070.008 · Clear Mailbox Data · Detection rules & anomalies
- T1070.009 · Clear Persistence · Detection rules & anomalies
- T1070.010 · Relocate Malware · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1072 · Software Deployment Tools · Detection rules & anomalies
- T1074 · Data Staged · Detection rules & anomalies
- T1074.001 · Local Data Staging · Detection rules & anomalies
- T1074.002 · Remote Data Staging · Detection rules & anomalies
- T1082 · System Information Discovery · Detection rules & anomalies
- T1083 · File and Directory Discovery · Detection rules & anomalies
- T1087 · Account Discovery · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1087.003 · Email Account · Detection rules & anomalies
- T1087.004 · Cloud Account · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1098.004 · SSH Authorized Keys · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1114 · Email Collection · Detection rules & anomalies
- T1114.002 · Remote Email Collection · Detection rules & anomalies
- T1114.003 · Email Forwarding Rule · Detection rules & anomalies
- T1124 · System Time Discovery · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1136 · Create Account · Detection rules & anomalies
- T1136.001 · Local Account · Detection rules & anomalies
- T1136.002 · Domain Account · Detection rules & anomalies
- T1137.001 · Office Template Macros · Detection rules & anomalies
- T1137.002 · Office Test · Detection rules & anomalies
- T1137.003 · Outlook Forms · Detection rules & anomalies
- T1137.004 · Outlook Home Page · Detection rules & anomalies
- T1137.005 · Outlook Rules · Detection rules & anomalies
- T1137.006 · Add-ins · Detection rules & anomalies
- T1140 · Deobfuscate/Decode Files or Information · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1197 · BITS Jobs · Detection rules & anomalies
- T1201 · Password Policy Discovery · Detection rules & anomalies
- T1204.003 · Malicious Image · Detection rules & anomalies
- T1204.004 · Malicious Copy and Paste · Detection rules & anomalies
- T1205 · Traffic Signaling · Detection rules & anomalies
- T1213 · Data from Information Repositories · Detection rules & anomalies
- T1216 · System Script Proxy Execution · Detection rules & anomalies
- T1216.001 · PubPrn · Detection rules & anomalies
- T1216.002 · SyncAppvPublishingServer · Detection rules & anomalies
- T1217 · Browser Information Discovery · Detection rules & anomalies
- T1218.003 · CMSTP · Detection rules & anomalies
- T1218.004 · InstallUtil · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.013 · Mavinject · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1222 · File and Directory Permissions Modification · Detection rules & anomalies
- T1222.001 · Windows Permissions · Detection rules & anomalies
- T1222.002 · Linux and Mac Permissions · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1482 · Domain Trust Discovery · Detection rules & anomalies
- T1484.002 · Trust Modification · Detection rules & anomalies
- T1485 · Data Destruction · Detection rules & anomalies
- T1486 · Data Encrypted for Impact · Detection rules & anomalies
- T1490 · Inhibit System Recovery · Detection rules & anomalies
- T1491.001 · Internal Defacement · Detection rules & anomalies
- T1497 · Virtualization/Sandbox Evasion · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1498.002 · Reflection Amplification · Detection rules & anomalies
- T1505 · Server Software Component · Detection rules & anomalies
- T1505.002 · Transport Agent · Detection rules & anomalies
- T1505.006 · vSphere Installation Bundles · Detection rules & anomalies
- T1518 · Software Discovery · Detection rules & anomalies
- T1518.001 · Security Software Discovery · Detection rules & anomalies
- T1529 · System Shutdown/Reboot · Detection rules & anomalies
- T1531 · Account Access Removal · Detection rules & anomalies
- T1534 · Internal Spearphishing · Detection rules & anomalies
- T1542 · Pre-OS Boot · Detection rules & anomalies
- T1542.005 · TFTP Boot · Detection rules & anomalies
- T1543 · Create or Modify System Process · Detection rules & anomalies
- T1543.001 · Launch Agent · Detection rules & anomalies
- T1543.002 · Systemd Service · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.013 · PowerShell Profile · Detection rules & anomalies
- T1546.014 · Emond · Detection rules & anomalies
- T1546.017 · Udev Rules · Detection rules & anomalies
- T1547.006 · Kernel Modules and Extensions · Detection rules & anomalies
- T1548.001 · Setuid and Setgid · Detection rules & anomalies
- T1548.003 · Sudo and Sudo Caching · Detection rules & anomalies
- T1548.006 · TCC Manipulation · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.004 · Private Keys · Detection rules & anomalies
- T1552.007 · Container API · Detection rules & anomalies
- T1553 · Subvert Trust Controls · Detection rules & anomalies
- T1553.004 · Install Root Certificate · Detection rules & anomalies
- T1553.006 · Code Signing Policy Modification · Detection rules & anomalies
- T1555.002 · Securityd Memory · Detection rules & anomalies
- T1556.005 · Reversible Encryption · Detection rules & anomalies
- T1560 · Archive Collected Data · Detection rules & anomalies
- T1560.001 · Archive via Utility · Detection rules & anomalies
- T1560.002 · Archive via Library · Detection rules & anomalies
- T1560.003 · Archive via Custom Method · Detection rules & anomalies
- T1561 · Disk Wipe · Detection rules & anomalies
- T1561.001 · Disk Content Wipe · Detection rules & anomalies
- T1561.002 · Disk Structure Wipe · Detection rules & anomalies
- T1563 · Remote Service Session Hijacking · Detection rules & anomalies
- T1564 · Hide Artifacts · Detection rules & anomalies
- T1564.001 · Hidden Files and Directories · Detection rules & anomalies
- T1564.002 · Hidden Users · Detection rules & anomalies
- T1564.003 · Hidden Window · Detection rules & anomalies
- T1564.005 · Hidden File System · Detection rules & anomalies
- T1564.006 · Run Virtual Instance · Detection rules & anomalies
- T1564.008 · Email Hiding Rules · Detection rules & anomalies
- T1564.009 · Resource Forking · Detection rules & anomalies
- T1564.011 · Ignore Process Interrupts · Detection rules & anomalies
- T1564.014 · Extended Attributes · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1569.001 · Launchctl · Detection rules & anomalies
- T1569.003 · Systemctl · Detection rules & anomalies
- T1570 · Lateral Tool Transfer · Detection rules & anomalies
- T1600.001 · Reduce Key Space · Detection rules & anomalies
- T1600.002 · Disable Crypto Hardware · Detection rules & anomalies
- T1601 · Modify System Image · Detection rules & anomalies
- T1601.001 · Patch System Image · Detection rules & anomalies
- T1601.002 · Downgrade System Image · Detection rules & anomalies
- T1602.002 · Network Device Configuration Dump · Detection rules & anomalies
- T1609 · Container Administration Command · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
- T1614.001 · System Language Discovery · Detection rules & anomalies
- T1615 · Group Policy Discovery · Detection rules & anomalies
- T1647 · Plist File Modification · Detection rules & anomalies
- T1649 · Steal or Forge Authentication Certificates · Detection rules & anomalies
- T1651 · Cloud Administration Command · Detection rules & anomalies
- T1652 · Device Driver Discovery · Detection rules & anomalies
- T1653 · Power Settings · Detection rules & anomalies
- T1654 · Log Enumeration · Detection rules & anomalies
- T1657 · Financial Theft · Detection rules & anomalies
- T1659 · Content Injection · Detection rules & anomalies
- T1668 · Exclusive Control · Detection rules & anomalies
- T1673 · Virtual Machine Discovery · Detection rules & anomalies
- T1674 · Input Injection · Detection rules & anomalies
- T1677 · Poisoned Pipeline Execution · Detection rules & anomalies
- T1679 · Selective Exclusion · Detection rules & anomalies
- T1680 · Local Storage Discovery · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T1684.001 · Impersonation · Detection rules & anomalies
- T1685 · Disable or Modify Tools · Detection rules & anomalies
- T1685.004 · Disable or Modify Linux Audit System Log · Detection rules & anomalies
- T1686 · Disable or Modify System Firewall · Detection rules & anomalies
- T1686.002 · Network Device Firewall · Detection rules & anomalies
- T1687 · Exploitation for Defense Impairment · Detection rules & anomalies
- T1689 · Downgrade Attack · Detection rules & anomalies
- T1690 · Prevent Command History Logging · Detection rules & anomalies
- T0802 · Automated Collection · Detection rules & anomalies
- T0807 · Command-Line Interface · Detection rules & anomalies
- T0809 · Data Destruction · Detection rules & anomalies
- T0823 · Graphical User Interface · Detection rules & anomalies
- T0840 · Network Connection Enumeration · Detection rules & anomalies
- T0842 · Network Sniffing · Detection rules & anomalies
- T0849 · Masquerading · Detection rules & anomalies
- T0852 · Screen Capture · Detection rules & anomalies
- T0853 · Scripting · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T0872 · Indicator Removal on Host · Detection rules & anomalies
- T0881 · Service Stop · Detection rules & anomalies
- T0886 · Remote Services · Detection rules & anomalies
- T0893 · Data from Local System · Detection rules & anomalies
- T0894 · System Binary Proxy Execution · Detection rules & anomalies
- T1418 · Software Discovery · Detection rules & anomalies
- T1418.001 · Security Software Discovery · Detection rules & anomalies
- T1623 · Command and Scripting Interpreter · Detection rules & anomalies
- T1623.001 · Unix Shell · Detection rules & anomalies
- T1662 · Data Destruction · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- Arp · S0099
- AsyncRAT · S1087
- at · S0110
- attrib · S1176
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- certutil · S0160
- cipher.exe · S1205
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Diskpart · S9002
- Donut · S0695
- dsquery · S0105
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Expand · S0361
- FlexiSpy · S0408
- Forfiles · S0193
- FRP · S1144
- ftp · S0095
- HTRAN · S0040
- ifconfig · S0101
- Imminent Monitor · S0434
- Impacket · S0357
- ipconfig · S0100
- IronNetInjector · S0581
- Koadic · S0250
- LaZagne · S0349
- MailSniper · S0413
- MCMD · S0500
- Mimikatz · S0002
- Mythic · S0699
- NBTscan · S0590
- nbtstat · S0102
- Net · S0039
- netsh · S0108
- netstat · S0104
- ngrok · S0508
- Nltest · S0359
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- Peirates · S0683
- Ping · S0097
- PoshC2 · S0378
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- RawDisk · S0364
- Rclone · S1040
- Reg · S0075
- Remcos · S0332
- RemoteUtilities · S0592
- Responder · S0174
- ROADTools · S0684
- route · S0103
- Rubeus · S1071
- Ruler · S0358
- SDelete · S0195
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- Systeminfo · S0096
- Tasklist · S0057
- TruffleHog · S9009
- Wevtutil · S0645
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.