1200KM / telemetry
Network Traffic Flow — Detection Telemetry
Connection/flow summaries such as endpoints, duration, byte counts and transport.
Collection and providers
Collect Zeek conn.log, Suricata flow events or exporter equivalents, including observation point and sampling settings.
- Zeek: Connection and protocol metadata from traffic visible to the sensor.
- Suricata EVE: Configured flow, alert, DNS, HTTP, TLS and protocol records.
- AWS VPC Flow Logs: IP traffic metadata alternative; no packet payload or DNS answer history, and some traffic is not logged.
Configuration
- Use an authorized lab TAP/SPAN, virtual mirror or gateway interface. Define which traffic crosses it; avoid assuming visibility into every segment.
- Enable the required Zeek analyzers or Suricata EVE event types. Export logs with sensor identity, clock synchronization and flow correlation identifiers.
- Monitor capture loss, truncation and exporter sampling. Capture payload only with approval and restrictive retention; encryption normally prevents plaintext inspection.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0078",
"collector": "illustrative-lab-collector",
"observation": {
"source_ip": "192.0.2.10",
"destination_ip": "198.51.100.20",
"destination_port": 443,
"protocol": "tcp",
"bytes_sent": 128,
"bytes_received": 512
}
}Visibility and validation
Flows are not packet payloads. NAT, asymmetric routes, encryption, missing mirrors and sampling can hide attribution or content. A destination connection alone does not prove malicious intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1008 · Fallback Channels · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1020.001 · Traffic Duplication · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1021.005 · VNC · Detection rules & anomalies
- T1021.006 · Windows Remote Management · Detection rules & anomalies
- T1029 · Scheduled Transfer · Detection rules & anomalies
- T1030 · Data Transfer Size Limits · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1059.004 · Unix Shell · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.003 · Mail Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1071.005 · Publish/Subscribe Protocols · Detection rules & anomalies
- T1072 · Software Deployment Tools · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1102 · Web Service · Detection rules & anomalies
- T1102.001 · Dead Drop Resolver · Detection rules & anomalies
- T1102.002 · Bidirectional Communication · Detection rules & anomalies
- T1102.003 · One-Way Communication · Detection rules & anomalies
- T1104 · Multi-Stage Channels · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1132.002 · Non-Standard Encoding · Detection rules & anomalies
- T1133 · External Remote Services · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.002 · IDE Extensions · Detection rules & anomalies
- T1187 · Forced Authentication · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1195 · Supply Chain Compromise · Detection rules & anomalies
- T1195.001 · Compromise Software Dependencies and Development Tools · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1205 · Traffic Signaling · Detection rules & anomalies
- T1205.001 · Port Knocking · Detection rules & anomalies
- T1496 · Resource Hijacking · Detection rules & anomalies
- T1496.001 · Compute Hijacking · Detection rules & anomalies
- T1496.002 · Bandwidth Hijacking · Detection rules & anomalies
- T1498 · Network Denial of Service · Detection rules & anomalies
- T1498.001 · Direct Network Flood · Detection rules & anomalies
- T1498.002 · Reflection Amplification · Detection rules & anomalies
- T1499 · Endpoint Denial of Service · Detection rules & anomalies
- T1499.001 · OS Exhaustion Flood · Detection rules & anomalies
- T1499.002 · Service Exhaustion Flood · Detection rules & anomalies
- T1505 · Server Software Component · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1557.002 · ARP Cache Poisoning · Detection rules & anomalies
- T1557.003 · DHCP Spoofing · Detection rules & anomalies
- T1557.004 · Evil Twin · Detection rules & anomalies
- T1563 · Remote Service Session Hijacking · Detection rules & anomalies
- T1565.002 · Transmitted Data Manipulation · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1568.001 · Fast Flux DNS · Detection rules & anomalies
- T1568.002 · Domain Generation Algorithms · Detection rules & anomalies
- T1568.003 · DNS Calculation · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1595 · Active Scanning · Detection rules & anomalies
- T1595.001 · Scanning IP Blocks · Detection rules & anomalies
- T1595.002 · Vulnerability Scanning · Detection rules & anomalies
- T1598 · Phishing for Information · Detection rules & anomalies
- T1598.001 · Spearphishing Service · Detection rules & anomalies
- T1598.002 · Spearphishing Attachment · Detection rules & anomalies
- T1598.003 · Spearphishing Link · Detection rules & anomalies
- T1599 · Network Boundary Bridging · Detection rules & anomalies
- T1599.001 · Network Address Translation Traversal · Detection rules & anomalies
- T1669 · Wi-Fi Networks · Detection rules & anomalies
- T0814 · Denial of Service · Detection rules & anomalies
- T0816 · Device Restart/Shutdown · Detection rules & anomalies
- T0822 · External Remote Services · Detection rules & anomalies
- T0830 · Adversary-in-the-Middle · Detection rules & anomalies
- T0845 · Program Upload · Detection rules & anomalies
- T0846 · Remote System Discovery · Detection rules & anomalies
- T0846.001 · Port Scan · Detection rules & anomalies
- T0846.002 · Broadcast Discovery · Detection rules & anomalies
- T0846.003 · Multicast Discovery · Detection rules & anomalies
- T0848 · Rogue Master · Detection rules & anomalies
- T0860 · Wireless Compromise · Detection rules & anomalies
- T0864 · Transient Cyber Asset · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T0869 · Standard Application Layer Protocol · Detection rules & anomalies
- T0878 · Alarm Suppression · Detection rules & anomalies
- T0883 · Internet Accessible Device · Detection rules & anomalies
- T0884 · Connection Proxy · Detection rules & anomalies
- T0885 · Commonly Used Port · Detection rules & anomalies
- T0886 · Remote Services · Detection rules & anomalies
- T0887 · Wireless Sniffing · Detection rules & anomalies
- T0888 · Remote System Information Discovery · Detection rules & anomalies
- T1691 · Block Operational Technology Message · Detection rules & anomalies
- T1691.001 · Command Message · Detection rules & anomalies
- T1691.002 · Reporting Message · Detection rules & anomalies
- T1692 · Unauthorized Message · Detection rules & anomalies
- T1692.001 · Command Message · Detection rules & anomalies
- T1692.002 · Reporting Message · Detection rules & anomalies
- T1695 · Block Communications · Detection rules & anomalies
- T1695.001 · Serial COM · Detection rules & anomalies
- T1695.002 · Ethernet · Detection rules & anomalies
- T1695.003 · Wi-Fi · Detection rules & anomalies
- T1430.002 · Impersonate SS7 Nodes · Detection rules & anomalies
- T1437 · Application Layer Protocol · Detection rules & anomalies
- T1604 · Proxy Through Victim · Detection rules & anomalies
- T1660 · Phishing · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AsyncRAT · S1087
- BITSAdmin · S0190
- Brute Ratel C4 · S1063
- Burp Suite · burp-suite
- CARROTBALL · S0465
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- FRP · S1144
- ftp · S0095
- Havij · S0224
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- Koadic · S0250
- MCMD · S0500
- Mythic · S0699
- NBTscan · S0590
- Net · S0039
- netsh · S0108
- ngrok · S0508
- Nikto · nikto
- Nmap · nmap
- NPPSPY · S1131
- Out1 · S0594
- PcShare · S1050
- Peirates · S0683
- PoshC2 · S0378
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Rclone · S1040
- Remcos · S0332
- RemoteUtilities · S0592
- Responder · S0174
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- sqlmap · S0225
- Tor · S0183
- ZAP · zap
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.