1200KM / telemetry
Network Connection Creation — Detection Telemetry
Creation of an endpoint network connection linked to a process.
Collection and providers
Enable scoped Sysmon NetworkConnect (3), disabled by default, or a platform-equivalent process-aware network sensor.
- Microsoft Sysmon: Windows event-based collection; enable the event types needed below.
- Linux Audit: Linux alternative for supported system-call and file events; different semantics and fields.
- Apple Endpoint Security clients: macOS alternative where the subscribed event exists; requires an entitled, approved client, not an iOS collector.
Configuration
- On a disposable Windows host, review the installed Sysmon schema and current configuration; merge scoped event filters into the existing policy rather than replacing it.
- Forward Microsoft-Windows-Sysmon/Operational to the lab collector. Preserve event ID, timestamp, computer, process identifiers and the original event.
- For Linux or macOS, select the equivalent sensor separately and test its emitted fields; a Windows event ID does not transfer across platforms.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0082",
"collector": "illustrative-lab-collector",
"observation": {
"process_guid": "lab-process-001",
"destination_ip": "198.51.100.20",
"destination_port": 443,
"protocol": "tcp",
"initiated": true
}
}Visibility and validation
Event filtering and sensor versions change coverage. High-volume image-load and process-access collection needs tuning; endpoint events alone do not establish intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001 · Data Obfuscation · Detection rules & anomalies
- T1001.001 · Junk Data · Detection rules & anomalies
- T1001.002 · Steganography · Detection rules & anomalies
- T1001.003 · Protocol or Service Impersonation · Detection rules & anomalies
- T1008 · Fallback Channels · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1011.001 · Exfiltration Over Bluetooth · Detection rules & anomalies
- T1016.001 · Internet Connection Discovery · Detection rules & anomalies
- T1018 · Remote System Discovery · Detection rules & anomalies
- T1020 · Automated Exfiltration · Detection rules & anomalies
- T1020.001 · Traffic Duplication · Detection rules & anomalies
- T1021 · Remote Services · Detection rules & anomalies
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1021.002 · SMB/Windows Admin Shares · Detection rules & anomalies
- T1021.003 · Distributed Component Object Model · Detection rules & anomalies
- T1027.003 · Steganography · Detection rules & anomalies
- T1027.004 · Compile After Delivery · Detection rules & anomalies
- T1027.012 · LNK Icon Smuggling · Detection rules & anomalies
- T1027.013 · Encrypted/Encoded File · Detection rules & anomalies
- T1027.017 · SVG Smuggling · Detection rules & anomalies
- T1027.018 · Invisible Unicode · Detection rules & anomalies
- T1029 · Scheduled Transfer · Detection rules & anomalies
- T1030 · Data Transfer Size Limits · Detection rules & anomalies
- T1036.012 · Browser Fingerprint · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1047 · Windows Management Instrumentation · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1059.004 · Unix Shell · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.003 · Mail Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1071.005 · Publish/Subscribe Protocols · Detection rules & anomalies
- T1078.002 · Domain Accounts · Detection rules & anomalies
- T1090 · Proxy · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1090.004 · Domain Fronting · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1102 · Web Service · Detection rules & anomalies
- T1102.001 · Dead Drop Resolver · Detection rules & anomalies
- T1102.002 · Bidirectional Communication · Detection rules & anomalies
- T1102.003 · One-Way Communication · Detection rules & anomalies
- T1104 · Multi-Stage Channels · Detection rules & anomalies
- T1105 · Ingress Tool Transfer · Detection rules & anomalies
- T1114 · Email Collection · Detection rules & anomalies
- T1114.001 · Local Email Collection · Detection rules & anomalies
- T1114.002 · Remote Email Collection · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1127 · Trusted Developer Utilities Proxy Execution · Detection rules & anomalies
- T1127.001 · MSBuild · Detection rules & anomalies
- T1127.003 · JamPlus · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1132.002 · Non-Standard Encoding · Detection rules & anomalies
- T1133 · External Remote Services · Detection rules & anomalies
- T1135 · Network Share Discovery · Detection rules & anomalies
- T1176 · Software Extensions · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1176.002 · IDE Extensions · Detection rules & anomalies
- T1185 · Browser Session Hijacking · Detection rules & anomalies
- T1189 · Drive-by Compromise · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1195.002 · Compromise Software Supply Chain · Detection rules & anomalies
- T1197 · BITS Jobs · Detection rules & anomalies
- T1199 · Trusted Relationship · Detection rules & anomalies
- T1200 · Hardware Additions · Detection rules & anomalies
- T1202 · Indirect Command Execution · Detection rules & anomalies
- T1203 · Exploitation for Client Execution · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1204.001 · Malicious Link · Detection rules & anomalies
- T1204.004 · Malicious Copy and Paste · Detection rules & anomalies
- T1204.005 · Malicious Library · Detection rules & anomalies
- T1205 · Traffic Signaling · Detection rules & anomalies
- T1205.001 · Port Knocking · Detection rules & anomalies
- T1205.002 · Socket Filters · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1213 · Data from Information Repositories · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1216.001 · PubPrn · Detection rules & anomalies
- T1218 · System Binary Proxy Execution · Detection rules & anomalies
- T1218.001 · Compiled HTML File · Detection rules & anomalies
- T1218.003 · CMSTP · Detection rules & anomalies
- T1218.005 · Mshta · Detection rules & anomalies
- T1218.007 · Msiexec · Detection rules & anomalies
- T1218.008 · Odbcconf · Detection rules & anomalies
- T1218.009 · Regsvcs/Regasm · Detection rules & anomalies
- T1218.010 · Regsvr32 · Detection rules & anomalies
- T1218.011 · Rundll32 · Detection rules & anomalies
- T1218.012 · Verclsid · Detection rules & anomalies
- T1218.013 · Mavinject · Detection rules & anomalies
- T1218.014 · MMC · Detection rules & anomalies
- T1218.015 · Electron Applications · Detection rules & anomalies
- T1219 · Remote Access Tools · Detection rules & anomalies
- T1219.001 · IDE Tunneling · Detection rules & anomalies
- T1219.002 · Remote Desktop Software · Detection rules & anomalies
- T1221 · Template Injection · Detection rules & anomalies
- T1480 · Execution Guardrails · Detection rules & anomalies
- T1480.001 · Environmental Keying · Detection rules & anomalies
- T1496 · Resource Hijacking · Detection rules & anomalies
- T1496.001 · Compute Hijacking · Detection rules & anomalies
- T1496.002 · Bandwidth Hijacking · Detection rules & anomalies
- T1498 · Network Denial of Service · Detection rules & anomalies
- T1498.001 · Direct Network Flood · Detection rules & anomalies
- T1498.002 · Reflection Amplification · Detection rules & anomalies
- T1499.002 · Service Exhaustion Flood · Detection rules & anomalies
- T1535 · Unused/Unsupported Cloud Regions · Detection rules & anomalies
- T1542.004 · ROMMONkit · Detection rules & anomalies
- T1542.005 · TFTP Boot · Detection rules & anomalies
- T1550.002 · Pass the Hash · Detection rules & anomalies
- T1552.001 · Credentials In Files · Detection rules & anomalies
- T1552.005 · Cloud Instance Metadata API · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1557.002 · ARP Cache Poisoning · Detection rules & anomalies
- T1563 · Remote Service Session Hijacking · Detection rules & anomalies
- T1563.001 · SSH Hijacking · Detection rules & anomalies
- T1563.002 · RDP Hijacking · Detection rules & anomalies
- T1565.002 · Transmitted Data Manipulation · Detection rules & anomalies
- T1566.001 · Spearphishing Attachment · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1568.001 · Fast Flux DNS · Detection rules & anomalies
- T1568.002 · Domain Generation Algorithms · Detection rules & anomalies
- T1568.003 · DNS Calculation · Detection rules & anomalies
- T1569.002 · Service Execution · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1602 · Data from Configuration Repository · Detection rules & anomalies
- T1602.001 · SNMP (MIB Dump) · Detection rules & anomalies
- T1602.002 · Network Device Configuration Dump · Detection rules & anomalies
- T1606.001 · Web Cookies · Detection rules & anomalies
- T1612 · Build Image on Host · Detection rules & anomalies
- T1665 · Hide Infrastructure · Detection rules & anomalies
- T1669 · Wi-Fi Networks · Detection rules & anomalies
- T1684 · Social Engineering · Detection rules & anomalies
- T1686.002 · Network Device Firewall · Detection rules & anomalies
- T1686.003 · Windows Host Firewall · Detection rules & anomalies
- T0817 · Drive-by Compromise · Detection rules & anomalies
- T0846.001 · Port Scan · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0886 · Remote Services · Detection rules & anomalies
- T1638 · Adversary-in-the-Middle · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- Arp · S0099
- AsyncRAT · S1087
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- CARROTBALL · S0465
- certutil · S0160
- cmd · S0106
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- Donut · S0695
- Empire · S0363
- esentutl · S0404
- evilginx2 · S9003
- Forfiles · S0193
- FRP · S1144
- ftp · S0095
- Havij · S0224
- HTRAN · S0040
- Imminent Monitor · S0434
- Impacket · S0357
- Invoke-PSImage · S0231
- IronNetInjector · S0581
- Koadic · S0250
- LaZagne · S0349
- MailSniper · S0413
- MCMD · S0500
- meek · S0175
- Mimikatz · S0002
- Mythic · S0699
- NBTscan · S0590
- Net · S0039
- netsh · S0108
- ngrok · S0508
- Nltest · S0359
- Nmap · nmap
- NPPSPY · S1131
- Out1 · S0594
- Pass-The-Hash Toolkit · S0122
- PcShare · S1050
- Peirates · S0683
- Ping · S0097
- PoshC2 · S0378
- PowerSploit · S0194
- PsExec · S0029
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Rclone · S1040
- Remcos · S0332
- RemoteUtilities · S0592
- ROADTools · S0684
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- sqlmap · S0225
- Tor · S0183
- TruffleHog · S9009
- Winexe · S0191
- xCmd · S0123
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.