1200KM / telemetry
Network Traffic Content — Detection Telemetry
Packet or decoded application-protocol content visible at a network sensor.
Collection and providers
Scope approved packet capture/protocol content collection to the lab flow; retain capture provenance and truncation indicators.
- Zeek: Connection and protocol metadata from traffic visible to the sensor.
- Suricata EVE: Configured flow, alert, DNS, HTTP, TLS and protocol records.
Configuration
- Use an authorized lab TAP/SPAN, virtual mirror or gateway interface. Define which traffic crosses it; avoid assuming visibility into every segment.
- Enable the required Zeek analyzers or Suricata EVE event types. Export logs with sensor identity, clock synchronization and flow correlation identifiers.
- Monitor capture loss, truncation and exporter sampling. Capture payload only with approval and restrictive retention; encryption normally prevents plaintext inspection.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0085",
"collector": "illustrative-lab-collector",
"observation": {
"flow_id": "lab-flow-1",
"protocol": "http",
"method": "GET",
"path": "/lab-check",
"payload_excerpt": "LAB_TELEMETRY_CHECK"
}
}Visibility and validation
Flows are not packet payloads. NAT, asymmetric routes, encryption, missing mirrors and sampling can hide attribution or content. A destination connection alone does not prove malicious intent.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1001 · Data Obfuscation · Detection rules & anomalies
- T1001.001 · Junk Data · Detection rules & anomalies
- T1001.002 · Steganography · Detection rules & anomalies
- T1001.003 · Protocol or Service Impersonation · Detection rules & anomalies
- T1003.006 · DCSync · Detection rules & anomalies
- T1011 · Exfiltration Over Other Network Medium · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1027 · Obfuscated Files or Information · Detection rules & anomalies
- T1027.006 · HTML Smuggling · Detection rules & anomalies
- T1027.008 · Stripped Payloads · Detection rules & anomalies
- T1027.017 · SVG Smuggling · Detection rules & anomalies
- T1036.012 · Browser Fingerprint · Detection rules & anomalies
- T1040 · Network Sniffing · Detection rules & anomalies
- T1041 · Exfiltration Over C2 Channel · Detection rules & anomalies
- T1046 · Network Service Discovery · Detection rules & anomalies
- T1048 · Exfiltration Over Alternative Protocol · Detection rules & anomalies
- T1048.001 · Exfiltration Over Symmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.002 · Exfiltration Over Asymmetric Encrypted Non-C2 Protocol · Detection rules & anomalies
- T1048.003 · Exfiltration Over Unencrypted Non-C2 Protocol · Detection rules & anomalies
- T1049 · System Network Connections Discovery · Detection rules & anomalies
- T1053.007 · Container Orchestration Job · Detection rules & anomalies
- T1056 · Input Capture · Detection rules & anomalies
- T1056.001 · Keylogging · Detection rules & anomalies
- T1056.003 · Web Portal Capture · Detection rules & anomalies
- T1059.006 · Python · Detection rules & anomalies
- T1059.008 · Network Device CLI · Detection rules & anomalies
- T1069.002 · Domain Groups · Detection rules & anomalies
- T1070.005 · Network Share Connection Removal · Detection rules & anomalies
- T1070.007 · Clear Network Connection History and Configurations · Detection rules & anomalies
- T1071 · Application Layer Protocol · Detection rules & anomalies
- T1071.001 · Web Protocols · Detection rules & anomalies
- T1071.002 · File Transfer Protocols · Detection rules & anomalies
- T1071.003 · Mail Protocols · Detection rules & anomalies
- T1071.004 · DNS · Detection rules & anomalies
- T1071.005 · Publish/Subscribe Protocols · Detection rules & anomalies
- T1074.002 · Remote Data Staging · Detection rules & anomalies
- T1087.002 · Domain Account · Detection rules & anomalies
- T1090.001 · Internal Proxy · Detection rules & anomalies
- T1090.002 · External Proxy · Detection rules & anomalies
- T1090.003 · Multi-hop Proxy · Detection rules & anomalies
- T1090.004 · Domain Fronting · Detection rules & anomalies
- T1095 · Non-Application Layer Protocol · Detection rules & anomalies
- T1102 · Web Service · Detection rules & anomalies
- T1102.001 · Dead Drop Resolver · Detection rules & anomalies
- T1102.002 · Bidirectional Communication · Detection rules & anomalies
- T1102.003 · One-Way Communication · Detection rules & anomalies
- T1125 · Video Capture · Detection rules & anomalies
- T1129 · Shared Modules · Detection rules & anomalies
- T1132 · Data Encoding · Detection rules & anomalies
- T1132.001 · Standard Encoding · Detection rules & anomalies
- T1132.002 · Non-Standard Encoding · Detection rules & anomalies
- T1176.001 · Browser Extensions · Detection rules & anomalies
- T1187 · Forced Authentication · Detection rules & anomalies
- T1189 · Drive-by Compromise · Detection rules & anomalies
- T1190 · Exploit Public-Facing Application · Detection rules & anomalies
- T1199 · Trusted Relationship · Detection rules & anomalies
- T1204 · User Execution · Detection rules & anomalies
- T1204.001 · Malicious Link · Detection rules & anomalies
- T1204.003 · Malicious Image · Detection rules & anomalies
- T1204.004 · Malicious Copy and Paste · Detection rules & anomalies
- T1204.005 · Malicious Library · Detection rules & anomalies
- T1205 · Traffic Signaling · Detection rules & anomalies
- T1205.002 · Socket Filters · Detection rules & anomalies
- T1207 · Rogue Domain Controller · Detection rules & anomalies
- T1210 · Exploitation of Remote Services · Detection rules & anomalies
- T1213.001 · Confluence · Detection rules & anomalies
- T1213.006 · Databases · Detection rules & anomalies
- T1491 · Defacement · Detection rules & anomalies
- T1491.002 · External Defacement · Detection rules & anomalies
- T1495 · Firmware Corruption · Detection rules & anomalies
- T1496 · Resource Hijacking · Detection rules & anomalies
- T1496.001 · Compute Hijacking · Detection rules & anomalies
- T1496.002 · Bandwidth Hijacking · Detection rules & anomalies
- T1499.001 · OS Exhaustion Flood · Detection rules & anomalies
- T1499.002 · Service Exhaustion Flood · Detection rules & anomalies
- T1499.003 · Application Exhaustion Flood · Detection rules & anomalies
- T1499.004 · Application or System Exploitation · Detection rules & anomalies
- T1505 · Server Software Component · Detection rules & anomalies
- T1505.003 · Web Shell · Detection rules & anomalies
- T1530 · Data from Cloud Storage · Detection rules & anomalies
- T1534 · Internal Spearphishing · Detection rules & anomalies
- T1537 · Transfer Data to Cloud Account · Detection rules & anomalies
- T1546 · Event Triggered Execution · Detection rules & anomalies
- T1546.004 · Unix Shell Configuration Modification · Detection rules & anomalies
- T1546.018 · Python Startup Hooks · Detection rules & anomalies
- T1552 · Unsecured Credentials · Detection rules & anomalies
- T1552.005 · Cloud Instance Metadata API · Detection rules & anomalies
- T1557 · Adversary-in-the-Middle · Detection rules & anomalies
- T1557.001 · Name Resolution Poisoning and SMB Relay · Detection rules & anomalies
- T1557.002 · ARP Cache Poisoning · Detection rules & anomalies
- T1557.003 · DHCP Spoofing · Detection rules & anomalies
- T1557.004 · Evil Twin · Detection rules & anomalies
- T1563 · Remote Service Session Hijacking · Detection rules & anomalies
- T1565 · Data Manipulation · Detection rules & anomalies
- T1565.002 · Transmitted Data Manipulation · Detection rules & anomalies
- T1566.002 · Spearphishing Link · Detection rules & anomalies
- T1566.003 · Spearphishing via Service · Detection rules & anomalies
- T1567 · Exfiltration Over Web Service · Detection rules & anomalies
- T1567.001 · Exfiltration to Code Repository · Detection rules & anomalies
- T1567.002 · Exfiltration to Cloud Storage · Detection rules & anomalies
- T1567.003 · Exfiltration to Text Storage Sites · Detection rules & anomalies
- T1567.004 · Exfiltration Over Webhook · Detection rules & anomalies
- T1568 · Dynamic Resolution · Detection rules & anomalies
- T1568.002 · Domain Generation Algorithms · Detection rules & anomalies
- T1568.003 · DNS Calculation · Detection rules & anomalies
- T1571 · Non-Standard Port · Detection rules & anomalies
- T1572 · Protocol Tunneling · Detection rules & anomalies
- T1573 · Encrypted Channel · Detection rules & anomalies
- T1573.001 · Symmetric Cryptography · Detection rules & anomalies
- T1573.002 · Asymmetric Cryptography · Detection rules & anomalies
- T1585 · Establish Accounts · Detection rules & anomalies
- T1585.001 · Social Media Accounts · Detection rules & anomalies
- T1586 · Compromise Accounts · Detection rules & anomalies
- T1586.001 · Social Media Accounts · Detection rules & anomalies
- T1589 · Gather Victim Identity Information · Detection rules & anomalies
- T1589.002 · Email Addresses · Detection rules & anomalies
- T1595 · Active Scanning · Detection rules & anomalies
- T1595.001 · Scanning IP Blocks · Detection rules & anomalies
- T1595.002 · Vulnerability Scanning · Detection rules & anomalies
- T1595.003 · Wordlist Scanning · Detection rules & anomalies
- T1598 · Phishing for Information · Detection rules & anomalies
- T1598.001 · Spearphishing Service · Detection rules & anomalies
- T1598.002 · Spearphishing Attachment · Detection rules & anomalies
- T1598.003 · Spearphishing Link · Detection rules & anomalies
- T1599 · Network Boundary Bridging · Detection rules & anomalies
- T1599.001 · Network Address Translation Traversal · Detection rules & anomalies
- T1600 · Weaken Encryption · Detection rules & anomalies
- T1600.001 · Reduce Key Space · Detection rules & anomalies
- T1600.002 · Disable Crypto Hardware · Detection rules & anomalies
- T1602 · Data from Configuration Repository · Detection rules & anomalies
- T1602.001 · SNMP (MIB Dump) · Detection rules & anomalies
- T1602.002 · Network Device Configuration Dump · Detection rules & anomalies
- T1606 · Forge Web Credentials · Detection rules & anomalies
- T1610 · Deploy Container · Detection rules & anomalies
- T1614 · System Location Discovery · Detection rules & anomalies
- T1615 · Group Policy Discovery · Detection rules & anomalies
- T1659 · Content Injection · Detection rules & anomalies
- T1665 · Hide Infrastructure · Detection rules & anomalies
- T1669 · Wi-Fi Networks · Detection rules & anomalies
- T1687 · Exploitation for Defense Impairment · Detection rules & anomalies
- T0800 · Activate Firmware Update Mode · Detection rules & anomalies
- T0801 · Monitor Process State · Detection rules & anomalies
- T0802 · Automated Collection · Detection rules & anomalies
- T0806 · Brute Force I/O · Detection rules & anomalies
- T0814 · Denial of Service · Detection rules & anomalies
- T0816 · Device Restart/Shutdown · Detection rules & anomalies
- T0817 · Drive-by Compromise · Detection rules & anomalies
- T0819 · Exploit Public-Facing Application · Detection rules & anomalies
- T0830 · Adversary-in-the-Middle · Detection rules & anomalies
- T0836 · Modify Parameter · Detection rules & anomalies
- T0838 · Modify Alarm Settings · Detection rules & anomalies
- T0843 · Program Download · Detection rules & anomalies
- T0843.001 · Download All · Detection rules & anomalies
- T0843.002 · Online Edit · Detection rules & anomalies
- T0843.003 · Program Append · Detection rules & anomalies
- T0845 · Program Upload · Detection rules & anomalies
- T0846 · Remote System Discovery · Detection rules & anomalies
- T0846.001 · Port Scan · Detection rules & anomalies
- T0846.002 · Broadcast Discovery · Detection rules & anomalies
- T0846.003 · Multicast Discovery · Detection rules & anomalies
- T0848 · Rogue Master · Detection rules & anomalies
- T0858 · Change Operating Mode · Detection rules & anomalies
- T0861 · Point & Tag Identification · Detection rules & anomalies
- T0863 · User Execution · Detection rules & anomalies
- T0865 · Spearphishing Attachment · Detection rules & anomalies
- T0866 · Exploitation of Remote Services · Detection rules & anomalies
- T0867 · Lateral Tool Transfer · Detection rules & anomalies
- T0868 · Detect Operating Mode · Detection rules & anomalies
- T0869 · Standard Application Layer Protocol · Detection rules & anomalies
- T0883 · Internet Accessible Device · Detection rules & anomalies
- T0884 · Connection Proxy · Detection rules & anomalies
- T0885 · Commonly Used Port · Detection rules & anomalies
- T0888 · Remote System Information Discovery · Detection rules & anomalies
- T0889 · Modify Program · Detection rules & anomalies
- T0892 · Change Credential · Detection rules & anomalies
- T1692 · Unauthorized Message · Detection rules & anomalies
- T1692.001 · Command Message · Detection rules & anomalies
- T1692.002 · Reporting Message · Detection rules & anomalies
- T1693 · Modify Firmware · Detection rules & anomalies
- T1693.001 · System Firmware · Detection rules & anomalies
- T1693.002 · Module Firmware · Detection rules & anomalies
- T1694 · Insecure Credentials · Detection rules & anomalies
- T1694.001 · Default Credentials · Detection rules & anomalies
- T1694.002 · Hardcoded Credentials · Detection rules & anomalies
- T1406 · Obfuscated Files or Information · Detection rules & anomalies
- T1406.001 · Steganography · Detection rules & anomalies
- T1407 · Download New Code at Runtime · Detection rules & anomalies
- T1417.002 · GUI Input Capture · Detection rules & anomalies
- T1421 · System Network Connections Discovery · Detection rules & anomalies
- T1428 · Exploitation of Remote Services · Detection rules & anomalies
- T1430.002 · Impersonate SS7 Nodes · Detection rules & anomalies
- T1437 · Application Layer Protocol · Detection rules & anomalies
- T1437.001 · Web Protocols · Detection rules & anomalies
- T1451 · SIM Card Swap · Detection rules & anomalies
- T1456 · Drive-By Compromise · Detection rules & anomalies
- T1474.002 · Compromise Hardware Supply Chain · Detection rules & anomalies
- T1481 · Web Service · Detection rules & anomalies
- T1481.001 · Dead Drop Resolver · Detection rules & anomalies
- T1481.002 · Bidirectional Communication · Detection rules & anomalies
- T1481.003 · One-Way Communication · Detection rules & anomalies
- T1509 · Non-Standard Port · Detection rules & anomalies
- T1521.003 · SSL Pinning · Detection rules & anomalies
- T1544 · Ingress Tool Transfer · Detection rules & anomalies
- T1604 · Proxy Through Victim · Detection rules & anomalies
- T1660 · Phishing · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- AdFind · S0552
- AsyncRAT · S1087
- BITSAdmin · S0190
- BloodHound · S0521
- Brute Ratel C4 · S1063
- Burp Suite · burp-suite
- CARROTBALL · S0465
- Cobalt Strike · S0154
- ConnectWise · S0591
- Covenant · S1155
- CrackMapExec · S0488
- CSPY Downloader · S0527
- DCRAT · S9017
- DirBuster · dirbuster
- Donut · S0695
- dsquery · S0105
- Empire · S0363
- evilginx2 · S9003
- FlexiSpy · S0408
- FRP · S1144
- ftp · S0095
- Havij · S0224
- Imminent Monitor · S0434
- Impacket · S0357
- IronNetInjector · S0581
- Koadic · S0250
- MCMD · S0500
- meek · S0175
- Mimikatz · S0002
- Mythic · S0699
- NBTscan · S0590
- nbtstat · S0102
- Net · S0039
- netstat · S0104
- ngrok · S0508
- Nikto · nikto
- Nmap · nmap
- NPPSPY · S1131
- Out1 · S0594
- Pacu · S1091
- PcShare · S1050
- Peirates · S0683
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Quick Assist · S1209
- Rclone · S1040
- Remcos · S0332
- Responder · S0174
- ShimRatReporter · S0445
- SILENTTRINITY · S0692
- Sliver · S0633
- sqlmap · S0225
- Tor · S0183
- TruffleHog · S9009
- Xbot · S0298
- ZAP · zap
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.