1200KM / telemetry
Logon Session Metadata — Detection Telemetry
Attributes of existing logon sessions and their association with accounts or hosts.
Collection and providers
Collect supported session inventory and correlate session IDs with authentication, logon and logoff events.
- osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
- Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.
Configuration
- Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
- Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
- Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0088",
"collector": "illustrative-lab-collector",
"observation": {
"session_id": "lab-session-1",
"account": "LAB\\analyst",
"host": "lab-host-1",
"session_type": "interactive"
}
}Visibility and validation
Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1021.001 · Remote Desktop Protocol · Detection rules & anomalies
- T1021.004 · SSH · Detection rules & anomalies
- T1021.005 · VNC · Detection rules & anomalies
- T1068 · Exploitation for Privilege Escalation · Detection rules & anomalies
- T1078 · Valid Accounts · Detection rules & anomalies
- T1078.001 · Default Accounts · Detection rules & anomalies
- T1078.002 · Domain Accounts · Detection rules & anomalies
- T1078.003 · Local Accounts · Detection rules & anomalies
- T1078.004 · Cloud Accounts · Detection rules & anomalies
- T1133 · External Remote Services · Detection rules & anomalies
- T1134 · Access Token Manipulation · Detection rules & anomalies
- T1134.002 · Create Process with Token · Detection rules & anomalies
- T1134.003 · Make and Impersonate Token · Detection rules & anomalies
- T1185 · Browser Session Hijacking · Detection rules & anomalies
- T1199 · Trusted Relationship · Detection rules & anomalies
- T1489 · Service Stop · Detection rules & anomalies
- T1491.002 · External Defacement · Detection rules & anomalies
- T1497.002 · User Activity Based Checks · Detection rules & anomalies
- T1534 · Internal Spearphishing · Detection rules & anomalies
- T1546.001 · Change Default File Association · Detection rules & anomalies
- T1547.007 · Re-opened Applications · Detection rules & anomalies
- T1547.014 · Active Setup · Detection rules & anomalies
- T1548 · Abuse Elevation Control Mechanism · Detection rules & anomalies
- T1548.002 · Bypass User Account Control · Detection rules & anomalies
- T1558 · Steal or Forge Kerberos Tickets · Detection rules & anomalies
- T1558.001 · Golden Ticket · Detection rules & anomalies
- T1558.002 · Silver Ticket · Detection rules & anomalies
- T1558.003 · Kerberoasting · Detection rules & anomalies
- T1606.002 · SAML Tokens · Detection rules & anomalies
- T1621 · Multi-Factor Authentication Request Generation · Detection rules & anomalies
- T0822 · External Remote Services · Detection rules & anomalies
- T0859 · Valid Accounts · Detection rules & anomalies
- T0883 · Internet Accessible Device · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
- AADInternals · S0677
- Brute Ratel C4 · S1063
- Cobalt Strike · S0154
- CSPY Downloader · S0527
- Empire · S0363
- evilginx2 · S9003
- Imminent Monitor · S0434
- Impacket · S0357
- Koadic · S0250
- Mimikatz · S0002
- Pacu · S1091
- Peirates · S0683
- PoshC2 · S0378
- PowerSploit · S0194
- Pupy · S0192
- QuasarRAT · S0262
- Remcos · S0332
- ROADTools · S0684
- Rubeus · S1071
- SILENTTRINITY · S0692
- Sliver · S0633
- TruffleHog · S9009
- UACMe · S0116
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.