1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / telemetry

Logon Session Metadata — Detection Telemetry

Attributes of existing logon sessions and their association with accounts or hosts.

Collection and providers

Collect supported session inventory and correlate session IDs with authentication, logon and logoff events.

  • osquery: Scheduled host-state queries; supported tables and privileges vary by OS. Select a table that actually exposes the required object.
  • Linux Audit plus inventory snapshots: Events explain changes; snapshots describe state at collection time.

Configuration

  • Define the inventory query, allowed host set, interval and least-privileged reader. Store a stable asset ID, observation time and collector version.
  • Keep successive snapshots and calculate additions, removals and changed attributes. Pair state changes with audit events when available.
  • Export collector health and missed-poll counts so a missing snapshot is not misclassified as a missing asset.

Synthetic event example

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0088",
  "collector": "illustrative-lab-collector",
  "observation": {
    "session_id": "lab-session-1",
    "account": "LAB\\analyst",
    "host": "lab-host-1",
    "session_type": "interactive"
  }
}

Visibility and validation

Snapshots miss short-lived objects and do not identify who caused a change. A generic inventory agent is not guaranteed to expose firmware or kernel-level details.

  • Record the lab scope, collector version, effective configuration and expected source fields before testing.
  • Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
  • Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
  • Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.

Primary sources

Connected ecosystem references

Linked tags

Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.

Attack tools through shared TTPs

These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.