1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / telemetry

Certificate Registration — Detection Telemetry

Certificate issuance/registration context for infrastructure discovery and investigation.

Collection and providers

Ingest authorized certificate/CA or transparency observations with fingerprint, names, issuer and observation/issuance times; do not collect private keys.

  • Certificate Transparency logs / monitors: Public certificate observations; not proof of ownership or compromise.
  • Authorized CA inventory exports: Customer-controlled certificate state; revocation/expiry need their own checks.

Configuration

  • Use an approved feed/API or documented lawful export. Store retrieval time, source URL, original record ID, observation time and confidence separately.
  • Retain the raw response, licensing constraints and analyst assessment. Deduplicate observations without erasing independent provenance.
  • Correlate external context with authorized internal observations; do not label ownership, attribution or compromise from a shared indicator alone.

Synthetic event example

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0093",
  "collector": "illustrative-lab-collector",
  "observation": {
    "certificate_sha256": "cccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccccc",
    "dns_names": [
      "lab.example.test"
    ],
    "issuer": "Lab Test CA",
    "observation_source": "lab-ca-export"
  }
}

Visibility and validation

Coverage, licensing, redaction and reporting delays vary. External context is not proof of access to the target, and cannot substitute for unavailable provider-side audit.

  • Record the lab scope, collector version, effective configuration and expected source fields before testing.
  • Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
  • Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
  • Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.

Primary sources

Connected ecosystem references

Linked tags

Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.

Attack tools through shared TTPs

These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.

No reviewed association in this snapshot.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.