1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / telemetry

Active DNS — Detection Telemetry

DNS results obtained through active queries rather than a historical passive observation.

Collection and providers

Record authorized query name/type, resolver, request time, response code and returned records. Keep active-query results separate from evidence that a victim made the same query.

  • ISC BIND dig: Explicit DNS lookups against a selected resolver; output contains answer and query context.
  • Zeek DNS logs: Passive corroboration when the active query crosses an authorized visible sensor.

Configuration

  • Select the owned lab resolver, allowed query names and record types. Use bounded queries, not unrestricted enumeration.
  • Retain full answer sections, response codes, TTLs, resolver address and query/collection timestamps; record cache and split-DNS context.
  • Store current resolutions separately from passive historical observations. Repeat only at an approved interval and record changes without inferring ownership.

Synthetic event example

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "DC0103",
  "collector": "illustrative-lab-collector",
  "observation": {
    "query": "lab.example.test",
    "rrtype": "A",
    "resolver": "192.0.2.53",
    "answer": "192.0.2.20",
    "response_code": "NOERROR"
  }
}

Visibility and validation

A resolution result is time- and resolver-dependent. Active queries generated by an analyst do not prove a target or adversary made those queries.

  • Record the lab scope, collector version, effective configuration and expected source fields before testing.
  • Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
  • Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
  • Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.

Primary sources

Connected ecosystem references

Linked tags

Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.

Attack tools through shared TTPs

These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.

No reviewed association in this snapshot.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.