1200KM / telemetry
Device Alarm — Detection Telemetry
Device-generated alarms about equipment or controller state.
Collection and providers
Subscribe to supported device alarm/audit channels; retain code, severity, source asset and acknowledgement/clear times.
- OPC UA audit-capable servers: Auditable actions where supported and enabled; inspect server conformance and vendor documentation.
- Controller, HMI and historian exports: Vendor-specific process values, quality flags, alarms and operational context.
- Independent lab sensors / safety records: Physical-effect corroboration, not a universal cybersecurity log format.
Configuration
- Agree the measurement points, read-only interfaces, sampling intervals and safety boundary with the process owner. Use a simulator or non-production fixture.
- Subscribe to supported audit/alarm events or approved historian exports. Preserve source timestamp, quality, engineering units, asset/tag identity and clock offset.
- Compare independent measurements and record gaps/latency. Do not enable intrusive polling, change controller logic or alter safety setpoints merely to generate logs.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "DC0108",
"collector": "illustrative-lab-collector",
"observation": {
"asset_id": "lab-controller-1",
"alarm_code": "LAB_COMM_LOSS",
"severity": "warning",
"active": true
}
}Visibility and validation
There is no universal PLC event ID or configuration command. Visibility depends on vendor, protocol and process. An alarm or process deviation demonstrates an effect, not necessarily a cyberattack.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T0800 · Activate Firmware Update Mode · Detection rules & anomalies
- T0816 · Device Restart/Shutdown · Detection rules & anomalies
- T0821 · Modify Controller Tasking · Detection rules & anomalies
- T0836 · Modify Parameter · Detection rules & anomalies
- T0843 · Program Download · Detection rules & anomalies
- T0843.001 · Download All · Detection rules & anomalies
- T0843.002 · Online Edit · Detection rules & anomalies
- T0843.003 · Program Append · Detection rules & anomalies
- T0848 · Rogue Master · Detection rules & anomalies
- T0858 · Change Operating Mode · Detection rules & anomalies
- T0878 · Alarm Suppression · Detection rules & anomalies
- T0889 · Modify Program · Detection rules & anomalies
- T0892 · Change Credential · Detection rules & anomalies
- T1692.002 · Reporting Message · Detection rules & anomalies
- T1693 · Modify Firmware · Detection rules & anomalies
- T1693.001 · System Firmware · Detection rules & anomalies
- T1693.002 · Module Firmware · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
No reviewed association in this snapshot.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.