1200KM / telemetry
External intelligence (context only) — Detection Telemetry
External observations that may contextualize adversary preparation but do not show access to a victim.
Collection and providers
Retain source provenance, confidence and temporal bounds; explicitly label observations outside victim visibility.
- Authorized intelligence feeds / STIX repositories: Provenance-bearing observations and analysis, not direct victim-side logs.
- RDAP registries/registrars: Registration context; public fields can be redacted or unavailable.
Configuration
- Use an approved feed/API or documented lawful export. Store retrieval time, source URL, original record ID, observation time and confidence separately.
- Retain the raw response, licensing constraints and analyst assessment. Deduplicate observations without erasing independent provenance.
- Correlate external context with authorized internal observations; do not label ownership, attribution or compromise from a shared indicator alone.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "proposed-external-intelligence-context-only",
"collector": "illustrative-lab-collector",
"observation": {
"indicator": "lab.example.test",
"source_record": "lab-feed-1",
"confidence": "context_only",
"victim_access_observed": false
}
}Visibility and validation
Coverage, licensing, redaction and reporting delays vary. External context is not proof of access to the target, and cannot substitute for unavailable provider-side audit.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1583.002 · DNS Server · Detection rules & anomalies
- T1583.005 · Botnet · Detection rules & anomalies
- T1584.005 · Botnet · Detection rules & anomalies
- T1585.002 · Email Accounts · Detection rules & anomalies
- T1585.003 · Cloud Accounts · Detection rules & anomalies
- T1586.002 · Email Accounts · Detection rules & anomalies
- T1586.003 · Cloud Accounts · Detection rules & anomalies
- T1587.004 · Exploits · Detection rules & anomalies
- T1588.005 · Exploits · Detection rules & anomalies
- T1588.006 · Vulnerabilities · Detection rules & anomalies
- T1588.007 · Artificial Intelligence · Detection rules & anomalies
- T1589.001 · Credentials · Detection rules & anomalies
- T1589.003 · Employee Names · Detection rules & anomalies
- T1590 · Gather Victim Network Information · Detection rules & anomalies
- T1590.001 · Domain Properties · Detection rules & anomalies
- T1590.002 · DNS · Detection rules & anomalies
- T1590.003 · Network Trust Dependencies · Detection rules & anomalies
- T1590.004 · Network Topology · Detection rules & anomalies
- T1590.005 · IP Addresses · Detection rules & anomalies
- T1590.006 · Network Security Appliances · Detection rules & anomalies
- T1591 · Gather Victim Org Information · Detection rules & anomalies
- T1591.001 · Determine Physical Locations · Detection rules & anomalies
- T1591.002 · Business Relationships · Detection rules & anomalies
- T1591.003 · Identify Business Tempo · Detection rules & anomalies
- T1591.004 · Identify Roles · Detection rules & anomalies
- T1592.003 · Firmware · Detection rules & anomalies
- T1593 · Search Open Websites/Domains · Detection rules & anomalies
- T1593.001 · Social Media · Detection rules & anomalies
- T1593.002 · Search Engines · Detection rules & anomalies
- T1593.003 · Code Repositories · Detection rules & anomalies
- T1596 · Search Open Technical Databases · Detection rules & anomalies
- T1596.001 · DNS/Passive DNS · Detection rules & anomalies
- T1596.002 · WHOIS · Detection rules & anomalies
- T1596.003 · Digital Certificates · Detection rules & anomalies
- T1596.004 · CDNs · Detection rules & anomalies
- T1596.005 · Scan Databases · Detection rules & anomalies
- T1597 · Search Closed Sources · Detection rules & anomalies
- T1597.001 · Threat Intel Vendors · Detection rules & anomalies
- T1597.002 · Purchase Technical Data · Detection rules & anomalies
- T1650 · Acquire Access · Detection rules & anomalies
- T1681 · Search Threat Vendor Data · Detection rules & anomalies
- T1682 · Query Public AI Services · Detection rules & anomalies
- T1683 · Generate Content · Detection rules & anomalies
- T1683.001 · Written Content · Detection rules & anomalies
- T1683.002 · Audio-Visual Content · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.