1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / telemetry

Operational document access audit — Detection Telemetry

Access to operational documentation through a repository or document service.

Collection and providers

Enable document-read/download audit on the lab repository; retain document ID, identity and result without storing document bodies.

  • Application audit logs: First-party service events and request/result fields; schema is application-specific.
  • OpenTelemetry-compatible log pipelines: Transport and normalization of emitted records; do not create missing audit instrumentation.

Configuration

  • Enable the application audit category or instrument the owned lab application at the authorization/action boundary.
  • Define a schema with timestamp, service, actor, object, action, result and correlation ID. Export structured records through an authenticated collector.
  • Redact secrets and personal content, separate audit from debug logs, set retention and verify delivery during rotation/restart.

Synthetic event example

Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.

{
  "schema": "1200km.telemetry.example.v1",
  "synthetic": true,
  "timestamp": "2026-09-27T12:00:00Z",
  "telemetry_id": "proposed-operational-document-access-audit",
  "collector": "illustrative-lab-collector",
  "observation": {
    "document_id": "lab-procedure-1",
    "actor": "lab-reader",
    "action": "download",
    "result": "success"
  }
}

Visibility and validation

Debug output is not necessarily a durable audit trail. Application developers must emit the relevant event; installing a log pipeline does not make an absent event exist.

  • Record the lab scope, collector version, effective configuration and expected source fields before testing.
  • Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
  • Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
  • Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.

Primary sources

Connected ecosystem references

Linked tags

Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.

Attack tools through shared TTPs

These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.

No reviewed association in this snapshot.

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.