1200KM / telemetry
Provider-side audit (if lawfully available) — Detection Telemetry
Audit records controlled by an external provider that may only be available through an authorized disclosure or account-owner export.
Collection and providers
Document legal/account-owner access and provider coverage before ingestion. Preserve original IDs, timestamps and disclosure limits; do not seek unauthorized access.
- Authorized provider/account-owner audit exports: Available only with the provider or account owner’s lawful access and supported export.
- CloudTrail in an owned lab account: A concrete lab-side example; it does not grant access to adversary-controlled accounts.
Configuration
- Establish the authorized account, record owner and export mechanism before collection. Without access, mark this input unavailable rather than simulating defender visibility.
- Preserve source event IDs, account/resource IDs, original timestamps and the authorized disclosure/export record.
- Document which events the provider actually exposes and compare delivered records to the request scope. Keep lab-side actions separate from victim-side evidence.
Synthetic event example
Project-normalized synthetic JSON, not a native provider log, captured event, attack verdict or validated detection. A parser/adapter is required for a real SIEM. Example names, IPs and values are fictional.
{
"schema": "1200km.telemetry.example.v1",
"synthetic": true,
"timestamp": "2026-09-27T12:00:00Z",
"telemetry_id": "proposed-provider-side-audit-if-lawfully-available",
"collector": "illustrative-lab-collector",
"observation": {
"provider_record_id": "lab-disclosure-1",
"access_basis": "authorized_test_account_export",
"action": "account_created",
"victim_network_observation": false
}
}Visibility and validation
Customer-accessible audit APIs do not expose arbitrary third-party accounts. A synthetic provider event cannot establish access, attribution or detection coverage in a real investigation.
- Record the lab scope, collector version, effective configuration and expected source fields before testing.
- Use an approved benign action or read-only snapshot appropriate to this type. For destructive, privileged or physical effects, use a reviewed fixture or existing authorized evidence instead of causing the effect.
- Verify the native source record locally and at the collector; compare timestamps, identity, object, action/result and the type-specific fields listed below. Save a redacted real capture separately from the synthetic example.
- Check a normal baseline and collector-loss case. Fixture parsing proves parser behavior only; it does not prove sensor coverage or malicious-behavior detection.
Primary sources
Connected ecosystem references
Linked tags
Related simulations and detection workspaces
Each workspace retains its own logsource and platform requirements. A technique-level association is not a per-rule sensor mapping.
- T1583.002 · DNS Server · Detection rules & anomalies
- T1583.005 · Botnet · Detection rules & anomalies
- T1584.005 · Botnet · Detection rules & anomalies
- T1585.002 · Email Accounts · Detection rules & anomalies
- T1585.003 · Cloud Accounts · Detection rules & anomalies
- T1586.002 · Email Accounts · Detection rules & anomalies
- T1586.003 · Cloud Accounts · Detection rules & anomalies
- T1587.004 · Exploits · Detection rules & anomalies
- T1588.005 · Exploits · Detection rules & anomalies
- T1588.006 · Vulnerabilities · Detection rules & anomalies
- T1588.007 · Artificial Intelligence · Detection rules & anomalies
- T1589.001 · Credentials · Detection rules & anomalies
- T1589.003 · Employee Names · Detection rules & anomalies
- T1590 · Gather Victim Network Information · Detection rules & anomalies
- T1590.001 · Domain Properties · Detection rules & anomalies
- T1590.002 · DNS · Detection rules & anomalies
- T1590.003 · Network Trust Dependencies · Detection rules & anomalies
- T1590.004 · Network Topology · Detection rules & anomalies
- T1590.005 · IP Addresses · Detection rules & anomalies
- T1590.006 · Network Security Appliances · Detection rules & anomalies
- T1591 · Gather Victim Org Information · Detection rules & anomalies
- T1591.001 · Determine Physical Locations · Detection rules & anomalies
- T1591.002 · Business Relationships · Detection rules & anomalies
- T1591.003 · Identify Business Tempo · Detection rules & anomalies
- T1591.004 · Identify Roles · Detection rules & anomalies
- T1592.003 · Firmware · Detection rules & anomalies
- T1593 · Search Open Websites/Domains · Detection rules & anomalies
- T1593.001 · Social Media · Detection rules & anomalies
- T1593.002 · Search Engines · Detection rules & anomalies
- T1593.003 · Code Repositories · Detection rules & anomalies
- T1596 · Search Open Technical Databases · Detection rules & anomalies
- T1596.001 · DNS/Passive DNS · Detection rules & anomalies
- T1596.002 · WHOIS · Detection rules & anomalies
- T1596.003 · Digital Certificates · Detection rules & anomalies
- T1596.004 · CDNs · Detection rules & anomalies
- T1596.005 · Scan Databases · Detection rules & anomalies
- T1597 · Search Closed Sources · Detection rules & anomalies
- T1597.001 · Threat Intel Vendors · Detection rules & anomalies
- T1597.002 · Purchase Technical Data · Detection rules & anomalies
- T1650 · Acquire Access · Detection rules & anomalies
- T1681 · Search Threat Vendor Data · Detection rules & anomalies
- T1682 · Query Public AI Services · Detection rules & anomalies
- T1683 · Generate Content · Detection rules & anomalies
- T1683.001 · Written Content · Detection rules & anomalies
- T1683.002 · Audio-Visual Content · Detection rules & anomalies
Attack tools through shared TTPs
These are two-hop navigation links through explicitly associated techniques, not independent tool-to-sensor assertions.
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.