Meta tags:
Headings (most frequently used words):
mobile, matrix,
Text of the page (most frequently used words):
techniques (31), data (25), discovery (20), access (18), application (18), software (16), system (16), capture (14), compromise (14), att (12), and (12), control (12), input (12), the (11), for (11), mobile (10), all (10), device (10), execution (10), network (9), service (8), injection (8), call (8), exfiltration (8), remote (8), exploitation (8), location (7), from (6), removal (6), over (6), protocol (6), services (6), abuse (6), through (6), process (6), evasion (6), api (6), persistence (6), supply (6), chain (6), mitre (5), ics (5), enterprise (5), none (5), defenses (5), information (5), tools (5), matrix (5), sms (4), denial (4), victim (4), manipulation (4), encrypted (4), impact (4), channel (4), non (4), communication (4), web (4), cryptography (4), user (4), impersonate (4), ss7 (4), nodes (4), management (4), tracking (4), linked (4), devices (4), gui (4), keylogging (4), clipboard (4), notifications (4), accessibility (4), features (4), replication (4), removable (4), media (4), file (4), hijacking (4), virtualization (4), code (4), ptrace (4), calls (4), files (4), native (4), foreground (4), runtime (4), versioning (4), privilege (4), escalation (4), scheduled (4), task (4), job (4), client (4), command (4), initial (4), are (3), policy (3), contact (3), cti (3), sub (3), tactics (3), matrices (3), hide (3), version (3), 2026 (2), corporation (2), domains (2), resources (2), reference (2), campaigns (2), groups (2), components (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), core (2), objects (2), generate (2), traffic (2), endpoint (2), transmitted (2), destruction (2), account (2), unencrypted (2), alternative (2), one (2), way (2), bidirectional (2), dead (2), drop (2), resolver (2), out (2), band (2), standard (2), port (2), ingress (2), tool (2), transfer (2), ssl (2), pinning (2), asymmetric (2), symmetric (2), domain (2), generation (2), algorithms (2), dynamic (2), resolution (2), protocols (2), layer (2), video (2), stored (2), screen (2), accounts (2), messages (2), list (2), log (2), calendar (2), entries (2), protected (2), local (2), audio (2), archive (2), collected (2), adversary (2), middle (2), connections (2), internet (2), connection (2), configuration (2), security (2), scanning (2), directory (2), uri (2), steal (2), token (2), keychain (2), credentials (2), password (2), store (2), checks (2), sandbox (2), solution (2), signing (2), modification (2), subvert (2), trust (2), controls (2), proxy (2), packing (2), steganography (2), obfuscated (2), match (2), legitimate (2), name (2), masquerading (2), disguise (2), root (2), jailbreak (2), indicators (2), deletion (2), uninstall (2), malicious (2), indicator (2), host (2), disable (2), modify (2), lockout (2), prevent (2), impair (2), hooking (2), conceal (2), multimedia (2), suppress (2), icon (2), artifacts (2), geofencing (2), guardrails (2), download (2), new (2), administrator (2), permissions (2), elevation (2), mechanism (2), hijack (2), flow (2), broadcast (2), receivers (2), event (2), triggered (2), binary (2), executable (2), boot (2), logon (2), initialization (2), scripts (2), unix (2), shell (2), scripting (2), interpreter (2), hardware (2), dependencies (2), development (2), sim (2), card (2), swap (2), phishing (2), lockscreen (2), bypass (2), drive (2), collection (2), lateral (2), movement (2), credential (2), defense (2), side (2), can (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, terms, use, reset, filters, help, show, flat, layout, live, permalink, view, navigator, below, representing, covers, involving, based, effects, that, used, adversaries, without, contains, following, platforms, ios, android, home, open, join, october, mclean, hotel, details, found, register, here, search, blog, contribute, benefactors, legal, branding, updates, history, engage, with, advisory, council, learn, more, about, get, started, detections,
Text of the page (random words):
matrix mobile mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home matrices mobile mobile mobile matrix below are the tactics and techniques representing the mitre att ck matrix for mobile the matrix covers techniques involving device access and network based effects that can be used by adversaries without device access the matrix contains information for the following platforms android ios view on the att ck navigator version permalink live version layout side side flat show sub techniques hide sub techniques help initial access execution persistence privilege escalation defense evasion credential access discovery lateral movement collection command and control exfiltration impact 8 techniques 4 techniques 8 techniques 3 techniques 17 techniques 6 techniques 8 techniques 2 techniques 15 techniques 9 techniques 2 techniques 10 techniques application versioning drive by compromise exploitation for initial access lockscreen bypass phishing replication through removable media sim card swap supply chain compromise 3 compromise software dependencies and development tools compromise hardware supply chain compromise software supply chain command and scripting interpreter 1 unix shell exploitation for client execution native api scheduled task job boot or logon initialization scripts compromise application executable compromise client software binary event triggered execution 1 broadcast receivers foreground persistence hijack execution flow 1 system runtime api hijacking linked devices scheduled task job abuse elevation control mechanism 1 device administrator permissions exploitation for privilege escalation process injection 1 ptrace system calls application versioning download new code at runtime execution guardrails 1 geofencing foreground persistence hide artifacts 3 suppress application icon user evasion conceal multimedia files hooking impair defenses 3 prevent application removal device lockout disable or modify tools indicator removal on host 3 uninstall malicious application file deletion disguise root jailbreak indicators input injection masquerading 1 match legitimate name or location native api obfuscated files or information 2 steganography software packing process injection 1 ptrace system calls proxy through victim subvert trust controls 1 code signing policy modification virtualization solution virtualization sandbox evasion 1 system checks abuse accessibility features access notifications clipboard data credentials from password store 1 keychain input capture 2 keylogging gui input capture steal application access token 1 uri hijacking file and directory discovery location tracking 2 remote device management services impersonate ss7 nodes network service scanning process discovery software discovery 1 security software discovery system information discovery system network configuration discovery 2 internet connection discovery wi fi discovery system network connections discovery exploitation of remote services replication through removable media abuse accessibility features access notifications adversary in the middle archive collected data audio capture call control clipboard data data from local system input capture 2 keylogging gui input capture linked devices location tracking 2 remote device management services impersonate ss7 nodes protected user data 5 calendar entries call log contact list sms messages accounts screen capture stored application data video capture application layer protocol 1 web protocols call control dynamic resolution 1 domain generation algorithms encrypted channel 3 symmetric cryptography asymmetric cryptography ssl pinning ingress tool transfer non standard port out of band data remote access software web service 3 dead drop resolver bidirectional communication one way communication exfiltration over alternative protocol 1 exfiltration over unencrypted non c2 protocol exfiltration over c2 channel account access removal call control data destruction data encrypted for impact data manipulation 1 transmitted data manipulation endpoint denial of service generate traffic from victim input injection network denial of service sms control initial access execution persistence privilege escalation defense evasion credential access discovery lateral movement collection command and control exfiltration impact 8 techniques 4 techniques 8 techniques 3 techniques 17 techniques 6 techniques 8 techniques 2 techniques 15 techniques 9 techniques 2 techniques 10 techniques application versioning drive by compromise exploitation for initial access lockscreen bypass phishing replication through removable media sim card swap supply chain compromise 3 compromise software dependencies and development tools compromise hardware supply chain compromise software supply chain command and scripting interpreter 1 unix shell exploitation for client execution native api scheduled task job boot or logon initialization scripts compromise application executable compromise client software binary event triggered execution 1 broadcast receivers foreground persistence hijack execution flow 1 system runtime api hijacking linked devices scheduled task job abuse elevation control mechanism 1 device administrator permissions exploitation for privilege escalation process injection 1 ptrace system calls application versioning download new code at runtime execution guardrails 1 geofencing foreground persistence hide artifacts 3 suppress application icon user evasion conceal multimedia files hooking impair defenses 3 prevent application removal device lockout disable or modify tools indicator removal on host 3 uninstall malicious application file deletion disguise root jailbreak indicators input injection masquerading 1 match legitimate name or location native api obfuscated files or information 2 steganography software packing process injection 1 ptrace system calls proxy through victim subvert trust controls 1 code signing policy modification virtualization solution virtualization sandbox evasion 1 system checks abuse accessibility features access notifications clipboard data credentials from password store 1 keychain input capture 2 keylogging gui input capture steal application access token 1 uri hijacking file and directory discovery location tracking 2 remote device management services impersonate ss7 nodes network service scanning process discovery software discovery 1 security software discovery system information discovery system network configuration discovery 2 internet connection discovery wi fi discovery system network connections discovery exploitation of remote services replication through removable media abuse accessibility features access notifications adversary in the middle archive collected data audio capture call control clipboard data data from local system input capture 2 keylogging gui input capture linked devices location tracking 2 remote device management services impersonate ss7 nodes protected user data 5 calendar entries call log contact list sms messages accounts screen capture stored application data video capture application layer protocol 1 web protocols call control dynamic resolution 1 domain generation algorithms encrypted channel 3 symmetric cryptography asymmetric cryptography ssl pinning ingress tool transfer non standard port out of band data remote access software web service 3 dead drop resolver bidirectional communication one way communication exfiltration over alternative protocol 1 exfiltration over unencrypted non c2 protocol exfiltration over c2 channel account access removal call control data destruction data encrypted for impact data manipulation 1 transmitted data manipulation endpoint denial of service generate traffic from victim input injection network denial of service sms control core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
|