MITRE ATT&CK Matrix

MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. When Mobile Security detects a malicious application, it uses the MITRE ATT&CK tactics and techniques to categorize and represent the risks and damages that this application may cause.

For more information about the MITRE ATT&CK Matrix, see https://attack.mitre.org/techniques/mobile/

Note:

The MITRE ATT&CK Matrix is available only if the application contains malware.

  1. Go to Forensics > Application.
  2. Do one of these:
    1. If the application was installed on the tenant device, click View Application Risk.
    2. If the application file or URL was uploaded for analysis, click View MARS scores.
  3. Click the application in the table to view its details.
    Note:
    If you selected View MARS scores in step 2, click the application and then click App Info to view the application details.
  4. To view the attack technique description, click any of the MITRE ATT&CK Tactics (for example, T1532: Data Encrypted).

    The system opens a web page on the MITRE ATT&CK website that shows the description of the specific attack technique.

  5. To view the complete MITRE ATT&CK Matrix for the application, click Open MITRE ATT&CK full table.

    This matrix highlights the tactics and techniques used for the application.