MITRE ATT&CK is a globally accessible knowledge base of adversary tactics and techniques based on real-world observations. When Mobile Security detects a malicious application, it uses the MITRE ATT&CK tactics and techniques to categorize and represent the risks and damages that this application may cause.
For more information about the MITRE ATT&CK Matrix, see https://attack.mitre.org/techniques/mobile/
Note:
The MITRE ATT&CK Matrix is available only if the application contains malware.
-
Go to Forensics > Application.
-
Do one of these:
-
If the application was installed on the tenant device, click View Application Risk.
-
If the application file or URL was uploaded for analysis, click View MARS scores.
-
Click the application in the table to view its details.
Note: If you selected View MARS scores in step 2, click the application and then click App Info to view the application details.
-
To view the attack technique description, click any of the MITRE ATT&CK Tactics (for example, T1532: Data Encrypted).
The system opens a web page on the MITRE ATT&CK website that shows the description of the specific attack technique.
-
To view the complete MITRE ATT&CK Matrix for the application, click Open MITRE ATT&CK full table.
This matrix highlights the tactics and techniques used for the application.
