Skip to content

Hide Navigation Hide TOC

User Interface - DS0042 (55ba7d30-887f-42c1-a24e-c4e90aff24b8)

Visual activity on the device that could alert the user to potentially malicious behavior.

Cluster A Galaxy A Cluster B Galaxy B Level
User Interface - DS0042 (55ba7d30-887f-42c1-a24e-c4e90aff24b8) mitre-data-source System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component 1
User Interface - DS0042 (55ba7d30-887f-42c1-a24e-c4e90aff24b8) mitre-data-source System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 1
User Interface - DS0042 (55ba7d30-887f-42c1-a24e-c4e90aff24b8) mitre-data-source Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component 1
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Masquerading - T1655 (f856eaab-e84a-4265-a8a2-7bf37e5dc2fc) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Out of Band Data - T1644 (ec4c4baa-026f-43e8-8f56-58c36f3162dd) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Network Denial of Service - T1464 (d2e112dc-f6d4-488d-b8df-ecbfb57a0a2d) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component URI Hijacking - T1635.001 (789ef15a-34d9-4b32-a779-8cbbc9eb32f5) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Call Control - T1616 (351ddf79-2d3a-41b4-9bef-82ea5d3ccd69) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Geofencing - T1627.001 (e422b6fa-4739-46b9-992e-82f1b350c780) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Steal Application Access Token - T1635 (233fe2c0-cb41-4765-b454-e0087597fbce) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Remote Device Management Services - T1430.001 (9ef05e3d-52db-4c12-be4f-519214bbe91f) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Foreground Persistence - T1541 (648f8051-1a35-46d3-b1d8-3a3f5cf2cc8e) Attack Pattern 2
System Notifications (bf0ff551-a5a7-40e5-bff9-f9405011b1f4) mitre-data-component Match Legitimate Name or Location - T1655.001 (114fed8b-7eed-4136-8b9c-411c5c7fff4b) Attack Pattern 2
Execution Guardrails - T1627 (498e7b81-238d-404c-aa5e-332904d63286) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Generate Traffic from Victim - T1643 (a8e971b8-8dc7-4514-8249-ae95427ec467) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Hide Artifacts - T1628 (fc53309d-ebd5-4573-9242-57024ebdad4f) Attack Pattern 2
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Subvert Trust Controls - T1632 (79cb02f4-ac4e-4335-8b51-425c9573cce1) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component File Deletion - T1630.002 (ab7400b7-3476-4776-9545-ef3fa373de63) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Input Capture - T1417 (a8c31121-852b-46bd-9ba4-674ae5afe7ad) Attack Pattern 2
Code Signing Policy Modification - T1632.001 (fcb11f06-ce0e-490b-bcc1-04a1623579f0) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Input Injection - T1516 (d1f1337e-aea7-454c-86bd-482a98ffaf62) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Keylogging - T1417.001 (b1c95426-2550-4621-8028-ceebf28b3a47) Attack Pattern 2
Access Notifications - T1517 (39dd7871-f59b-495f-a9a5-3cb8cc50c9b2) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Uninstall Malicious Application - T1630.001 (0cdd66ad-26ac-4338-a764-4972a1e17ee3) Attack Pattern 2
Call Control - T1616 (351ddf79-2d3a-41b4-9bef-82ea5d3ccd69) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
Indicator Removal on Host - T1630 (0d4e3bbb-7af5-4c88-a215-0c0906bc1e8d) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Geofencing - T1627.001 (e422b6fa-4739-46b9-992e-82f1b350c780) Attack Pattern 2
Disable or Modify Tools - T1629.003 (2aa78dfd-cb6f-4c70-9408-137cfd96be49) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
Calendar Entries - T1636.001 (a9fa0d30-a8ff-45bf-922e-7720da0b7922) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern 2
Video Capture - T1512 (d8940e76-f9c1-4912-bea6-e21c251370b6) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
Endpoint Denial of Service - T1642 (eb6cf439-1bcb-4d10-bc68-1eed844ed7b3) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
GUI Input Capture - T1417.002 (4c58b7c6-a839-4789-bda9-9de33e4d4512) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
Device Administrator Permissions - T1626.001 (9c049d7b-c92a-4733-9381-27e2bd2ccadc) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Suppress Application Icon - T1628.001 (f05fc151-aa62-47e3-ae57-2d1b23d64bf6) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Location Tracking - T1430 (99e6295e-741b-4857-b6e5-64989eb039b4) Attack Pattern 2
Audio Capture - T1429 (6683aa0c-d98a-4f5b-ac57-ca7e9934a760) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
Prevent Application Removal - T1629.001 (dc01774a-d1c1-45fb-b506-0a5d1d6593d9) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Screen Capture - T1513 (73c26732-6422-4081-8b63-6d0ae93d449e) Attack Pattern 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Device Lockout - T1629.002 (acf8fd2a-dc98-43b4-8d37-64e10728e591) Attack Pattern 2
SMS Control - T1582 (b327a9c0-e709-495c-aa6e-00b042136e2b) Attack Pattern System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component 2
System Settings (56c2b384-77f8-461f-a71a-76f7888ebfb6) mitre-data-component Data Destruction - T1662 (9ef14445-6f35-4ed0-a042-5024f13a9242) Attack Pattern 2
Adversary-in-the-Middle - T1638 (08e22979-d320-48ed-8711-e7bf94aabb13) Attack Pattern Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component 2
Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component Remote Access Software - T1663 (0b761f2b-197a-40f2-b100-8152cb957c0c) Attack Pattern 2
Device Administrator Permissions - T1626.001 (9c049d7b-c92a-4733-9381-27e2bd2ccadc) Attack Pattern Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component 2
Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component File and Directory Discovery - T1420 (cf28ca46-1fd3-46b4-b1f6-ec0b72361848) Attack Pattern 2
Abuse Elevation Control Mechanism - T1626 (08ea902d-ecb5-47ed-a453-2798057bb2d3) Attack Pattern Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component 2
Permissions Request (e2f72131-14d1-411f-8e8c-aa3453dd5456) mitre-data-component Data Destruction - T1662 (9ef14445-6f35-4ed0-a042-5024f13a9242) Attack Pattern 2
Steal Application Access Token - T1635 (233fe2c0-cb41-4765-b454-e0087597fbce) Attack Pattern URI Hijacking - T1635.001 (789ef15a-34d9-4b32-a779-8cbbc9eb32f5) Attack Pattern 3
Execution Guardrails - T1627 (498e7b81-238d-404c-aa5e-332904d63286) Attack Pattern Geofencing - T1627.001 (e422b6fa-4739-46b9-992e-82f1b350c780) Attack Pattern 3
Remote Device Management Services - T1430.001 (9ef05e3d-52db-4c12-be4f-519214bbe91f) Attack Pattern Location Tracking - T1430 (99e6295e-741b-4857-b6e5-64989eb039b4) Attack Pattern 3
Masquerading - T1655 (f856eaab-e84a-4265-a8a2-7bf37e5dc2fc) Attack Pattern Match Legitimate Name or Location - T1655.001 (114fed8b-7eed-4136-8b9c-411c5c7fff4b) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Call Log - T1636.002 (1d1b1558-c833-482e-aabb-d07ef6eae63d) Attack Pattern 3
Indicator Removal on Host - T1630 (0d4e3bbb-7af5-4c88-a215-0c0906bc1e8d) Attack Pattern File Deletion - T1630.002 (ab7400b7-3476-4776-9545-ef3fa373de63) Attack Pattern 3
Code Signing Policy Modification - T1632.001 (fcb11f06-ce0e-490b-bcc1-04a1623579f0) Attack Pattern Subvert Trust Controls - T1632 (79cb02f4-ac4e-4335-8b51-425c9573cce1) Attack Pattern 3
Input Capture - T1417 (a8c31121-852b-46bd-9ba4-674ae5afe7ad) Attack Pattern Keylogging - T1417.001 (b1c95426-2550-4621-8028-ceebf28b3a47) Attack Pattern 3
Indicator Removal on Host - T1630 (0d4e3bbb-7af5-4c88-a215-0c0906bc1e8d) Attack Pattern Uninstall Malicious Application - T1630.001 (0cdd66ad-26ac-4338-a764-4972a1e17ee3) Attack Pattern 3
Disable or Modify Tools - T1629.003 (2aa78dfd-cb6f-4c70-9408-137cfd96be49) Attack Pattern Impair Defenses - T1629 (20b0931a-8952-42ca-975f-775bad295f1a) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Calendar Entries - T1636.001 (a9fa0d30-a8ff-45bf-922e-7720da0b7922) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern Contact List - T1636.003 (e0b9ecb8-a7d1-43c7-aa30-8e19c6a92c86) Attack Pattern 3
GUI Input Capture - T1417.002 (4c58b7c6-a839-4789-bda9-9de33e4d4512) Attack Pattern Input Capture - T1417 (a8c31121-852b-46bd-9ba4-674ae5afe7ad) Attack Pattern 3
Protected User Data - T1636 (11c2c2b7-1fd4-408f-bc2e-fe772ef9df5e) Attack Pattern SMS Messages - T1636.004 (c6421411-ae61-42bb-9098-73fddb315002) Attack Pattern 3
Device Administrator Permissions - T1626.001 (9c049d7b-c92a-4733-9381-27e2bd2ccadc) Attack Pattern Abuse Elevation Control Mechanism - T1626 (08ea902d-ecb5-47ed-a453-2798057bb2d3) Attack Pattern 3
Suppress Application Icon - T1628.001 (f05fc151-aa62-47e3-ae57-2d1b23d64bf6) Attack Pattern Hide Artifacts - T1628 (fc53309d-ebd5-4573-9242-57024ebdad4f) Attack Pattern 3
Prevent Application Removal - T1629.001 (dc01774a-d1c1-45fb-b506-0a5d1d6593d9) Attack Pattern Impair Defenses - T1629 (20b0931a-8952-42ca-975f-775bad295f1a) Attack Pattern 3
Impair Defenses - T1629 (20b0931a-8952-42ca-975f-775bad295f1a) Attack Pattern Device Lockout - T1629.002 (acf8fd2a-dc98-43b4-8d37-64e10728e591) Attack Pattern 3