Skip to content

DET0606 Detection of Virtualization Solution

Item Value
ID DET0606
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1670 (Virtualization Solution)

Analytics

Android

AN1656

The user can view a list of device administrators and applications that have registered Accessibility services in device settings. Applications that register an Accessibility service or request device administrator permissions should be scrutinized further for malicious behavior. Application vetting services can look for applications that request permissions to Accessibility services or application overlay. Monitor for API calls that are related to GooglePlayServices.

Log Sources
Data Component Name Channel
Permissions Request (DC0116) User Interface None
Permissions Requests (DC0114) Application Vetting None
OS API Execution (DC0021) Process None
Mutable Elements
Field Description