Skip to content

DET0649 Detection of Compromise Application Executable

Item Value
ID DET0649
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1577 (Compromise Application Executable)

Analytics

Android

AN1730

This behavior is seamless to the user and is typically undetectable.

Log Sources
Data Component Name Channel
Mutable Elements
Field Description