Skip to content

DET0687 Detection of Impair Defenses

Item Value
ID DET0687
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1629 (Impair Defenses)

Analytics

Android

AN1797

Application vetting can detect many techniques associated with impairing device defenses.(Citation: Samsung Knox Mobile Threat Defense) Mobile security products integrated with Samsung Knox for Mobile Threat Defense can monitor processes to see if security tools are killed or stop running.

Log Sources
Data Component Name Channel
API Calls (DC0112) Application Vetting None
Process Termination (DC0033) Process None
Mutable Elements
Field Description