Skip to content

DET0694 Detection of Hijack Execution Flow

Item Value
ID DET0694
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1625 (Hijack Execution Flow)

Analytics

Android

AN1807

Mobile threat defense agents could detect unauthorized operating system modifications by using attestation.

Log Sources
Data Component Name Channel
Host Status (DC0018) Sensor Health None
Mutable Elements
Field Description