Skip to content

DET0697 Detection of Abuse Accessibility Features

Item Value
ID DET0697
Version 1.0
Created 21 October 2025
Last Modified 21 October 2025

Technique Detected: T1453 (Abuse Accessibility Features)

Analytics

Android

AN1812

Application vetting services can look for applications requesting the permissions granting access to accessibility services or application overlay. The user can view a list of device administrators and applications that have registered Accessibility services in device settings. Applications that register an Accessibility service should be scrutinized further for malicious behavior.

Log Sources
Data Component Name Channel
Permissions Requests (DC0114) Application Vetting None
Permissions Request (DC0116) User Interface None
Mutable Elements
Field Description