System Notifications

System Notifications represent operating system alerts, warnings, or status messages generated in response to application actions, system state changes, or security events. These notifications may indicate potentially malicious activity or abnormal application behavior.

Examples

  • Application requesting sensitive permissions
  • USB device connected notifications
  • Security warnings triggered by device configuration changes

Collection Methods

  • Mobile OS notification monitoring
  • Mobile EDR sensors
  • Device management telemetry
ID: DC0117
Domains: Mobile
Version: 2.1
Created: 13 March 2023
Last Modified: 10 March 2026

Log Sources

Name Channel
iOS:unifiedlog \"has pasted from\" cross-app paste notification text containing source app name
User Interface None

Detection Strategy