Detection of Execution Guardrails

Technique Detected:  Execution Guardrails | T1627

ID: DET0653
Domains: Mobile
Analytics: AN1737, AN1738
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1737

The user can review which applications have location and sensitive phone information permissions in the operating system’s settings menu.
Application vetting services can detect unnecessary and potentially abused API calls.
Application vetting services can detect unnecessary and potentially abused permissions.

Log Sources
Data Component Name Channel
System Settings (DC0118) User Interface None
API Calls (DC0112) Application Vetting None
Permissions Requests (DC0114) Application Vetting None

AN1738

The user can review which applications have location and sensitive phone information permissions in the operating system’s settings menu.
Application vetting services can detect unnecessary and potentially abused API calls.
Application vetting services can detect unnecessary and potentially abused permissions.

Log Sources
Data Component Name Channel
System Settings (DC0118) User Interface None
API Calls (DC0112) Application Vetting None
Permissions Requests (DC0114) Application Vetting None