Detection of Process Discovery

Technique Detected:  Process Discovery | T1424

ID: DET0692
Domains: Mobile
Analytics: AN1804, AN1805
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1804

Mobile security products can typically detect rooted devices, which is an indication that Process Discovery is possible. Application vetting could potentially detect when applications attempt to abuse root access or root the system itself. Further, application vetting services could look for attempted usage of legacy process discovery mechanisms, such as the usage of ps or inspection of the /proc directory.

Log Sources
Data Component Name Channel
API Calls (DC0112) Application Vetting None

AN1805

Mobile security products can typically detect rooted devices, which is an indication that Process Discovery is possible. Application vetting could potentially detect when applications attempt to abuse root access or root the system itself. Further, application vetting services could look for attempted usage of legacy process discovery mechanisms, such as the usage of ps or inspection of the /proc directory.

Log Sources
Data Component Name Channel
API Calls (DC0112) Application Vetting None