Detection of Hijack Execution Flow

Technique Detected:  Hijack Execution Flow | T1625

ID: DET0694
Domains: Mobile
Analytics: AN1807
Version: 1.0
Created: 21 October 2025
Last Modified: 21 October 2025

Analytics

AN1807

Mobile threat defense agents could detect unauthorized operating system modifications by using attestation.

Log Sources
Data Component Name Channel
Host Status (DC0018) Sensor Health None