{
  "node_id": "mitre-attack-mobile-t1629-002-device-lockout",
  "title": "MITRE ATT&CK Mobile T1629.002: Device Lockout (Mobile Tactic TA0030 - Defense Evasion)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-05-25",
  "bluf": "MITRE ATT&CK T1629.002 (Device Lockout) is an ATT&CK for Mobile Defense Evasion sub-technique of T1629 (Impair Defenses). An adversary may seek to inhibit user interaction by locking the legitimate user out of the device. This is typically accomplished by requesting device administrator permissions and then locking the screen using DevicePolicyManager.lockNow(). Other novel techniques for locking the user out of the device have been observed, such as showing a persistent overlay, using carefully crafted \"call\" notification screens, and locking HTML pages in the foreground. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "mitre_d3fend"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022",
    "nist-sp-800-53-r5",
    "cis-controls-v8",
    "mitre-attack-mobile-t1629-impair-defenses"
  ],
  "primary_citations_count": 6
}