What MITRE ATT&CK Mobile T1417.001: Keylogging (Mobile Tactic TA0035 - Collection / TA0031 - Credential Access) requires
MITRE ATT&CK T1417.001 (Keylogging) is an ATT&CK for Mobile Collection and Credential Access sub-technique of T1417 (Input Capture). Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them. Some methods of keylogging include: * Masquerading as a legitimate third-party keyboard to record user keystrokes. On both Android and iOS, users must explicitly authorize the use of third-party keyboard apps. Users should be advised to use extreme caution before granting this authorization when it is requested. * Abusing accessibility features. Affected platforms: Android, iOS. MITRE-documented mitigations include M1012 Enterprise Policy, M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1417/001/
SHA-256 integrity: 5b51621cb0a808989ea402fb64079fd980e8cbff30c862d5d6cebc386492ea8d
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1417.001: Keylogging (https://attack.mitre.org/techniques/T1417/001/)
- MITRE ATT&CK Mobile Tactic TA0035: Collection (https://attack.mitre.org/tactics/TA0035/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.