Compliance Node Overview
MITRE ATT&CK T1629.002 (Device Lockout) is an ATT&CK for Mobile Defense Evasion sub-technique of T1629 (Impair Defenses). An adversary may seek to inhibit user interaction by locking the legitimate user out of the device. This is typically accomplished by requesting device administrator permissions and then locking the screen using DevicePolicyManager.lockNow(). Other novel techniques for locking the user out of the device have been observed, such as showing a persistent overlay, using carefully crafted "call" notification screens, and locking HTML pages in the foreground. Affected platforms: Android. MITRE-documented mitigations include M1006 Use Recent OS Version. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1629/002/
SHA-256 integrity: 789dd8934e1147d8b1d541dd4514f9dbc4c4a9f24f92385e25e3c1d45570d885
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1629.002: Device Lockout (https://attack.mitre.org/techniques/T1629/002/)
- MITRE ATT&CK Mobile Tactic TA0030: Defense Evasion (https://attack.mitre.org/tactics/TA0030/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.