Compliance Node Overview
MITRE ATT&CK T1636.003 (Contact List) is an ATT&CK for Mobile Collection sub-technique of T1636 (Protected User Data). Adversaries may utilize standard operating system APIs to gather contact list data. On Android, this can be accomplished using the Contacts Content Provider. On iOS, this can be accomplished using the Contacts framework. If the device has been jailbroken or rooted, an adversary may be able to access the Contact List without the user's knowledge or approval. Affected platforms: iOS, Android. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1636/003/
SHA-256 integrity: f303abad9bd71eef163d71d7d36fef5be89c428bf20ec4fb0c2acfd90137f62d
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1636.003: Contact List (https://attack.mitre.org/techniques/T1636/003/)
- MITRE ATT&CK Mobile Tactic TA0035: Collection (https://attack.mitre.org/tactics/TA0035/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.