Compliance Node Overview
MITRE ATT&CK T1655.001 (Match Legitimate Name or Location) is an ATT&CK for Mobile Defense Evasion sub-technique of T1655 (Masquerading). Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them. This is done for the sake of evading defenses and observation. This may be done by giving artifacts the name and icon of a legitimate, trusted application (i.e., Settings), or using a package name that matches legitimate, trusted applications (i.e., com.google.android.gm). Adversaries may also use the same icon of the file or application they are trying to mimic. Affected platforms: Android, iOS. MITRE-documented mitigations include M1011 User Guidance. Mobile controls map to NIST SP 800-124 Rev 2 and OWASP MASVS.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1655/001/
SHA-256 integrity: d0830d2b7aa7266c49708a83fc2ccbb32a30ffd2a39248c2568d2a22e1bd471b
Primary Citations — 6 traced to source
- MITRE ATT&CK for Mobile Technique T1655.001: Match Legitimate Name or Location (https://attack.mitre.org/techniques/T1655/001/)
- MITRE ATT&CK Mobile Tactic TA0030: Defense Evasion (https://attack.mitre.org/tactics/TA0030/)
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.