Live Active security incident? Get immediate response
MITRE ATT&CK® Matrix

Mobile ATT&CK Matrix

A Glexia-styled visualization of ATT&CK tactics and techniques. This is not the MITRE Navigator UI and does not imply MITRE endorsement.

Matrix workbench

124 techniques and sub-techniques mapped across 12 tactics

Use this as a fast defensive coverage map. Each cell links to the normalized Glexia detail page with official source attribution and relationship context.

TA0035

Collection

24 techniques

T1409 Stored Application Data Android, iOS T1414 Clipboard Data Android, iOS T1417 Input Capture Android, iOS T1417.001 Keylogging Android, iOS T1417.002 GUI Input Capture Android, iOS T1429 Audio Capture Android, iOS T1430 Location Tracking Android, iOS T1430.001 Remote Device Management Services Android, iOS T1430.002 Impersonate SS7 Nodes Android, iOS T1453 Abuse Accessibility Features Android T1512 Video Capture Android, iOS T1513 Screen Capture Android T1517 Access Notifications Android T1532 Archive Collected Data Android, iOS T1533 Data from Local System Android, iOS T1616 Call Control Android T1636 Protected User Data Android, iOS T1636.001 Calendar Entries Android, iOS T1636.002 Call Log Android, iOS T1636.003 Contact List Android, iOS T1636.004 SMS Messages Android, iOS T1636.005 Accounts Android, iOS T1638 Adversary-in-the-Middle Android, iOS T1676 Linked Devices Android, iOS
TA0037

Command and Control

17 techniques

TA0031

Credential Access

10 techniques

TA0030

Defense Evasion

33 techniques

T1406 Obfuscated Files or Information Android, iOS T1406.001 Steganography Android T1406.002 Software Packing Android, iOS T1407 Download New Code at Runtime Android, iOS T1516 Input Injection Android T1541 Foreground Persistence Android T1575 Native API Android T1604 Proxy Through Victim Android T1617 Hooking Android T1627 Execution Guardrails Android, iOS T1627.001 Geofencing Android, iOS T1628 Hide Artifacts Android T1628.001 Suppress Application Icon Android T1628.002 User Evasion Android T1628.003 Conceal Multimedia Files Android T1629 Impair Defenses Android T1629.001 Prevent Application Removal Android T1629.002 Device Lockout Android T1629.003 Disable or Modify Tools Android T1630 Indicator Removal on Host iOS, Android T1630.001 Uninstall Malicious Application Android T1630.002 File Deletion Android T1630.003 Disguise Root/Jailbreak Indicators Android, iOS T1631 Process Injection Android, iOS T1631.001 Ptrace System Calls Android, iOS T1632 Subvert Trust Controls Android, iOS T1632.001 Code Signing Policy Modification Android, iOS T1633 Virtualization/Sandbox Evasion Android, iOS T1633.001 System Checks Android, iOS T1655 Masquerading Android, iOS T1655.001 Match Legitimate Name or Location Android, iOS T1661 Application Versioning Android, iOS T1670 Virtualization Solution Android
TA0032

Discovery

13 techniques

TA0041

Execution

5 techniques

TA0036

Exfiltration

3 techniques

TA0034

Impact

11 techniques

TA0027

Initial Access

11 techniques

TA0033

Lateral Movement

2 techniques

TA0028

Persistence

10 techniques

TA0029

Privilege Escalation

5 techniques

Exports

Structured JSON, CSV, and Navigator-layer export generation will use the normalized reference records after full sync. The current page is intentionally lightweight and source-backed.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.