LiveActive security incident?Get immediate response
MITRE ATT&CK® Mitigation

M1011: User Guidance

Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.

MobileM1011MitigationObject v1.0Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

M1011: User Guidance describes Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.

Executive priority

M1011: User Guidance is an official MITRE ATT&CK mitigation. Glexia treats it as defensive behavior context for prioritizing monitoring, control validation, and response planning without using the object by itself as an attribution claim.

Technical view

Security teams should validate M1011: User Guidance by reviewing the official ATT&CK relationships, mapped tactics (the mapped ATT&CK tactic context), supported platforms (the platforms named in the official object), and available local telemetry before making detection or mitigation decisions.

Likely telemetry

  • Official ATT&CK relationships and object metadata

Detection direction

  • Validate whether M1011: User Guidance appears in your detection coverage and tabletop scenarios.
  • Use the object to align executive risk language with SOC, incident response, and detection engineering work.
  • Do not treat ATT&CK relationship context as attribution without corroborating evidence.

Mitigation priorities

  • Map the object to existing controls and identify missing telemetry or response ownership.
  • Prioritize mitigations that reduce exposure on the listed platforms and tactics.
  • Review adjacent ATT&CK relationships before changing policy, detections, or reporting language.
Additional notes and limits

Baseline Glexia take generated from the official MITRE ATT&CK STIX object, source hash, tactics, platforms, and detection fields. It is safe to replace with a richer model-generated take for the same source hash later.

This baseline take is source-grounded and schema-validated, but it does not include environment-specific telemetry, incident evidence, or threat-intelligence corroboration.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

User Guidance

Describes any guidance or training given to users to set particular configuration settings or avoid specific potentially risky behaviors.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

ATT&CK relationship table

Techniques used

This mirrors the MITRE pattern of making group, software, campaign, and technique relationships scannable. Relationship notes come from mirrored ATT&CK relationship text when available.

49 rows
DomainIDNameRelationship / procedure
MobileT1541Foreground Persistence

If a user sees a persistent notification they do not recognize, they should uninstall the source application and look for other unwanted applications or anomalies.

MobileT1630.002File DeletionSub-technique

Users should be trained on what device administrator permission request prompts look like, and how to avoid granting permissions on phishing popups.

MobileT1660Phishing

Users can be trained to identify social engineering techniques and phishing emails.

MobileT1632Subvert Trust Controls

Typically, insecure or malicious configuration settings are not installed without the user's consent. Users should be advised not to install unexpected configuration settings (CA certificates, iOS Configuration Profiles, Mobile Device Management server provisioning).

MobileT1516Input Injection

Users should be warned against granting access to accessibility features, and to carefully scrutinize applications that request this dangerous permission.

MobileT1418.001Security Software DiscoverySub-technique

iOS users should be instructed to not download applications from unofficial sources, as applications distributed via the Apple App Store cannot list installed applications on a device.

MobileT1643Generate Traffic from Victim

Users should be advised that applications generally do not require permission to send SMS messages.

MobileT1658Exploitation for Client Execution

Users should be wary of iMessages from unknown senders. Additionally, users should be instructed not to open unrecognized links or other attachments in text messages.

MobileT1517Access Notifications

Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as access to notifications.

MobileT1430.001Remote Device Management ServicesSub-technique

Users should protect their account credentials and enable multi-factor authentication options when available.

MobileT1644Out of Band Data

Users should be instructed to not grant applications unexpected or unnecessary permissions.

MobileT1513Screen Capture

Users should be advised not to grant consent for screen captures to occur unless expected. Users should avoid enabling USB debugging (Android Debug Bridge) unless explicitly required.

MobileT1629.003Disable or Modify ToolsSub-technique

Users should be taught the dangers of rooting or jailbreaking their device.

MobileT1453Abuse Accessibility Features

First, users should be wary of clicking on suspicious text messages, links and emails. Secondly, users should be wary of granting applications accessibility features. Users may check applications that have been granted accessibility features by going to Settings, then Accessibility. Finally, users should be wary of downloading applications; although applications may be on the Google Play Store, they may not be benign (see Application Versioning).

MobileT1417Input Capture

Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as keyboard registration or accessibility service access.

MobileT1630.001Uninstall Malicious ApplicationSub-technique

Inform users that device rooting or granting unnecessary access to the accessibility service presents security risks that could be taken advantage of without their knowledge.

MobileT1521.003SSL PinningSub-technique

Users should be advised to not trust or install self-signed certificates.

MobileT1628.001Suppress Application IconSub-technique

Users should be shown what a synthetic activity looks like so they can scrutinize them in the future.

MobileT1635Steal Application Access Token

Users should be instructed to not open links in applications they don’t recognize.

MobileT1632.001Code Signing Policy ModificationSub-technique

Typically, insecure or malicious configuration settings are not installed without the user's consent. Users should be advised not to install unexpected configuration settings (CA certificates, iOS Configuration Profiles, Mobile Device Management server provisioning).

MobileT1640Account Access Removal

Users should be taught that Device Administrator permissions are very dangerous, and very few applications need it.

MobileT1627.001GeofencingSub-technique

Users should be advised to be extra scrutinous of applications that request location, and to deny any permissions requests for applications they do not recognize.

MobileT1418Software Discovery

iOS users should be instructed to not download applications from unofficial sources, as applications distributed via the Apple App Store cannot list installed applications on a device.

MobileT1676Linked Devices

For Android devices, users should be advised to enable Google Play Protect, which checks the device itself and the applications for malicious behavior. For iOS devices, users who are concerned about being targeted should consider enabling Lockdown Mode, which provides extreme protection of the device as well as data stored and transmitted. In general, users should be advised against scanning QR codes and/or clicking on suspicious links or text messages, which may masquerade as device-linking instructions by Signal or WhatsApp.

MobileT1636.002Call LogSub-technique

Call Log access an uncommonly needed permission, so users should be instructedto use extra scrutiny when granting access to their call logs.

MobileT1430Location Tracking

Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as access to location information. Users should also protect their account credentials and enable multi-factor authentication options when available.

MobileT1635.001URI HijackingSub-technique

Users should be instructed to not open links in applications they don’t recognize.

MobileT1662Data Destruction

Users should be trained on what device administrator permission request prompts look like, and how to avoid granting permissions on phishing popups.

MobileT1642Endpoint Denial of Service

Users should be cautioned against granting administrative access to applications.

MobileT1582SMS Control

Users should be encouraged to be very careful with what applications they grant SMS access to. Further, users should not change their default SMS handler to applications they do not recognize.CitationSMS KitKat

MobileT1629Impair Defenses

Providing user guidance around commonly abused features, such as the modal that requests for administrator permissions, should aid in preventing impairing defenses.

MobileT1417.001KeyloggingSub-technique

Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as keyboard registration or accessibility service access.

MobileT1616Call Control

Users should be encouraged to be very careful with what applications they grant phone call-based permissions to. Further, users should not change their default call handler to applications they do not recognize.

MobileT1627Execution Guardrails

Users should be advised to be extra scrutinous of applications that request location or sensitive phone information permissions, and to deny any permissions requests for applications they do not recognize.

MobileT1451SIM Card Swap

The user should become familiar with social engineering tactics that ask for Personally Identifiable Information (PII). Additionally, the user should include the use of hardware tokens, biometrics, and other non-SMS based authentication mechanisms where possible. Finally, the user should enable SIM swapping protections offered by the mobile carrier, such as setting up a PIN or password to authorize any changes to the account.

MobileT1626.001Device Administrator PermissionsSub-technique

Users should scrutinize every device administration permission request. If the request is not expected or the user does not recognize the application, the application should be uninstalled immediately.

MobileT1629.001Prevent Application RemovalSub-technique

Users should be warned against granting access to accessibility features and device administration services, and to carefully scrutinize applications that request these dangerous permissions. Users should be taught how to boot into safe mode to uninstall malicious applications that may be interfering with the uninstallation process.

MobileT1655.001Match Legitimate Name or LocationSub-technique

Users should be encouraged to only install apps from authorized app stores, which are less likely to contain malicious repackaged apps.

MobileT1458Replication Through Removable Media

Users should be advised not to use public charging stations or computers to charge their devices. Instead, users should be issued a charger acquired from a trustworthy source. Users should be advised not to click on device prompts to trust attached computers unless absolutely necessary.

MobileT1636Protected User Data

Users should be taught the danger behind granting unnecessary permissions to an application and should be advised to use extra scrutiny when an application requests them.

MobileT1655Masquerading

Users should be encouraged to only install apps from authorized app stores, which are less likely to contain malicious repackaged apps.

MobileT1636.004SMS MessagesSub-technique

Access to SMS messages is an uncommonly needed permission, so users should be instructed to use extra scrutiny when granting access to their SMS messages.

MobileT1636.001Calendar EntriesSub-technique

Calendar access is an uncommonly needed permission, so users should be instructed to use extra scrutiny when granting access to their device calendar.

MobileT1630Indicator Removal on Host

Inform users that device rooting or granting unnecessary access to the accessibility service presents security risks that could be taken advantage of without their knowledge.

MobileT1670Virtualization Solution

Users should be encouraged to only install apps from authorized app stores, which are less likely to contain malicious applications.

MobileT1663Remote Access Software

Users should be encouraged to be very careful with granting dangerous permissions, such as device administrator or access to device accessibility.

MobileT1636.003Contact ListSub-technique

Contact list access is an uncommonly needed permission, so users should be instructed to use extra scrutiny when granting access to their contact list.

MobileT1429Audio Capture

Users should be wary of granting applications dangerous or privacy-intrusive permissions, such as access to microphone or audio output.

MobileT1636.005AccountsSub-technique

Access to accounts is an uncommonly needed permission, so users should be instructed to use extra scrutiny when granting access to their accounts.

Relationship explorer

All related ATT&CK context

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.2
Object version
1.0
Created
Modified
Raw hash
78639487f8cddc8c...
Imported snapshots across ATT&CK releases(2)
ReleaseBundle importedObject versionModifiedStatusRaw hash
19.21.0Current bundle78639487f8cd…
19.11.0Older bundle78639487f8cd…
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source references

External references and citations

MITRE external references are preserved separately from Glexia analysis so citations remain traceable to their original source records.

  1. [1]
    mitre-attackM1011
    Open source URL
Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.