Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence. Initialization scripts are part of the underlying operating system and are not accessible to the user unless the device has been rooted or jailbroken.
Install security updates in response to discovered vulnerabilities. Purchase devices with a vendor and/or mobile carrier commitment to provide security updates in a prompt manner for a set period of time. Decommission devices that will no longer receive security updates. Limit or block access to enterprise resources from devices that have not installed recent security updates. On Android devices, access can be controlled based on each device's security patch level. On iOS devices, access can be controlled based on the iOS version.
M1004System Partition IntegrityEnsure that Android devices being used include and enable the Verified Boot capability, which cryptographically ensures the integrity of the system partition.
M1002AttestationEnable remote attestation capabilities when available (such as Android SafetyNet or Samsung Knox TIMA Attestation) and prohibit devices that fail the attestation from accessing enterprise resources.
M1003Lock BootloaderOn devices that provide the capability to unlock the bootloader (hence allowing any operating system code to be flashed onto the device), perform periodic checks to ensure that the bootloader is locked.
MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.