▸case-13 A compliance auditor requires standard catalog cross-references for the post-install code retrieval threat in mobile devices. Provide a compliance mapping document listing standard cross-references for post-install code retrieval across NIST Mobile Threat Catalogue items and industry threat research. | fail→pass | 32,600 | 22,236 | -32% | 1 | 1 | 0% | 3,725 | 3,683 | -1% | 0 | 0 | — |
▸case-01 We are auditing a mobile application that fetches external scripts and executable modules after installation. Please evaluate this runtime dynamic loading behavior against mobile security frameworks. Provide a structured assessment that covers platform-specific attack vectors for Android and iOS, evaluates existing OS-level mitigations, and includes a risk assessment table with impact and severity ratings. | fail→fail | 32,924 | 33,594 | +2% | 1 | 1 | 0% | 3,747 | 5,328 | +42% | 0 | 0 | — |
▸case-02 Our team is reviewing an enterprise app update mechanism where new runtime components are downloaded post-install. Conduct a threat evaluation for this technique, detailing what indicators to check on target mobile operating systems, the relevant CWE categories, and actionable remediation guidance to limit runtime execution capabilities. | fail→fail | 24,052 | 26,003 | +8% | 1 | 1 | 0% | 3,893 | 3,720 | -4% | 0 | 0 | — |
▸case-03 Can you perform a security review on the threat of post-installation dynamic code retrieval in mobile environments? Format the output as a formal security assessment that identifies the target attack surface, outlines detection check items, and lists the defensive recommendations and standard MITRE ATT&CK Mobile mappings. | fail→fail | 24,894 | 30,843 | +24% | 1 | 1 | 0% | 4,008 | 5,085 | +27% | 0 | 0 | — |
▸case-04 We are performing a mobile security assessment on an application's HTTPS network communications. The application communicates with backend REST endpoints using custom TLS certificate validation. Provide a technical report evaluating missing SSL/TLS certificate pinning risks, detail interception attack vectors, and outline remediation recommendations for network configuration. | pass→pass | 24,254 | 32,989 | +36% | 1 | 1 | 0% | 3,993 | 5,152 | +29% | 0 | 0 | — |
▸case-05 Conduct a mobile app security evaluation focusing on static reverse engineering risks. The application source code was compiled without symbol stripping or code obfuscation. Provide a technical assessment detailing the risks associated with static decompilation, reference the relevant ATT&CK Mobile technique, and outline obfuscation recommendations. | pass→pass | 27,004 | 37,420 | +39% | 1 | 1 | 0% | 3,483 | 5,698 | +64% | 0 | 0 | — |
▸case-06 Our mobile security audit is inspecting local data storage security on Android and iOS. The app stores user credentials and session tokens in shared preferences and plist files on the device filesystem. Provide a security assessment evaluating the threat of unencrypted local data storage, reference the relevant ATT&CK Mobile technique, and list hardware-backed storage recommendations. | pass→pass | 26,018 | 24,701 | -5% | 1 | 1 | 0% | 3,416 | 3,940 | +15% | 0 | 0 | — |
▸case-07 An Android app security audit revealed that the app renders external WebViews with JavaScript bridging enabled, and also attempts to execute dynamic Dalvik DEX files loaded at runtime from a remote server. Provide a platform analysis evaluating the specific Android attack vectors for dynamic code loading, contrasting native code, Dalvik code, and WebView JavascriptInterface mechanisms. | pass→pass | 40,620 | 41,255 | +2% | 1 | 1 | 0% | 5,592 | 5,596 | +0% | 0 | 0 | — |
▸case-08 During an iOS app review, developers argue that iOS strictly enforces code signing, so post-install dynamic code execution cannot happen on non-jailbroken devices. Auditors suspect third-party hot-patching libraries might bypass static store reviews. Provide a technical assessment of post-installation dynamic code execution vectors on iOS, explicitly identifying common third-party patch libraries used for runtime JavaScript execution. | pass→pass | 34,488 | 29,455 | -15% | 1 | 1 | 0% | 3,646 | 4,449 | +22% | 0 | 0 | — |
▸case-09 Many developers assume downloading dynamic script updates post-installation should be rated as Critical severity because code is fetched over the wire. Provide a structured analysis detailing the standard weakness classification (CWE) and the formal risk severity rating used in ATT&CK-aligned mobile threat assessments. | fail→pass | 26,588 | 22,144 | -17% | 1 | 1 | 0% | 3,746 | 3,207 | -14% | 0 | 0 | — |
▸case-10 A development team wants to mitigate dynamic native code execution in their Android app by setting the app's compile SDK level. They plan to target API level 26. Provide an engineering evaluation analyzing API level thresholds for native code execution in internal app storage under mobile OS mitigations. | pass→pass | 19,979 | 21,970 | +10% | 1 | 1 | 0% | 3,266 | 4,205 | +29% | 0 | 0 | — |
▸case-11 When documenting mobile app dynamic code download findings in a threat report, the triage lead wants to classify this activity under Persistence (TA0003) with High severity. Provide a threat classification summary supplying the correct MITRE ATT&CK Mobile technique identifier, tactic phase, and risk severity mapping. | fail→pass | 35,946 | 14,946 | -58% | 1 | 1 | 0% | 4,348 | 2,215 | -49% | 0 | 0 | — |
▸case-12 Why do adversaries utilize dynamic code retrieval after installation rather than including all executable code in the original application package submitted to official app stores? Provide an evasion analysis explaining why adversaries perform dynamic code retrieval, how Execution Guardrails interact with this technique, and applicable detection strategies. | pass→pass | 26,411 | 25,815 | -2% | 1 | 1 | 0% | 3,781 | 3,320 | -12% | 0 | 0 | — |
▸case-14 Security engineers are creating automated check items to assess if an enterprise Android app environment is susceptible to dynamic runtime code execution. Provide a checklist of technical check items for inspecting Android runtime indicators across native, Dalvik, and web view vectors. | pass→pass | 29,341 | 34,914 | +19% | 1 | 1 | 0% | 4,084 | 4,828 | +18% | 0 | 0 | — |
▸case-15 An enterprise mobile application downloads remote JavaScript bundles at launch to modify UI behavior. Developers claim this does not present any defense evasion risk because no compiled C binary is downloaded. Provide an architectural evaluation assessing whether remote JavaScript bundle fetching via web view bridging constitutes dynamic runtime code execution. | pass→pass | 30,060 | 29,759 | -1% | 1 | 1 | 0% | 3,139 | 3,833 | +22% | 0 | 0 | — |
▸case-16 During a mobile penetration test report write-up, the tester needs to populate a risk assessment table for an app that dynamically fetches executable modules post-install. Provide a structured risk assessment table formatted with finding, severity, and impact according to mobile ATT&CK risk assessment standards. | fail→fail | 18,429 | 22,025 | +20% | 1 | 1 | 0% | 2,072 | 2,199 | +6% | 0 | 0 | — |
▸case-17 A security architect is performing attack surface identification for mobile platforms (Android and iOS) regarding post-installation code downloading. Provide a scoping document detailing the platform-specific attack surfaces that must be examined during initial mobile security assessments. | pass→pass | 42,140 | 36,305 | -14% | 1 | 1 | 0% | 4,673 | 5,307 | +14% | 0 | 0 | — |
▸case-18 Developers are asking for actionable remediation to prevent dynamic native code execution within their Android application's internal data directory. Provide actionable remediation guidance specifying OS version targeting requirements and explaining internal storage execution restrictions. | fail→pass | 27,852 | 17,748 | -36% | 1 | 1 | 0% | 3,097 | 3,530 | +14% | 0 | 0 | — |
▸case-19 A SOC team wants to implement detection rules for mobile devices downloading dynamic code at runtime. They assume static app analysis in CI/CD will catch all runtime code downloads. Provide a detection coverage report evaluating the limitations of static analysis and detailing required dynamic behavioral detection focus areas. | pass→pass | 36,674 | 35,917 | -2% | 1 | 1 | 0% | 4,198 | 5,132 | +22% | 0 | 0 | — |
▸case-20 Explain how CWE-693 relates to dynamic code loading in mobile applications and why this behavior is categorized under the Defense Evasion kill chain tactic. Provide an explanatory report linking CWE classification to post-installation dynamic code loading and Defense Evasion tactic alignment. | pass→pass | 35,795 | 24,188 | -32% | 1 | 1 | 0% | 4,075 | 4,331 | +6% | 0 | 0 | — |
▸case-21 A healthcare enterprise is reviewing a mobile app that downloads dynamic plugins at startup. Provide a formal threat classification report including MITRE technique mapping, tactic phase, target platforms, and OS level mitigation details. | fail→pass | 29,182 | 37,702 | +29% | 1 | 1 | 0% | 3,653 | 5,146 | +41% | 0 | 0 | — |
▸case-22 A threat model for an Android banking app evaluates the risk of adversaries decompiling the APK, injecting malicious code into the bytecode, repacking the app with a new signature, and distributing it on third-party app stores. Provide a threat evaluation report analyzing binary repacking, referencing the relevant ATT&CK Mobile technique, and detailing runtime integrity mitigations. | pass→pass | 35,617 | 33,661 | -5% | 1 | 1 | 0% | 4,189 | 5,072 | +21% | 0 | 0 | — |