▸case-01 I need a security assessment report detailing how mobile devices in our fleet might be checked for active internet connectivity by malicious actors. Please evaluate the attack surface across Android and iOS platforms, review existing encryption mitigations, and return the findings formatted as a structured summary with platform applicability, risk severity, and recommended countermeasures. | fail→fail | 29,441 | 143,282 | +387% | 1 | 1 | 0% | 3,569 | 2,973 | -17% | 0 | 0 | — |
▸case-02 Can you analyze our mobile environment for susceptibility to network connection discovery tactics? Walk through the necessary verification steps for mobile OS endpoints, check whether traffic encryption defenses are adequate, and output your final analysis as a bulleted remediation and detection guide. | fail→fail | 36,036 | 27,831 | -23% | 1 | 1 | 0% | 3,052 | 4,122 | +35% | 0 | 0 | — |
▸case-03 We are conducting a mobile threat review regarding T1422.001 tactics on company smartphones. Please review the relevant CWE categories, assess detection coverage on handheld devices, and present the evaluation as a structured JSON object containing the risk finding, associated impact, and primary mitigation strategy. | fail→pass | 17,341 | 15,193 | -12% | 1 | 1 | 0% | 2,100 | 2,064 | -2% | 0 | 0 | — |
▸case-04 Our SOC wants to audit command-line discovery activity on managed Android devices. Engineers suggested searching logs for 'ifconfig' or 'ip link' to spot network checks. What exact command does MITRE ATT&CK Mobile T1422.001 document for checking active network connections via ADB shell? Provide a brief operational analysis. | pass→pass | 16,621 | 14,598 | -12% | 1 | 1 | 0% | 1,862 | 1,490 | -20% | 0 | 0 | — |
▸case-05 During an incident response investigation into Android malware, the team observed outbound ping requests right after installation. An analyst argues the malware is attempting local broadcast discovery to infect neighboring laptops. Based on ATT&CK Mobile T1422.001, why do adversaries perform internet connection discovery before initiating primary payload activity? Provide your rationale in a short technical summary. | fail→pass | 17,390 | 6,416 | -63% | 1 | 1 | 0% | 1,676 | 1,525 | -9% | 0 | 0 | — |
▸case-10 Our mobile app security team is selecting mitigations for T1422.001. A consultant suggested implementing M1037 (Filter Network Traffic) or M1042 (Disable or Remove Feature/Program). What is the specific MITRE Mobile mitigation ID and title cataloged for T1422.001? Present the mitigation in an executive recommendation note. | fail→pass | 15,909 | 26,903 | +69% | 1 | 1 | 0% | 3,076 | 1,950 | -37% | 0 | 0 | — |
▸case-06 We are updating our SIEM rule taxonomy for mobile threats. An analyst classified sub-technique T1422.001 under parent technique T1082 (System Information Discovery). Please clarify the correct parent ATT&CK technique code and title for T1422.001 in a short mapping report. | fail→pass | 12,023 | 12,439 | +3% | 1 | 1 | 0% | 2,354 | 1,877 | -20% | 0 | 0 | — |
▸case-07 Our compliance officer is mapping mobile threat vectors to MITRE ATT&CK tactics. They placed T1422.001 under the Command and Control (TA0011) tactic group because connection tests precede C2 beaconing. What is the official ATT&CK Kill Chain Phase and tactic ID for T1422.001? Answer with a quick technical verification. | fail→pass | 33,248 | 9,862 | -70% | 1 | 1 | 0% | 1,832 | 1,280 | -30% | 0 | 0 | — |
▸case-08 A security vendor claims their desktop firewall rule set mitigates T1422.001 across Windows Server 2022 and Red Hat Enterprise Linux. Which mobile operating system platforms are actually targeted by ATT&CK sub-technique T1422.001? Provide a platform scope breakdown. | pass→pass | 42,531 | 16,031 | -62% | 1 | 1 | 0% | 2,818 | 1,824 | -35% | 0 | 0 | — |
▸case-09 An appsec scanner flagged a mobile application for improper input validation (CWE-20) and hardcoded credentials (CWE-798) in relation to T1422.001. Which specific CWE identifier is assigned to T1422.001 Internet Connection Discovery? Respond with the CWE ID and official title. | pass→pass | 31,828 | 18,787 | -41% | 1 | 1 | 0% | 5,109 | 911 | -82% | 0 | 0 | — |
▸case-11 A threat modeling audit requires exact counts of official mitigations and detection strategies for ATT&CK T1422.001. The auditor assumes there are 4 mitigations and 3 detection strategies available. How many known mitigations and detection strategies are cataloged for T1422.001? Output a concise metric summary. | fail→pass | 21,706 | 4,334 | -80% | 1 | 1 | 0% | 4,181 | 1,148 | -73% | 0 | 0 | — |
▸case-12 In our risk register, an engineer assigned a Critical severity rating to the finding 'Internet Connection Discovery technique applicable'. What is the standard severity rating specified for this finding in T1422.001 threat assessments? Respond with the finding title and severity. | fail→pass | 25,142 | 2,390 | -90% | 1 | 1 | 0% | 3,734 | 798 | -79% | 0 | 0 | — |
▸case-13 When recording a vulnerability assessment finding for T1422.001 applicability, our team logged the impact category as Credential Access. What is the impact category assigned to this finding in T1422.001 risk assessments? Provide the verified impact classification. | pass→pass | 34,014 | 8,610 | -75% | 1 | 1 | 0% | 5,410 | 797 | -85% | 0 | 0 | — |
▸case-14 A SOC analyst asks why malware inspects intermediate network responses during internet connection checks instead of simply pinging 8.8.8.8. Beyond confirming basic internet connectivity, what network infrastructure details do adversaries aim to identify from these responses according to ATT&CK T1422.001? | fail→pass | 14,474 | 18,009 | +24% | 1 | 1 | 0% | 2,153 | 1,700 | -21% | 0 | 0 | — |
▸case-15 We need a multi-step mobile environment readiness checklist for T1422.001. A draft proposal focuses solely on desktop web browsers. What specific mobile platform checks should be included in the verification checklist for T1422.001? Summarize the checklist steps. | fail→pass | 22,702 | 20,711 | -9% | 1 | 1 | 0% | 2,826 | 3,375 | +19% | 0 | 0 | — |
▸case-16 A developer asks why encrypting network traffic (M1009) helps counter T1422.001 internet connection discovery when malware can still originate requests. Explain the operational objective of M1009 as described in T1422.001 remediation guidance. | fail→pass | 23,217 | 16,871 | -27% | 1 | 1 | 0% | 2,339 | 2,279 | -3% | 0 | 0 | — |
▸case-17 Our threat intelligence platform requires canonical reference links for ATT&CK Mobile T1422.001. An analyst provided a generic blog post on Wireshark. Which specific external references are listed for T1422.001 documentation and command reference? Provide the reference sources. | fail→pass | 16,614 | 11,195 | -33% | 1 | 1 | 0% | 2,981 | 1,497 | -50% | 0 | 0 | — |
▸case-18 A forensic engineer looking for evidence of connection discovery on a rooted Android device reviewed command history for `adb shell ip route`. Is this the specific command cited for Android internet connection discovery in T1422.001? Provide the correct command syntax and tool context. | fail→pass | 22,537 | 9,784 | -57% | 1 | 1 | 0% | 2,565 | 1,158 | -55% | 0 | 0 | — |
▸case-19 A mobile fleet administrator wants to implement countermeasures for T1422.001. They propose revoking runtime SMS permissions across all enterprise devices. According to T1422.001 remediation guidance, what primary defense measure should be implemented? Detail the remediation step. | fail→pass | 27,783 | 15,098 | -46% | 1 | 1 | 0% | 3,279 | 1,904 | -42% | 0 | 0 | — |
▸case-20 We are auditing enterprise Linux endpoints for MITRE ATT&CK T1049 (System Network Connections Discovery). The analyst wants to know if T1049 relies on mobile ADB commands and whether traffic encryption (M1009) is its sole mitigation on server subnets. Provide a standard assessment of T1049. | pass→pass | 26,509 | 27,419 | +3% | 1 | 1 | 0% | 3,031 | 3,605 | +19% | 0 | 0 | — |
▸case-21 Our mobile incident response team is investigating T1420 (System Information Discovery) on compromised Android handhelds. An analyst asks if T1420 is identical to T1422.001 and whether it only checks active socket connections via netstat. Differentiate T1420 from internet connection discovery. | pass→pass | 27,077 | 20,833 | -23% | 1 | 1 | 0% | 3,733 | 2,896 | -22% | 0 | 0 | — |
▸case-22 A mobile app review flagged potential location tracking tactics corresponding to MITRE ATT&CK Mobile T1430. The developer asks if T1430 is mitigated by M1009 Encrypt Network Traffic and classified under CWE-200 for internet connectivity probes. Provide an accurate evaluation of T1430. | pass→pass | 26,488 | 25,379 | -4% | 1 | 1 | 0% | 3,101 | 3,557 | +15% | 0 | 0 | — |
▸case-23 When building an automated reporting template for mobile threat assessments, a designer defaulted the finding 'Internet Connection Discovery technique applicable' to High severity with Impact: Exfiltrate. What are the precise severity and impact values specified for this finding in T1422.001? | fail→pass | 19,883 | 7,490 | -62% | 1 | 1 | 0% | 2,565 | 791 | -69% | 0 | 0 | — |