Security events
Last updated August 6th, 2025
The following table provides additional security event details, expanding on the descriptions provided on the Security events page.
Some security events are Android OS and device model dependent. While configuring Security Log settings, refer to the Dependencies information of each event description to ensure that your devices are supported.
Essential security events
Event Name | Event Description | Severity | Type | MITRE Technique IDs | Default? |
---|---|---|---|---|---|
BOOT_COMPROMISED_SOFTWARE_BINARY |
Indicates the device boot binary is at risk of compromiseDependencies: none Notes: none Properties:
|
High | System | T1645 | Yes |
BOOT_STATE |
Indicates the device boot stateDependencies: none Notes: none Properties:
|
Low | System | - | Yes |
KEY_INPUT_CAPTURE_CAPABILITY |
Indicates when the key input capture permission for an app is enabledDependencies: none Notes: none Properties:
|
Low | Application | T1417 | No |
LOG_IS_FULL |
Indicates the on-device Knox Security Log is fullDependencies: none Notes: none Properties: none |
High | Audit | KNOX.1 | Yes |
PASSWORD_LOCKOUT |
Indicates when the device is locked out after the user has reached maximum password attemptsDependencies: none Notes: none Properties: none |
High | User | T1110 | No |
PERIPHERAL_ACCESS_THROUGH_POLICY_DETECTED_CAMERA |
Indicates when the device camera access has been detected while it is disabled by a system policyDependencies: none Not supported on the following device models:
Notes: none Properties: none |
High | System | KNOX.2 | No |
PERIPHERAL_ACCESS_THROUGH_POLICY_DETECTED_MIC |
Indicates when the device microphone access has been detected while it is disabled by a system policyDependencies: Not supported on the following device models:
Notes: none Properties: none |
High | System | KNOX.2 | No |
PREVENT_APP_REMOVAL_CAPABILITY |
Indicates when an app removal is preventedDependencies: none Notes: none Properties:
|
Low | Application | T1629 | No |
TAG_ADB_SHELL_INTERACTIVE |
Indicates an ADB interactive shell was opened via "adb shell"Dependencies: none Notes: none Properties: none |
Medium | Audit | T1623 | No |
TAG_ADMIN_HAS_REQUESTED_FULL_WIPE_OF_DEVICE |
Indicates an administrator requested full wipe of deviceDependencies: none Notes: none Properties:
|
Low | Audit | T1630 | No |
TAG_FAILED_TO_WIPE_USER_DATA |
Indicates the process of wiping user data on the device failed for a specific reasonDependencies: none Notes: none Properties:
|
Low | Audit | T1630 | No |
TAG_WIPING_DATA_IS_NOT_ALLOWED_FOR_THIS_USER |
Indicates the process of wiping data (factory reset) is not allowed for this userDependencies: none Notes: none Properties: none |
Low | Audit | T1630 | No |
USER_INTERACTION_CONTROL_CAPABILITY |
Indicates when the user screen control permission in a app is enabledDependencies: none Notes: none Properties:
|
Low | Application | T1516 | No |
Advanced security events
Event Name | Event Description | Severity | Type | MITRE Technique IDs | Default? |
---|---|---|---|---|---|
ACCESS_CALL_LOG_PERMISSION |
Indicates when an app has permission to access call logs on launchDependencies: none Notes: none Properties:
|
Low | Application | T1636 | No |
ACCESS_NOTIFICATION_PERMISSION |
Indicates when permission to access/manage notification in an app is enabledDependencies: none Notes: none Properties:
|
Low | Application | T1517 | No |
PROCESS_PRIVILEGE_ESCALATION |
Indicates when an app has transitioned from an acceptable uid/esuid/fsuid to a non-app idDependencies: Device models compatible with 32-bit apps (ABI) are not supported. These include:
Notes: none Properties:
|
High | Process | T1548, T1543 | No |
RESTRICTED_PERMISSION |
Indicates the launched app has 'restricted permission'Dependencies: none Notes: none Properties: none |
Low | Application | - | No |
SCREEN_CAPTURE_CAPABILITY |
Indicates when the use of device screen capture permission for an app is enabledDependencies: none Notes: none Properties: none |
Low | Application | T1513 | No |
SUSPICIOUS_URL_ACCESSED |
Indicates when the user tapped or clicked on a potentially suspicious URL on the deviceDependencies: 32-bit device models are not supported Notes: none Properties:
|
Medium | User | T1566, T1660 | No |
SUSPICIOUS_URL_DETECTED |
Indicates when the user has copied a potentially suspicious URL on the deviceDependencies: 32-bit device models are not supported Notes: none Properties:
|
Low | User | T1566, T1660 | No |
TAG_ADB_SHELL_CMD |
Indicates that a shell command was issued over ADB via adb shellDependencies: none Notes: Potentially high volume event, triggered when the device is being used with a USB cable or in wireless debug mode. Properties:
|
Low | Audit | - | No |
TAG_ADD_UNTRUSTED |
Indicates an administrator added a certificate to the trusted databaseDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ADDED_SSID_TO_THE_RESTRICTION_ALLOWLIST |
Indicates an administrator added a SSID to restriction allowlistDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ADDED_TO_CAMERA_ALLOWLIST |
Indicates an administrator added package and signature to camera allowlistDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ALLOWED_CAMERA |
Indicates an administrator allowed cameraDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ALLOWED_MICROPHONE |
Indicates an administrator allowed microphoneDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ALLOWED_TO_INSTALL_APPLICATION |
Indicates an administrator allowed application installDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_CHANGED_LOCK_SCREEN_STATE_TO_DISABLED |
Indicates an administrator changed lock screen state to disabledDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_CHANGED_NFC_STATE_CHANGE |
Indicates an administrator has allowed the NFC state changeDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_CHANGED_SCREEN_LOCK_TIME_OUT |
Indicates an administrator changed screen lock time outDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_DISALLOWED_MICROPHONE |
Indicates an administrator disallowed microphoneDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ENABLED_BLUETOOTH_DISCOVERABLE_STATE |
Indicates an administrator enabled bluetooth discoverable stateDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_ENABLED_WIFI_DIRECT |
Indicates an administrator enabled Wi-Fi directDependencies: none Notes: none Properties: none |
Low | Audit | - | No |
TAG_ADMIN_HAS_LOCKED_WORKSPACE |
Indicates an administrator locked workspaceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_REMOVED_ALL_SSID_FROM_THE_RESTRICTION_BLOCKLIST |
Indicates an administrator removed all SSIDs from restriction blocklistDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_REMOVED_SSID_FROM_THE_RESTRICTION_BLOCKLIST |
Indicates an administrator removed a SSID from restriction blocklistDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_SUCCESSFULLY_LOCKED_WORKSPACE |
Indicates an administrator successfully locked workspaceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_SUCCESSFULLY_UNLOCKED_WORKSPACE |
Indicates an administrator successfully unlocked workspaceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ADMIN_HAS_UNLOCKED_WORKSPACE |
Indicates an administrator unlocked workspaceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_APPLICATION_ACTION_FAILED_BECAUSE_OF_SIGNATURE_VERIFICATION_FAILURE |
Indicates the application action has failed because of signature verification failureDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_APPLICATION_INSTALLATION_NOT_ALLOWED_BECAUSE_SIGNED_UNTRUSTED_CA |
Indicates an app installation is not allowed because it is signed by an untrusted CADependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_APPLICATION_INSTALLATION_NOT_ALLOWED_BY_ADMIN_BLOCKLIST |
Indicates the application is being blocked from installation by a device policy enforced by an administratorDependencies: none Notes: none Properties:
|
Low | Application | - | No |
TAG_APPLICATION_INSTALLATION_NOT_ALLOWED_BY_ADMIN_INSTALLER_BLOCKLIST |
Indicates that an administrator has blocked the installation of an application from a specific installerDependencies: none Notes: none Properties:
|
Low | Application | - | No |
TAG_BACKUP_SERVICE_TOGGLED |
Indicates an administrator has enabled or disabled backup serviceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_BIND_TO_VPN_FAILED_COULD_NOT_FIND_PACKAGE |
Indicates when a bind to VPN vendor service failed as vendor package could not be foundDependencies: none Notes: none Properties:
|
Low | Network | - | No |
TAG_BLUETOOTH_CONNECTION |
Indicates the device attempts to connect to a Bluetooth deviceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_CERT_AUTHORITY_INSTALLED |
Indicates a new root certificate has been installed into system's trusted credential storageDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_CERT_AUTHORITY_REMOVED |
Indicates a new root certificate has been removed from system's trusted credential storageDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_ERROR_OCCURRED_WHILE_VALIDATING_PROFILE_INFORMATION_FOR_VENDOR |
Indicates that during VPN profile creation, an error occurred while validating vendorDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_KEY_INTEGRITY_VIOLATION |
Indicates a failed cryptographic key integrity checkDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_KEYGUARD_DISMISS_AUTH_ATTEMPT |
Indicates there has been an authentication attempt to dismiss the keyguardDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_LOG_BUFFER_SIZE_CRITICAL |
Indicates that the audit log buffer has reached 90% of its capacityDependencies: none Notes: none Properties: none |
Low | Audit | - | No |
TAG_MEDIA_MOUNT |
Indicates removable media has been mounted on the deviceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_MEDIA_UNMOUNT |
Indicates that removable media was unmounted from the deviceDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_MICROPHONE_ENABLED |
Indicates the microphone is enabledDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_PACKAGE_INSTALLED |
Indicates a package is installedDependencies: none Notes: none Properties:
|
Low | Application | - | No |
TAG_PACKAGE_NAME_HAS_BEEN_ACTIVATED_AS_ADMIN |
Indicates the application was activated as administratorDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_PACKAGE_NAME_HAS_BEEN_REMOVED_AS_ADMIN |
Indicates the application was removed as administratorDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_PACKAGE_UNINSTALLED |
Indicates a package is uninstalledDependencies: none Notes: none Properties:
|
Low | Application | - | No |
TAG_PACKAGE_UPDATED |
Indicates a package is updatedDependencies: none Notes: none Properties:
|
Low | Application | - | No |
TAG_PASSWORD_CHANGED |
Indicates the user has just changed their lock screen passwordDependencies: none Notes: none Properties:
|
Low | User | - | No |
TAG_PASSWORD_COMPLEXITY_REQUIRED |
Indicates an administrator has set a password complexity requirement, using the platform's pre-defined complexity levelsDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_PASSWORD_COMPLEXITY_SET |
Indicates an administrator has set a requirement for password complexityDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_REMOTE_LOCK |
Indicates an administrator remotely locked the device or profileDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_REMOVE_UNTRUSTED |
Indicates an administrator removed a certificate from the untrusted databaseDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_SYNC_RECV_FILE |
Indicates a file was pulled from the device via the adb daemon, for example via adb pullDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_SYNC_SEND_FILE |
Indicates a file was pushed to the device via the adb daemon, for example via adb pushDependencies: none Notes: none Properties:
|
Low | Audit | - | No |
TAG_WIPE_FAILURE |
Indicates a failure to wipe device or user dataDependencies: none Notes: none Properties: none |
Low | Audit | - | No |
VIDEO_CAPTURE_PERMISSION |
Indicates when the video capture permission is requested by the appDependencies: none Notes: none Properties:
|
Low | Application | T1512 | No |
On this page
Is this page helpful?