This application provides a method, apparatus, device, medium, and program product for security detection of application behavior, relating to the financial technology field. It includes: based on the startup status of a banking application installed on a terminal
device under test, in a trusted execution environment corresponding to the security
chip of the terminal device, real-time collection of sensitive behavior data of the banking application; in the trusted execution environment, risk analysis
processing of the sensitive behavior data is performed based on the historical
usage data of the banking application corresponding to the terminal device to determine the
risk category of the sensitive behavior data; based on the
risk category, a security report for the banking application is generated, and a security
report generation prompt is displayed; in response to the user's viewing operation of the prompt, abnormal behavior
verification is performed on the terminal device and the banking application in the trusted execution environment; if the
verification is successful, the security report is de-identified to obtain and display a de-identified security report. The method of this application improves the security of application behavior detection.