Inclusion criteria describe evidence that can establish this activity. Exclusion criteria identify circumstances that do not establish it on that basis alone. The evaluation remains connected to its taxonomy version and supporting evidence.
Included when supported
Evidence may support involvement when it matches one or more of these inclusion criteria.
- 01Criterion
Include malware, destructive code, ransomware, wipers, implants, command-and-control frameworks, or comparable tools specifically designed or materially modified for offensive cyber operations.
- 02Criterion
Include exploit chains, zero-day exploit products, intrusion platforms, initial-access capabilities, and access-as-a-service offerings intended to obtain covert or unauthorized system access.
- 03Criterion
Include commercial or government spyware and device-intrusion systems designed to covertly access devices, communications, sensors, credentials, or stored data without the subject’s informed authorization.
- 04Criterion
Include managed offensive cyber operations, intrusion services, exploit delivery, and operational support where the entity knowingly conducts or supplies the offensive capability.
Excluded on this basis alone
These circumstances do not establish this activity unless separate evidence also meets an inclusion criterion.
- 01Criterion
Historical-Only Offensive Cyber or Intrusion-System Involvement
Defined as: Entities with verified past development, sale, supply, deployment, operation, or support of qualifying offensive-cyber or covert-intrusion systems, where reliable evidence establishes that the qualifying activity has fully ceased, been divested, transferred, dismantled, terminated, or otherwise ended and no current qualifying involvement remains. Historical-only activity does not qualify as current involvement. Preserve the historical record separately with the activity period, effective cessation or transfer date, relevant entity, product, programme, facility, or contract, and supporting evidence. Absence of recent evidence alone is not sufficient to establish cessation.
- 02Criterion
Exclude products and services designed only to prevent, detect, investigate, contain, or recover from cyber threats.
- 03Criterion
Exclude authorized penetration testing, red-team services, bug-bounty work, and security research conducted with the system owner’s authorization and without covert third-party deployment.
- 04Criterion
Exclude ordinary endpoint management, employee monitoring, parental controls, fraud prevention, and lawful-intercept systems that require authorized cooperation from the communications provider and do not covertly exploit the target device.
- 05Criterion
Exclude generic information technology, cloud, telecommunications, data hosting, systems integration, and software-development services without an offensive or covert-intrusion deliverable.
- 06Criterion
Exclude vulnerability discovery, disclosure, scanning, and proof-of-concept research when the entity does not operationalize, sell, or deploy the vulnerability as an offensive access capability.
- 07Criterion
Exclude sanctions, programme names, procurement references, or allegations that do not establish the entity, product, technical function, and qualifying role.
Evidence and evaluation methodology
How sources, entity pathways, decisions, qualifiers, and review history are handled.
Map screens to a client policy
How to choose provider screens, document coverage, and decide what happens after an outcome.