Evaluated screen

Offensive Cyber and Intrusion Systems

Identifies companies and other entities that develop, operate, sell, license, or knowingly supply malware, exploits, spyware, intrusion platforms, access-as-a-service, or managed capabilities specifically designed or materially modified to obtain covert or unauthorized access, exfiltrate information, manipulate systems, or disrupt, degrade, damage, or deny information systems. The screen covers military, intelligence, law-enforcement, and commercial customers where the product’s technical function is offensive or covert intrusion. Defensive cybersecurity, authorized testing, vulnerability research without operationalized exploit delivery, lawful-intercept systems dependent on carrier cooperation, and generic information technology are excluded.

Type
Evaluated
Version
2026.08.21.2
Published
Aug 21, 2026
Inclusions
4
Exclusions
7
How to read this definition

Inclusion criteria describe evidence that can establish this activity. Exclusion criteria identify circumstances that do not establish it on that basis alone. The evaluation remains connected to its taxonomy version and supporting evidence.

Can establish this activity

Included when supported

Evidence may support involvement when it matches one or more of these inclusion criteria.

4 criteria
  1. 01Criterion

    Include malware, destructive code, ransomware, wipers, implants, command-and-control frameworks, or comparable tools specifically designed or materially modified for offensive cyber operations.

  2. 02Criterion

    Include exploit chains, zero-day exploit products, intrusion platforms, initial-access capabilities, and access-as-a-service offerings intended to obtain covert or unauthorized system access.

  3. 03Criterion

    Include commercial or government spyware and device-intrusion systems designed to covertly access devices, communications, sensors, credentials, or stored data without the subject’s informed authorization.

  4. 04Criterion

    Include managed offensive cyber operations, intrusion services, exploit delivery, and operational support where the entity knowingly conducts or supplies the offensive capability.

Does not establish this activity on its own

Excluded on this basis alone

These circumstances do not establish this activity unless separate evidence also meets an inclusion criterion.

7 criteria
  1. 01Criterion

    Historical-Only Offensive Cyber or Intrusion-System Involvement

    Defined as: Entities with verified past development, sale, supply, deployment, operation, or support of qualifying offensive-cyber or covert-intrusion systems, where reliable evidence establishes that the qualifying activity has fully ceased, been divested, transferred, dismantled, terminated, or otherwise ended and no current qualifying involvement remains. Historical-only activity does not qualify as current involvement. Preserve the historical record separately with the activity period, effective cessation or transfer date, relevant entity, product, programme, facility, or contract, and supporting evidence. Absence of recent evidence alone is not sufficient to establish cessation.

  2. 02Criterion

    Exclude products and services designed only to prevent, detect, investigate, contain, or recover from cyber threats.

  3. 03Criterion

    Exclude authorized penetration testing, red-team services, bug-bounty work, and security research conducted with the system owner’s authorization and without covert third-party deployment.

  4. 04Criterion

    Exclude ordinary endpoint management, employee monitoring, parental controls, fraud prevention, and lawful-intercept systems that require authorized cooperation from the communications provider and do not covertly exploit the target device.

  5. 05Criterion

    Exclude generic information technology, cloud, telecommunications, data hosting, systems integration, and software-development services without an offensive or covert-intrusion deliverable.

  6. 06Criterion

    Exclude vulnerability discovery, disclosure, scanning, and proof-of-concept research when the entity does not operationalize, sell, or deploy the vulnerability as an offensive access capability.

  7. 07Criterion

    Exclude sanctions, programme names, procurement references, or allegations that do not establish the entity, product, technical function, and qualifying role.

Evidence and evaluation methodology

How sources, entity pathways, decisions, qualifiers, and review history are handled.

Map screens to a client policy

How to choose provider screens, document coverage, and decide what happens after an outcome.

Other screens under Military Cyber and Electronic Warfare Systems