| G01 |
Runtime identity and execution context
|
| G01 T01 |
Identify current working directory
|
Allowed |
Allowed |
Allowed |
| G01 T02 |
Identify current user/account name
|
Allowed |
Allowed |
Allowed |
| G01 T03 |
Identify process ID
|
Allowed |
Allowed |
Allowed |
| G01 T04 |
Identify operating system family
|
Allowed |
Allowed |
Allowed |
| G01 T05 |
Identify CPU architecture
|
Allowed |
Allowed |
Allowed |
| G01 T06 |
Identify hostname or machine name
|
Allowed |
Allowed |
Allowed |
| G01 T07 |
Identify container/VM indicators
|
Allowed |
Allowed |
Allowed |
| G01 T08 |
Read command-line arguments
|
Allowed |
Allowed |
Allowed |
| G01 T09 |
Read process environment summary
|
Allowed |
Allowed |
Allowed |
| G01 T10 |
Detect container / VM / cloud runtime markers
|
Allowed |
Allowed |
Allowed |
| G01 T11 |
Read Linux cgroup and namespace status
|
Allowed |
Allowed |
Allowed |
| G01 T12 |
Read Linux confinement status
|
Allowed |
Allowed |
Allowed |
| G01 T13 |
Detect effective Linux capabilities
|
Allowed |
Allowed |
Allowed |
| G01 T14 |
Detect Windows integrity and containment status
|
N/A |
N/A |
N/A |
| G01 T15 |
Detect host identity and domain visibility
|
Allowed |
Allowed |
Allowed |
| G01 T16 |
Read Linux process namespace links
|
Allowed |
Allowed |
Allowed |
| G02 |
Basic filesystem read access
|
| G02 T01 |
Read a known file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G02 T02 |
List current directory
|
Allowed |
Allowed |
Allowed |
| G02 T03 |
List parent directory
|
Allowed |
Allowed |
Allowed |
| G02 T04 |
Read file metadata in allowed directory
|
Allowed |
Allowed |
Allowed |
| G02 T05 |
Read hidden/dot files in allowed directory
|
Error |
Denied |
Denied |
| G02 T06 |
Read user home directory listing
|
Allowed |
Allowed |
Allowed |
| G02 T07 |
Read application config directory
|
Error |
Denied |
Denied |
| G02 T08 |
Read temporary directory listing
|
Allowed |
Allowed |
Allowed |
| G02 T09 |
Read mounted/shared directory listing
|
N/A |
N/A |
N/A |
| G02 T10 |
Read a known file in denied directory
|
Allowed |
Allowed |
Allowed |
| G02 T11 |
Read file metadata in denied directory
|
Allowed |
Allowed |
Allowed |
| G02 T12 |
Read hidden/dot files in denied directory
|
Error |
Denied |
Denied |
| G02 T13 |
Read Linux namespace surface directories
|
Allowed |
Allowed |
Allowed |
| G02 T14 |
Read Linux service account secret files
|
N/A |
N/A |
N/A |
| G02 T15 |
Detect Linux mounted host paths and writable volumes
|
Allowed |
Allowed |
Allowed |
| G03 |
Filesystem write and modification access
|
| G03 T01 |
Create temporary file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T02 |
Write content to temporary file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T03 |
Append to existing temporary file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T04 |
Create directory in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T05 |
Rename file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T06 |
Copy file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T07 |
Delete temporary file in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T08 |
Change file permissions or attributes in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T09 |
Create symbolic link or shortcut in allowed directory
|
Allowed |
Allowed |
Allowed |
| G03 T10 |
Create temporary file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T11 |
Write content to temporary file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T12 |
Append to existing temporary file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T13 |
Create directory in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T14 |
Rename file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T15 |
Copy file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T16 |
Delete temporary file in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T17 |
Change file permissions or attributes in denied directory
|
Allowed |
Allowed |
Allowed |
| G03 T18 |
Create symbolic link or shortcut in denied directory
|
Allowed |
Allowed |
Allowed |
| G04 |
Filesystem persistence
|
| G04 T08 |
Detect available disk space
|
Allowed |
Allowed |
Allowed |
| G05 |
Environment variables and secrets exposure
|
| G05 T01 |
List environment variable names
|
Allowed |
Allowed |
Allowed |
| G05 T04 |
Read path/search-path variable
|
Allowed |
Allowed |
Allowed |
| G05 T05 |
Access model/API credentials in environment/config
|
Allowed |
Allowed |
Allowed |
| G06 |
Program and executable invocation
|
| G06 T01 |
Run harmless built-in command
|
Allowed |
Allowed |
Allowed |
| G06 T02 |
Run language interpreter
|
Allowed |
Allowed |
Allowed |
| G06 T03 |
Run shell command through shell
|
Allowed |
Allowed |
Allowed |
| G06 T04 |
Run command without shell
|
Allowed |
Allowed |
Allowed |
| G06 T05 |
Invoke package manager
|
Allowed |
Allowed |
Allowed |
| G06 T06 |
Invoke compiler or build tool
|
Allowed |
Allowed |
Allowed |
| G06 T07 |
Invoke test runner
|
N/A |
N/A |
Denied |
| G06 T09 |
Invoke system administration tool
|
Allowed |
Allowed |
Allowed |
| G06 T11 |
Run newly created script
|
Allowed |
Allowed |
Allowed |
| G06 T12 |
Load system native library
|
Allowed |
Allowed |
Allowed |
| G06 T13 |
Create and import Python module in allowed directory
|
Allowed |
Allowed |
Allowed |
| G06 T14 |
Call OS API with ctypes
|
Allowed |
Allowed |
Allowed |
| G06 T15 |
Spawn PowerShell with constrained-language detection
|
N/A |
N/A |
N/A |
| G07 |
Process control
|
| G07 T01 |
List own process information
|
Allowed |
Allowed |
Allowed |
| G07 T02 |
List child processes
|
Allowed |
Allowed |
Allowed |
| G07 T03 |
List all user processes
|
Allowed |
Allowed |
Allowed |
| G07 T04 |
List system-wide processes
|
Allowed |
Allowed |
Allowed |
| G07 T05 |
Start child process
|
Allowed |
Allowed |
Allowed |
| G07 T06 |
Terminate own child process
|
Allowed |
Allowed |
Allowed |
| G07 T08 |
Change process priority
|
Allowed |
Allowed |
Allowed |
| G08 |
Resource limits
|
| G08 T01 |
Query CPU count
|
Allowed |
Allowed |
Allowed |
| G09 |
Network access
|
| G09 T01 |
Resolve DNS name
|
Allowed |
Allowed |
Allowed |
| G09 T02 |
Connect to known HTTP endpoint
|
Allowed |
Allowed |
Allowed |
| G09 T03 |
Connect to known HTTPS endpoint
|
Allowed |
Allowed |
Allowed |
| G09 T05 |
Connect to allowlisted domain
|
Allowed |
Allowed |
Allowed |
| G09 T06 |
Connect to blocked test domain
|
Allowed |
Allowed |
Allowed |
| G09 T07 |
Connect to raw IP address
|
Allowed |
Allowed |
Allowed |
| G09 T08 |
Connect to non-HTTP port
|
Allowed |
Allowed |
Allowed |
| G09 T09 |
Send HTTP POST
|
Allowed |
Allowed |
Allowed |
| G09 T10 |
Download small file
|
Allowed |
Allowed |
Allowed |
| G09 T11 |
Start local listening socket
|
Allowed |
Allowed |
Allowed |
| G09 T12 |
Connect to local loopback service
|
Allowed |
Allowed |
Allowed |
| G09 T13 |
Connect to allowed localnet address
|
N/A |
N/A |
N/A |
| G09 T14 |
Connect to denied localnet address
|
N/A |
N/A |
N/A |
| G09 T15 |
UDP send/receive
|
Allowed |
Allowed |
Allowed |
| G09 T16 |
ICMP ping / raw socket creation
|
Denied |
Allowed |
Allowed |
| G09 T17 |
DNS over TCP vs UDP
|
Allowed |
Allowed |
Allowed |
| G09 T18 |
Connect to link-local metadata endpoint
|
Denied |
Denied |
Denied |
| G09 T19 |
Connect to allowed intranet target
|
N/A |
N/A |
N/A |
| G09 T20 |
Connect to denied intranet target
|
Allowed |
Allowed |
Allowed |
| G09 T21 |
Listen on loopback interface
|
Allowed |
Allowed |
Allowed |
| G09 T22 |
Listen on public/all interfaces
|
Allowed |
Allowed |
Allowed |
| G09 T23 |
Bind Linux privileged loopback port
|
Denied |
Denied |
Denied |
| G09 T24 |
Detect outbound proxy configuration
|
Allowed |
Allowed |
Allowed |
| G09 T25 |
Send DNS query with encoded payload
|
Allowed |
Allowed |
Allowed |
| G09 T26 |
Send HTTP request with custom headers/body to configured endpoint
|
Allowed |
Allowed |
Allowed |
| G09 T27 |
Open WebSocket connection to configured endpoint
|
Allowed |
Allowed |
Allowed |
| G09 T28 |
SMTP submission to configured test server
|
N/A |
N/A |
N/A |
| G10 |
Local service and metadata access
|
| G10 T01 |
Connect to allowed local address
|
N/A |
N/A |
N/A |
| G10 T02 |
Connect to denied local address
|
N/A |
N/A |
N/A |
| G10 T03 |
Detect open local ports
|
Allowed |
Allowed |
Allowed |
| G10 T04 |
Connect to allowed database address
|
N/A |
N/A |
N/A |
| G10 T05 |
Connect to denied database address
|
N/A |
N/A |
N/A |
| G10 T06 |
Query Docker/container socket path
|
N/A |
N/A |
N/A |
| G10 T07 |
Query local development server
|
N/A |
N/A |
N/A |
| G10 T08 |
Query SSH agent socket
|
N/A |
N/A |
N/A |
| G10 T09 |
Query keychain/credential service
|
Allowed |
Allowed |
Allowed |
| G10 T10 |
Query print/spooler service
|
Denied |
Denied |
Denied |
| G10 T11 |
Query local model server
|
N/A |
N/A |
N/A |
| G10 T12 |
Access Linux container runtime Unix sockets
|
N/A |
N/A |
N/A |
| G11 |
Inter-process communication
|
| G11 T01 |
Create local socket/pipe
|
Allowed |
Allowed |
Allowed |
| G11 T02 |
Connect to existing local socket/pipe
|
Allowed |
Allowed |
Allowed |
| G11 T03 |
Use shared memory mechanism
|
Denied |
Allowed |
Allowed |
| G11 T04 |
Use message queue mechanism
|
Denied |
Allowed |
Allowed |
| G11 T05 |
Use clipboard
|
Error |
N/A |
N/A |
| G11 T06 |
Query desktop automation channel
|
Denied |
Allowed |
Allowed |
| G11 T08 |
Access browser debugging socket
|
N/A |
N/A |
N/A |
| G12 |
User interface and desktop automation
|
| G12 T01 |
Take screenshot
|
Denied |
N/A |
N/A |
| G12 T07 |
Open application window
|
Error |
N/A |
N/A |
| G12 T08 |
Read active window title
|
Denied |
N/A |
N/A |
| G12 T09 |
Query accessibility channel
|
Allowed |
Allowed |
Allowed |
| G13 |
Browser and web session access
|
| G13 T01 |
Launch browser with fresh profile
|
N/A |
N/A |
N/A |
| G13 T02 |
Launch browser with existing user profile
|
N/A |
N/A |
N/A |
| G13 T03 |
Read browser bookmarks
|
N/A |
N/A |
N/A |
| G13 T04 |
Read browser history
|
N/A |
N/A |
N/A |
| G13 T05 |
Read browser cookies
|
N/A |
N/A |
N/A |
| G13 T06 |
Read browser session store
|
N/A |
N/A |
N/A |
| G13 T07 |
Use browser automation protocol
|
N/A |
N/A |
N/A |
| G13 T08 |
Download file through browser
|
N/A |
N/A |
N/A |
| G13 T09 |
Upload file through browser
|
N/A |
N/A |
N/A |
| G13 T10 |
Submit form
|
N/A |
N/A |
N/A |
| G13 T11 |
Access password manager integration
|
N/A |
N/A |
N/A |
| G13 T12 |
Capture screenshot of allowed website
|
N/A |
N/A |
N/A |
| G13 T13 |
Capture screenshot with Playwright
|
Allowed |
Allowed |
N/A |
| G14 |
Package, dependency, and supply-chain access
|
| G14 T01 |
Query package registry
|
Allowed |
Allowed |
Allowed |
| G14 T02 |
Install package into environment
|
Allowed |
Allowed |
Allowed |
| G14 T03 |
Install package globally
|
Allowed |
Allowed |
Allowed |
| G14 T04 |
Install package locally
|
Allowed |
Allowed |
Allowed |
| G14 T06 |
Modify dependency lockfile
|
N/A |
N/A |
N/A |
| G14 T07 |
Read package manager credentials
|
N/A |
N/A |
N/A |
| G15 |
Source control access
|
| G15 T01 |
Detect allowed repository metadata
|
N/A |
N/A |
N/A |
| G15 T02 |
Detect denied repository metadata
|
N/A |
N/A |
N/A |
| G15 T03 |
Clone allowed repository
|
N/A |
N/A |
N/A |
| G15 T04 |
Clone denied repository
|
N/A |
N/A |
N/A |
| G15 T05 |
Read allowed repository commit history
|
N/A |
N/A |
N/A |
| G15 T06 |
Read denied repository commit history
|
N/A |
N/A |
N/A |
| G15 T07 |
Read remote URL
|
N/A |
N/A |
N/A |
| G15 T08 |
Read allowed repository ignored file
|
N/A |
N/A |
N/A |
| G15 T09 |
Read denied repository ignored file
|
N/A |
N/A |
N/A |
| G15 T10 |
Create branch in allowed repository
|
N/A |
N/A |
N/A |
| G15 T11 |
Create branch in denied repository
|
N/A |
N/A |
N/A |
| G15 T12 |
Modify tracked file in allowed repository
|
N/A |
N/A |
N/A |
| G15 T13 |
Modify tracked file in denied repository
|
N/A |
N/A |
N/A |
| G15 T14 |
Stage changes in allowed repository
|
N/A |
N/A |
N/A |
| G15 T15 |
Stage changes in denied repository
|
N/A |
N/A |
N/A |
| G15 T16 |
Create commit in allowed repository
|
N/A |
N/A |
N/A |
| G15 T17 |
Create commit in denied repository
|
N/A |
N/A |
N/A |
| G15 T18 |
Push allowed repository branch to remote
|
N/A |
N/A |
N/A |
| G15 T19 |
Push denied repository branch to remote
|
N/A |
N/A |
N/A |
| G15 T20 |
Pull allowed repository from remote
|
N/A |
N/A |
N/A |
| G15 T21 |
Pull denied repository from remote
|
N/A |
N/A |
N/A |
| G15 T22 |
Read allowed repository signing configuration
|
N/A |
N/A |
N/A |
| G15 T23 |
Read denied repository signing configuration
|
N/A |
N/A |
N/A |
| G16 |
Database and structured data access
|
| G16 T01 |
SQLite: Open database in allowed directory
|
Allowed |
N/A |
N/A |
| G16 T02 |
SQLite: Open database in denied directory
|
Allowed |
N/A |
N/A |
| G16 T05 |
MariaDB: List database schemas
|
N/A |
N/A |
N/A |
| G16 T06 |
MariaDB: Read table rows from allowed schema
|
N/A |
N/A |
N/A |
| G16 T07 |
MariaDB: Read table rows from denied schema
|
N/A |
N/A |
N/A |
| G16 T08 |
MariaDB: Insert table row into allowed schema
|
N/A |
N/A |
N/A |
| G16 T09 |
MariaDB: Insert table row into denied schema
|
N/A |
N/A |
N/A |
| G16 T10 |
MariaDB: Insert and update table row in allowed schema
|
N/A |
N/A |
N/A |
| G16 T11 |
MariaDB: Insert and update table row in denied schema
|
N/A |
N/A |
N/A |
| G16 T12 |
MariaDB: Insert and delete table row from allowed schema
|
N/A |
N/A |
N/A |
| G16 T13 |
MariaDB: Insert and delete table row from denied schema
|
N/A |
N/A |
N/A |
| G16 T14 |
MariaDB: Read view rows from allowed schema
|
N/A |
N/A |
N/A |
| G16 T15 |
MariaDB: Read view rows from denied schema
|
N/A |
N/A |
N/A |
| G16 T16 |
MariaDB: Call stored procedure in allowed schema
|
N/A |
N/A |
N/A |
| G16 T17 |
MariaDB: Call stored procedure in denied schema
|
N/A |
N/A |
N/A |
| G17 |
Cloud and external account access
|
| G17 T01 |
Detect Azure CLI availability
|
N/A |
Denied |
N/A |
| G17 T02 |
Detect AWS CLI availability
|
N/A |
Denied |
N/A |
| G17 T03 |
Detect Google Cloud CLI availability
|
N/A |
Denied |
N/A |
| G17 T04 |
Detect configured Azure profile
|
N/A |
N/A |
N/A |
| G17 T05 |
Detect configured AWS profile
|
N/A |
N/A |
N/A |
| G17 T06 |
Detect configured Google Cloud profile
|
N/A |
N/A |
N/A |
| G17 T07 |
List Azure account identity
|
N/A |
N/A |
N/A |
| G17 T08 |
List AWS account identity
|
N/A |
N/A |
N/A |
| G17 T09 |
List Google Cloud account identity
|
N/A |
N/A |
N/A |
| G18 |
Identity, authentication, and credential stores
|
| G18 T01 |
Read local credential store entry
|
N/A |
N/A |
N/A |
| G18 T02 |
Request credential store lookup
|
N/A |
N/A |
N/A |
| G18 T03 |
Use SSH agent to sign challenge
|
N/A |
N/A |
N/A |
| G18 T04 |
Access GPG/PGP agent
|
Allowed |
Allowed |
Allowed |
| G18 T05 |
Access OS keychain/wallet
|
N/A |
N/A |
N/A |
| G18 T09 |
Detect logged-in user sessions
|
Allowed |
Allowed |
Allowed |
| G19 |
System configuration and administration
|
| G19 T01 |
Read system configuration summary
|
Allowed |
Allowed |
Allowed |
| G19 T02 |
Read installed software list
|
Allowed |
Allowed |
Allowed |
| G19 T03 |
Read network configuration
|
Allowed |
Allowed |
Allowed |
| G19 T04 |
Read host firewall status
|
Denied |
Denied |
Denied |
| G19 T05 |
Change runtime environment configuration
|
Allowed |
Allowed |
Allowed |
| G19 T06 |
Change user-level settings
|
Allowed |
Allowed |
Allowed |
| G19 T07 |
Change system-level settings
|
Denied |
Denied |
Denied |
| G19 T08 |
Install system service
|
Denied |
Denied |
Denied |
| G19 T09 |
Modify startup item
|
Allowed |
Denied |
Denied |
| G19 T10 |
Change firewall rule
|
Denied |
Denied |
Denied |
| G19 T11 |
Create scheduled task
|
Allowed |
Allowed |
Allowed |
| G20 |
Hardware and device access
|
| G20 T01 |
Read camera availability
|
Allowed |
Allowed |
Allowed |
| G20 T02 |
Capture camera frame
|
N/A |
N/A |
N/A |
| G20 T03 |
Read microphone availability
|
Allowed |
Allowed |
Allowed |
| G20 T04 |
Capture audio sample
|
N/A |
N/A |
N/A |
| G20 T05 |
Access printer list
|
Allowed |
N/A |
N/A |
| G20 T07 |
Access USB device list
|
Allowed |
Allowed |
Allowed |
| G20 T08 |
Access serial port
|
Allowed |
Allowed |
Allowed |
| G20 T09 |
Access Bluetooth device list
|
Allowed |
Allowed |
Allowed |
| G20 T10 |
Access GPU details
|
Allowed |
Allowed |
Allowed |
| G21 |
Time, scheduling, and persistence mechanisms
|
| G21 T01 |
Read system time
|
Allowed |
Allowed |
Allowed |
| G21 T05 |
Create background daemon/service
|
Allowed |
Allowed |
Allowed |
| G21 T07 |
Set file watcher
|
Allowed |
N/A |
N/A |
| G21 T08 |
Cron/user crontab on Linux
|
Allowed |
Allowed |
Allowed |
| G21 T09 |
systemd user unit
|
Allowed |
Allowed |
Allowed |
| G21 T10 |
Windows Run key/user startup folder
|
N/A |
N/A |
N/A |
| G22 |
Logging, telemetry, and audit visibility
|
| G22 T01 |
Write application log entry
|
Allowed |
Allowed |
Allowed |
| G22 T03 |
Read system logs
|
Allowed |
Allowed |
Allowed |
| G22 T04 |
Read security logs
|
Allowed |
Allowed |
Allowed |
| G30 |
Local AI agents
|
| G30 T01 |
Local tool call, remote LLM call
|
Allowed |
N/A |
N/A |