Screenshare 规范 Terms(中英双语通用版)
通用 Screenshare(SS)检查规范、违规认定、证据与隐私要求、处罚阶梯及英文 Terms 原文
本文是从既有 Screenshare 条例中剔除特定社区身份、专属玩法与专属处分机制后形成的通用规范。任何组织在采用本 Terms 前,仍应依据适用法律、其已公开的规则以及与受查人的有效约定,确认检查权限、告知方式和处罚权限。
版本: 1.1
生效日期: 2026 年 8 月 31 日
适用范围: 由组织授权、以核验作弊、规避检查、证据篡改或相关违规为目的的 Screenshare(SS)检查。
下列中文版与文末英文 Terms 使用相同编号并表达相同规则。英文术语保留在中文定义中,便于跨语言执行和记录。
一、通用 Screenshare 规范 Terms(中文版)
1. 定义(Definitions)
- Screenshare(SS):在明确授权和已告知范围内,通过屏幕共享、远程连接或经批准的扫描工具,对设备状态、相关文件、系统记录及运行环境进行检查的过程。
- ScreenSharer(SSer):获组织授权、依本 Terms 执行 SS 的检查人员。
- 受查人(Subject):被要求参加或自愿参加 SS 的用户。原规则中的 “Player” 或 “Suspect” 在本 Terms 中统一称为 Subject;该称谓本身不表示其已经违规。
- SS Session:从正式告知检查开始,到 SSer 出具结论或明确终止检查为止的完整会话。
- SS Tool:经采用本 Terms 的组织事先批准,用于自动化查端、扫描或取证辅助的软件,包括但不限于 Echo、Ocean。SS Tool 仅在其名称、提供方、来源、访问范围、数据处理方式、输出内容及适用的服务条款(Terms of Service,简称 Tool TOS)已向受查人披露后,方属于本 Terms 所称的已批准工具(Approved SS Tool)。
- Bypass Attempt:为了妨碍、误导或规避 SS,故意删除、清除、修改、伪造、替换、转移或隐藏与检查事项有关的证据或环境。
- Anti-Forensics:旨在降低证据可见性、完整性、可追溯性或可信度的反取证方法、工具或操作。
- Force Majeure:任何人无法合理控制、无法合理预见或无法合理避免,并直接导致其不能完成 SS 要求的事件。
- Permanent / Perm:无限期停权;除非采用本 Terms 的组织另有书面规定,否则不当然等同于不可复核。
2. 基本原则(Core Principles)
- 授权与告知(Authority and Notice):SSer 必须具有执行检查的明确权限。开始前应向受查人说明检查理由、范围、所用工具、是否录制、预计时长、数据保存方式及可用的复核渠道。
- 目的限定(Purpose Limitation):仅可检查与已告知事项具有合理关联的内容。不得借 SS 搜索无关的私人信息、账号凭据、通信内容或商业秘密。
- 最小必要(Data Minimization):应优先使用侵入性最低、足以核验相关事实的方法。能够通过状态确认或特定扫描完成的,不应扩大为无边界的文件浏览。
- 不得擅自改变设备(No Unauthorized Alteration):除非受查人明确同意且确有检查必要,SSer 不得安装、删除、上传、下载、修改或执行与检查无关的内容。
- 无罪推定与证据标准(Presumption of Innocence and Evidence Standard):安装过某类软件、加入某个群组或出现单一异常,不得自动视为作弊或 Bypass Attempt。拒绝 Approved SS Tool 或其 Tool TOS 应依第 7.3 条作为程序性 Refusing 处理,但拒绝行为本身不得被直接认定为 Cheating 或 Bypass Attempt。任何实体违规结论仍必须由可复核事实支持。
- 一致与比例(Consistency and Proportionality):相同事实应适用相同标准;处分应考虑故意程度、证据影响、重复次数、配合情况及 Force Majeure。
- 保密(Confidentiality):SSer 及复核人员对检查中接触的非公开信息承担保密义务,不得将其用于检查以外的目的。
- 工具授权与 Tool TOS(Authorization of Tools and Tool TOS):受查人接受本 Terms 并选择继续 SS,即授权 SSer 在已披露范围内使用任何 Approved SS Tool。受查人在工具运行前还必须接受该工具当时适用的 Tool TOS。受查人可以拒绝本 Terms 并拒绝整个 SS,但不得在要求 SS 继续进行的同时,选择性拒绝某个 Approved SS Tool 或其 Tool TOS。
3. SS 前的要求(Pre-Session Requirements)
- SSer 应确认受查人身份、检查事项和适用版本,告知拟使用的 Approved SS Tool,向受查人提供当前 Tool TOS 的查看方式,并记录受查人对本 Terms、SS 及 Tool TOS 的接受或拒绝情况和 SS Session 的开始时间。
- 受查人应在收到检查通知后保持相关设备和环境的当前状态,不得为影响检查而重启服务、清理记录、删除文件、切换设备或运行清理工具。
- 如设备性能、网络、管理员权限、远程连接工具或辅助功能存在真实障碍,受查人应立即说明并提供可合理验证的信息。
- 如设备中存在与检查无关的敏感、私密或受保密义务保护的内容,受查人应在相关目录被查看前提出。SSer 应在不损害检查目的的前提下采用遮挡、限定路径、由受查人操作或其他替代方式。
- 受查人应披露可能影响判断的多鼠标、多存储设备、虚拟挂载、定制系统、优化工具或其他特殊环境;披露本身不构成违规。
4. SS 期间的行为(Session Conduct)
- 受查人应在事先说明的合理响应时间内答复,不得无故离开、故意拖延、反复中断连接或通过重新启动、退出相关程序等方式妨碍检查。
- 在 SSer 明确要求保持运行后,受查人不得关闭相关应用、游戏进程或远程连接程序。真实崩溃、断网或系统故障应依据可验证事实处理,不得仅因结果相同而推定为故意。
- 受查人不得夺取控制、遮挡相关窗口、提供虚假说明或引导 SSer 检查错误的设备、账号、目录或时间范围。
- SSer 不得超出已告知范围操作设备;发现无关私人内容时,应立即停止查看并避免复制或传播。
- SSer 有权在 SS 中使用 Approved SS Tool,包括但不限于 Echo、Ocean。工具首次运行前,SSer 必须披露其名称、提供方、来源、访问范围、向第三方传输或保存的数据、输出内容,并向受查人提供当前 Tool TOS 的查看和接受方式。SSer 不得使用未经批准的工具,也不得使工具超出已披露范围运行。
- 受查人接受本 Terms 并继续 SS 后,无权选择性拒绝任何 Approved SS Tool;受查人同时必须在该工具运行前接受其 Tool TOS。受查人拒绝本 Terms、拒绝整个 SS,或拒绝完成 SS 所必需的 Approved SS Tool 之 Tool TOS 时,SSer 应停止检查,并依第 7.3 条将其记录为对整个 SS 的 Refusing。该拒绝可触发已经公开的 Refusing 后果,但不得仅凭拒绝行为认定 Cheating 或 Bypass Attempt。
- Admitting 仅指受查人在理解问题和后果后作出的明确、自愿且被准确记录的承认。含糊陈述、推测或在压力下作出的表述不得单独作为结论依据。
5. 轻度违规(Light Offenses)
5.1 无法进行 SS(Inability to SS)
- Type I — 非故意技术障碍:低性能设备、网络不稳定、缺少管理员权限或远程连接工具故障,且没有证据表明这些问题由受查人故意制造、设置或伪造。
- Type I — 故意制造或伪造:受查人故意造成、夸大或伪造前述技术障碍,以阻止或缩短 SS。
- Type II — 环境性障碍:定制或精简操作系统、无法恢复的关键组件缺失,或其他使完整 SS 在技术上无法进行的环境。SSer 在作出结论前必须先尝试合理的替代检查方法。
- Type III — Approved SS Tool 替代扫描:受查人能够运行组织批准的 SS Tool、已经接受其 Tool TOS,且扫描范围足以解决检查事项时,可将该扫描作为完成或部分完成 SS 的方式。工具未覆盖的事项不得被描述为已经核验。
5.2 多个鼠标或缺少鼠标软件(1+ Mice Connected / No Mouse Software)
存在两个或以上已连接的指针设备、预装鼠标软件缺失、设备损坏或配置异常时,应记录设备标识和解释。只有在未披露、解释明显虚假,或该状态被用于隐藏宏、脚本、输入修改或设备替换时,方可按本项认定违规;设备数量本身不是作弊结论。
5.3 拖延(Stalling)
在收到明确指令和合理响应时间后,无正当理由离开、持续不回复、反复中断、故意制造无关步骤,或以其他方式延迟检查,构成 Stalling。短暂断网、无障碍需求、紧急事件或其他 Force Majeure 不构成 Stalling。
5.4 SS 滥用(SS Misuse)
伪造、冒用、篡改或重复使用 SS 报告,使用已经失效的报告规避新的检查要求,向无权人员披露 SS 资料,或将 SS 结论用于其授权范围以外的目的,构成 SS Misuse。
6. 不可抗力(Force Majeure)
- 经合理验证的 Force Majeure 不应产生主处罚,也不应与其他违规叠加。
- SSer 应记录事件、受影响的要求、已尝试的替代方法以及是否需要重新安排 SS。
- 如果只有部分检查受影响,应完成不受影响且仍属必要的部分,不得据此扩大检查范围。
- 故意伪造或恶意利用 Force Majeure 的,按 Bypass Attempt 评估;仅因无法立即证明事件,不得自动认定为恶意。
7. 中度违规(Medium Offenses)
7.1 禁用服务或记录源(Disabled Services)
- 与检查相关的系统服务或记录源被禁用、终止、截断或无法访问,并且该状态实质性降低证据可见性时,可认定为 Disabled Services。常见对象包括
SysMain、CDPUserSvc_{...}、PcaSvc、DPS、EventLog、Task Scheduler、SearchIndexer、BAM/DAM、DusmSvc和Appinfo。 - 同类状态包括终止 BAM inheritance、禁用 ActivitiesCache、禁用 Jump Lists,以及终止相关服务线程。
- 仅有服务关闭这一事实不足以证明故意。SSer 应检查关闭时间、方式、操作者、优化工具的作用、系统版本及是否能够恢复。
- 受查人使用优化软件或定制配置时,应自行了解其影响;但 SSer 仍必须证明该状态与本次检查的关联,不得以“使用优化工具”替代证据。
7.2 关闭相关程序(Closing Relevant Applications)
在明确收到保持运行的指令后,故意关闭相关程序、进程或远程连接,构成本项违规。真实崩溃或非人为掉线应单独核验。单纯退出账号而未影响相关证据的,不自动构成违规。
7.3 拒绝或承认(Refusing / Admitting)
- Refusing:在检查具有明确权限、范围合理且已完成必要告知后,受查人拒绝本 Terms、拒绝整个 SS,或拒绝使用完成 SS 所必需的 Approved SS Tool,包括拒绝接受该工具适用的 Tool TOS。其后果应由采用本 Terms 的组织预先公开。
- Admitting:受查人明确承认相关违规。承认应保留准确上下文,并尽可能由独立证据印证。
- 受查人可以拒绝本 Terms 并拒绝整个 SS,但接受本 Terms 并选择继续 SS 后,不得选择性拒绝任何 Approved SS Tool 或其 Tool TOS。此类选择性拒绝应视为对整个 SS 的 Refusing,而不是继续人工检查的当然依据。
- 如果工具未经组织批准、SSer 未提供当前 Tool TOS、未完成必要披露,或拟运行范围超出已披露范围,受查人对此提出异议不构成 Refusing;SSer 应先纠正相关缺陷。任何 Refusing 均不当然撤销无罪推定,也不单独证明 Cheating 或 Bypass Attempt。
7.4 干扰(Tampering)
故意使相关内容更难查找、隐藏或移动窗口、改变搜索结果、误导路径、撤回必要权限,或在 SS 期间改变相关状态,构成 Tampering。SSer 对受查人提出的保密内容应采用本 Terms 第 3.4 条的限定措施;仅以“文件可能私密”为由,不得无边界查看图片、文档、文本或脚本。
7.5 作弊(Cheating)
发现作弊客户端、作弊应用、宏、脚本或其他不公平功能,且证据能够证明其存在、可用性以及与受查事项的关联时,可认定 Cheating。认定时应区分:
- 工具是否具有自毁或告警式自毁功能;
- 是否使用了 Bypass 或 Anti-Forensics;
- 是否仅隐藏了工具,还是改变了其形式、时间或证据;
- 是否同时满足 Bypass Attempt 的任一类型。
若存在 Bypass Attempt,应分别记录,不得用笼统的 “Cheating” 掩盖更严重的证据篡改行为。
8. 严重违规(Severe Offenses)
8.1 规避检查(Bypass Attempt)
Bypass Attempt 仅应在有明确、可复核证据证明相关行为旨在妨碍或误导 SS 时成立。软件的存在、合法日常使用或孤立的系统异常,不足以单独成立本项。
- Type I — 清理或重置证据源:重启相关服务以改变状态;清理 Journal、注册表项、Event Logs、Prefetch 或
shell:recent;使用字符串清理器、文件粉碎器;篡改 NvAPPTimestamps;或就相关状态故意向 SSer 提供虚假信息。 - Type II — 替换、覆盖或重新连接环境:为改变证据而使用 PsExec 或脚本环境;在 FAT16/FAT32/exFAT 介质上覆盖或替换文件;重新连接大容量存储设备;改变 Virtual Mounts。开发工具、脚本环境或外置介质的正常存在不构成违规,必须证明其与证据改变有关。
- Type III — 临近或计划执行反取证操作:在 SS 前后计划或运行 PowerShell、PowerShell ISE、CMD、批处理、清理器、优化器、Process Hacker、System Informer、ProcMon、WMIC 方法、注册表修改或其他脚本操作,并有证据表明其用于隐藏、清理或改变相关信息;还包括通过 Unicode 混淆作弊工具或故意修改默认下载路径以误导检查。
- Type IV — 身份、设备或数据替换:切换设备或由他人、其他账号代替接受 SS;使用公开 Anti-Forensics;修改文件数据或元数据;组合实施多项不同类型的规避行为。
- 通过谎报自身环境、故意选择较轻的违规描述或其他方式逃避正确分类的,应按其实际行为重新分类;不得仅因当事人提出不同解释而认定其撒谎。
8.2 非法或被禁止的修改(Illegal Modifications)
用于取得不公平优势或规避检查的代理客户端、鼠标宏、外部宏、输入自动化、HitDelay 修改、Freelook 或同类功能,属于 Illegal Modifications。仅用于图形、性能或可访问性优化且不包含被禁止功能的启动器或工具,不因其类别自动违规。
8.3 网络、VPN 与 Ping 操纵(Ping Manipulation)
故意使用热点、代理、VPN 或其他方法伪造、操纵或隐藏网络状态,并以获取不公平优势、规避 SS 或逃避既有处分为目的时,可认定违规。VPN、企业网络、Cloudflare WARP 或网络波动本身不构成违规。
8.4 输入修改(Input Modification)
修改鼠标灵敏度、加速度或辅助输入的内部或外部工具,在不包含 CPS 自动化、HitDelay 修改、宏或其他被禁止功能时,不构成违规。
8.5 定制或精简系统(Modified OS)
- Customized OS 或 Trimmed OS 关闭大量必要服务、导致关键记录不可用且无法合理恢复时,可认定 Modified OS。SSer 在作出结论前必须尝试合理、低风险的替代检查。
- 若受影响的关键服务或记录源超过三项,可同时评估 Inability to SS,但不得重复计算同一事实造成的损害。
- Boot Camp 或其他合法的跨平台运行方式本身不构成违规。
- 系统优化器导致的精简效果应按实际状态、时间和证据影响判断,不因品牌或合作关系自动免责或定罪。
8.6 删除相关文件(Deleting Relevant Files)
在收到检查通知后,或能够合理预见即将接受检查时,故意删除、粉碎、覆盖或使相关文件无法恢复,并因此实质性影响 SS 的,构成本项违规。正常的自动清理、存储故障或与检查无关的删除,必须结合时间线和其他证据判断。
9. 组织性规避、利益输送与规避服务(Organized Bypass and Bribery)
- Organized Bypass:组织或协助他人以替换设备、替换身份、提供无违规设备、隐藏信息或统一虚假说法等方式规避 SS。
- Bribing ScreenSharers:向 SSer、复核人员或管理人员提供、承诺或索取利益,以影响检查、证据或结论。涉事 SSer 应立即回避并接受独立调查。
- Providing Bypass Services:制作、销售、分发、教授或定向提供用于规避 SS 的 Anti-Forensics、伪装程序、作弊工具或操作方案。
- Receiving Bypass Services:明知服务旨在规避 SS 而购买、获取或使用该服务。
- 单纯加入群组、浏览公开内容、与相关人员存在联系或表现兴趣,不得自动撤销无罪推定。必须证明当事人具有实际参与、提供、获取或使用行为。
10. 证据、结论与记录(Evidence, Findings and Records)
- 每项结论应记录适用条款、关键事实、时间线、证据来源、证据完整性、替代解释以及 SSer 的判断理由。
- 对可能自然产生或由正常软件产生的系统状态,应验证时间、因果关系和用户控制能力,不得把相关性直接当作故意。
- 屏幕截图、扫描结果或工具告警应保留必要上下文;无法验证来源、时间或对象的材料不得作为唯一依据。
- 同一事实符合多个条款时,应说明分别保护的利益和额外损害;不得仅为加重处分而重复计罚。
- Permanent、Server Ban 或其他重大处分应由未直接执行该次 SS 的第二名授权人员复核。
11. 处罚与叠加(Penalties and Stacking)
- 采用本 Terms 的组织可使用下方处罚表,也可在采用前公开替代方案。不得在事件发生后为个案临时提高处罚。
- “第 1 次至第 5 次”是指同一受查人在组织公开的有效追溯期内,被最终确认的同类违规次数。尚在复核中的决定不得计入下一次。
+7d stacking表示此后每次在上一档基础上增加 7 天;Perm/Permanent表示无限期停权;Server Ban表示平台级封禁;Event Penalty表示采用方公开规则中的额外活动限制。- 空白单元格表示所附表格未规定该档次,不得推定为自动升级。
- Force Majeure、证据不足或程序性错误不得通过“叠加”补足。由同一连续行为产生且损害相同的多个标签原则上不重复计罚。
12. 复核与申诉(Review and Appeal)
- 除保护他人隐私或真正敏感的检测方法所必需的有限内容外,受查人应收到书面结论摘要,其中包括适用条款、处分、开始时间和复核期限。
- 复核申请可以对身份、事实、证据完整性、违规分类、检查程序、Force Majeure、重复计罚或处分计算提出异议。
- 在合理可行的情况下,复核人员应独立于原决定,并记录复核结果及理由。
- 被撤销或更正的结论必须从叠加次数中移除,受影响的记录应及时更正。
13. 隐私、安全与保存(Privacy, Security and Retention)
- 仅可收集记录 SS 和支持结论所必需的数据。密码、认证令牌、无关私信及无关个人文件不得被保存。
- SS 资料仅可由具有明确工作需要的授权 SSer、复核人员和安全人员访问。
- 录像、导出文件、截图和报告应加密或采取其他合理保护措施,记录访问日志,并仅保存至公开期限届满。
- 保存期限届满后,应安全删除相关资料;法律要求或正在进行的复核确需保留的除外。
- 未授权访问或披露应按照采用方的安全事件响应流程处理,并在法律要求时通知受影响人员。
14. 采用与修订(Adoption and Amendments)
- 采用本 Terms 的组织应公开其身份、授权 SS 职位、批准工具、响应时间、资料保存期限、复核联系方式、违规追溯期以及处罚表的任何本地调整。
- 实质性修订自其公开生效日期起向后适用;如新规则对受查人更有利,且采用方明确决定适用于未结事项的除外。
- 任一条款无效或不可执行时,其余条款在法律允许的范围内继续有效。
二、处罚阶梯(Penalty Schedule)
下表按所附处罚表转录,并将违规名称与本文通用术语对齐。时间数值保持原表不变;表中 d 代表天,week 代表周。
| 违规项(Offense) | 第 1 次 | 第 2 次 | 第 3 次 | 第 4 次 | 第 5 次及以后 |
|---|---|---|---|---|---|
| 无法进行 SS(Inability to SS) | 2–4d | 2–5d | +week | +2 weeks | Perm |
| 连接多个鼠标或无鼠标软件(1+ Mice Connected or No Mouse Software) | 7d | 14d | 21d | 31d | +7d stacking |
| 拖延 / 干扰(Stalling / Tampering) | 14d | 21d | 31d | 91d | Perm |
| 关闭相关程序、承认或拒绝(Closed Relevant App / Admitting / Refusing) | 14d | 31d | 51d | 91d | Perm |
| SS 滥用(SS Misuse) | SS Denial | 1d | 7d | 14d | 21d |
| 非法修改、禁用服务、Modified OS、Cheating 或不公平优势 | 21d | 31d | 61d | 91d | Perm |
| 规避检查(Bypass Attempt) | Type I: 61d Type II: 91d Type III & IV: Perm | Type I: 91d Type II: 91d + Event Penalty Type III & IV: Perm | Type I: 91d + Event Penalty Type II: Perm Type III & IV: Perm | Permanent | — |
| 参与 Bypass 或贿赂 SSer(Involved in Bypass Acts / Bribing SSers) | Perm | Server Ban | — | — | — |
| 删除本 Terms 所指的相关文件(Deleting Files) | 31d | 61d | 91d | Permanent | Permanent + Event Penalty |
三、General Screenshare Terms(English Original)
Version: 1.1
Effective date: August 31, 2026
Scope: Screenshare inspections authorized by an adopting organization for the purpose of verifying cheating, inspection evasion, evidence tampering, or related violations.
1. Definitions
- Screenshare (SS) means a process, conducted within an expressly authorized and disclosed scope, in which screen sharing, remote access, or an approved scanner is used to inspect device state, relevant files, system records, and the operating environment.
- ScreenSharer (SSer) means a person authorized by the adopting organization to conduct an SS under these Terms.
- Subject means the person asked or volunteering to undergo an SS. The label does not imply that the person has committed a violation.
- SS Session means the complete session beginning when formal notice of the inspection is given and ending when the SSer issues a finding or expressly terminates the inspection.
- SS Tool means software, including but not limited to Echo and Ocean, approved in advance by the adopting organization for automated screenshare inspection, scanning, or forensic assistance. An SS Tool is an Approved SS Tool under these Terms only after its name, provider, source, access scope, data-processing practices, output, and applicable terms of service (Tool TOS) have been disclosed to the Subject.
- Bypass Attempt means an intentional act to obstruct, mislead, or evade an SS by deleting, clearing, modifying, falsifying, replacing, transferring, or concealing evidence or an environment relevant to the inspection.
- Anti-Forensics means a method, tool, or act intended to reduce the visibility, integrity, traceability, or reliability of evidence.
- Force Majeure means an event outside a person’s reasonable control that could not reasonably have been foreseen or avoided and that directly prevents compliance with an SS requirement.
- Permanent / Perm means an indefinite suspension. Unless the adopting organization expressly states otherwise in writing, it does not automatically mean that review is unavailable.
2. Core Principles
- Authority and Notice. An SSer must have clear authority to conduct the inspection. Before the SS begins, the Subject must be informed of the reason, scope, tools, recording status, expected duration, data-retention method, and available review process.
- Purpose Limitation. Inspection is limited to material reasonably connected to the disclosed matter. An SS must not be used to search unrelated private information, account credentials, communications, or trade secrets.
- Data Minimization. The least intrusive method sufficient to verify the relevant facts must be preferred. A bounded status check or targeted scan must not be expanded into unrestricted file browsing without a documented need.
- No Unauthorized Alteration. Unless the Subject expressly consents and the act is necessary for the inspection, an SSer must not install, delete, upload, download, modify, or execute unrelated material on the device.
- Presumption of Innocence and Evidence Standard. Having a category of software installed, joining a group, or presenting a single anomaly does not automatically establish Cheating or a Bypass Attempt. Refusal of an Approved SS Tool or its Tool TOS is handled as procedural Refusing under Section 7.3, but refusal itself must not be treated as direct proof of Cheating or a Bypass Attempt. Any substantive finding must remain supported by reviewable facts.
- Consistency and Proportionality. Comparable facts must be evaluated under comparable standards. A sanction must account for intent, impact on evidence, repetition, cooperation, and Force Majeure.
- Confidentiality. SSers and reviewers must keep non-public information encountered during an SS confidential and must not use it outside the inspection purpose.
- Authorization of Tools and Tool TOS. By accepting these Terms and electing to continue the SS, the Subject authorizes the SSer to use any Approved SS Tool within its disclosed scope. Before the tool runs, the Subject must also accept the Tool TOS then applicable to that tool. The Subject may reject these Terms and decline the entire SS, but may not demand that the SS continue while selectively refusing an Approved SS Tool or its Tool TOS.
3. Pre-Session Requirements
- The SSer must confirm the Subject’s identity, the matter under inspection, and the applicable version of these Terms; identify each proposed Approved SS Tool; provide a means to review the current Tool TOS; and record the Subject’s acceptance or rejection of these Terms, the SS, and the Tool TOS, together with the start time of the SS Session.
- After receiving notice, the Subject must preserve the current state of relevant devices and environments. The Subject must not restart services, clear records, delete files, switch devices, or run cleaners for the purpose of affecting the inspection.
- A genuine limitation involving device performance, network access, administrator permissions, or remote-access software must be disclosed promptly and supported with reasonably verifiable information.
- If a device contains unrelated sensitive, private, or legally protected material, the Subject must raise the concern before the relevant location is viewed. Where consistent with the inspection purpose, the SSer must use masking, path limitation, Subject-controlled navigation, or another alternative.
- The Subject must disclose multiple mice, storage devices, virtual mounts, customized operating systems, optimizers, or other unusual conditions that may affect interpretation. Disclosure alone is not a violation.
4. Session Conduct
- The Subject must respond within the reasonable interval stated in advance and must not leave without justification, deliberately delay, repeatedly interrupt the connection, or obstruct the inspection by restarting or exiting relevant applications.
- After an instruction to preserve an application, game process, or remote connection, the Subject must not close it. A genuine crash, outage, or system failure must be assessed on verifiable facts and must not be presumed intentional merely because it has the same result.
- The Subject must not seize control, conceal a relevant window, provide a false explanation, or direct the SSer to the wrong device, account, location, or time period.
- The SSer must remain within the disclosed scope. If unrelated private material appears, the SSer must stop viewing it and avoid copying or disclosing it.
- An SSer may use Approved SS Tools during an SS, including but not limited to Echo and Ocean. Before first use, the SSer must disclose the tool’s name, provider, source, access scope, data transmitted to or retained by a third party, and output, and must provide a means for the Subject to review and accept the current Tool TOS. The SSer must not use an unapproved tool or operate a tool outside its disclosed scope.
- After accepting these Terms and continuing the SS, the Subject has no right to selectively refuse an Approved SS Tool and must accept its Tool TOS before it runs. If the Subject rejects these Terms, declines the entire SS, or refuses the Tool TOS of an Approved SS Tool required to complete the SS, the SSer must stop the inspection and record the conduct as Refusing the entire SS under Section 7.3. Published consequences for Refusing may apply, but refusal alone must not establish Cheating or a Bypass Attempt.
- Admitting means a clear, voluntary, and accurately recorded admission made after the Subject understands the question and consequence. An ambiguous, speculative, or pressured statement must not be the sole basis of a finding.
5. Light Offenses
5.1 Inability to SS
- Type I — Unintentional technical limitation: low device performance, an unstable network, lack of administrator permissions, or a remote-access failure, where there is no evidence that the Subject intentionally created, configured, or falsified the limitation.
- Type I — Intentionally caused or falsified limitation: intentionally causing, exaggerating, or falsifying a technical limitation in order to prevent or shorten an SS.
- Type II — Environmental limitation: a Customized OS, Trimmed OS, irrecoverably missing component, or another environment that makes a complete SS technically impossible. The SSer must attempt reasonable alternative inspection methods before making a finding.
- Type III — Approved SS Tool scan: where the Subject can run an SS Tool approved by the adopting organization, has accepted its Tool TOS, and its scope is sufficient to resolve the matter, the scan may complete or partially complete the SS. A matter outside the tool’s coverage must not be described as verified.
5.2 1+ Mice Connected / No Mouse Software
Where two or more pointing devices are connected, expected mouse software is absent, a device is broken, or its configuration is unusual, the device identity and explanation must be recorded. A violation may be found only where the condition was not disclosed, the explanation is demonstrably false, or the condition was used to conceal a macro, script, input modification, or device substitution. The number of devices alone does not establish Cheating.
5.3 Stalling
Stalling means leaving without justification, persistently failing to reply, repeatedly disconnecting, deliberately creating irrelevant steps, or otherwise delaying the inspection after a clear instruction and reasonable response interval. A temporary outage, accessibility need, emergency, or other Force Majeure is not Stalling.
5.4 SS Misuse
SS Misuse means falsifying, impersonating, altering, or reusing an SS report; using an expired report to evade a new inspection requirement; disclosing SS material to an unauthorized person; or using an SS finding outside its authorized purpose.
6. Force Majeure
- A reasonably verified Force Majeure event must not result in a primary sanction and must not be stacked with another violation.
- The SSer must record the event, the affected requirement, the alternatives attempted, and whether the SS must be rescheduled.
- If only part of the inspection is affected, the necessary and unaffected portion may be completed, but the event must not be used to expand the inspection scope.
- Intentionally falsifying or abusing Force Majeure in bad faith may be evaluated as a Bypass Attempt. An inability to prove the event immediately does not by itself establish bad faith.
7. Medium Offenses
7.1 Disabled Services
- Disabled Services may be found where a system service or record source relevant to the inspection has been disabled, terminated, truncated, or made inaccessible, and that condition materially reduces evidence visibility. Common sources include
SysMain,CDPUserSvc_{...},PcaSvc,DPS,EventLog,Task Scheduler,SearchIndexer,BAM/DAM,DusmSvc, andAppinfo. - Equivalent conditions include terminating BAM inheritance, disabling ActivitiesCache, disabling Jump Lists, and terminating relevant service threads.
- A disabled service alone does not prove intent. The SSer must consider when and how it was disabled, who controlled the act, the effect of an optimizer, the operating-system version, and whether the condition can be restored.
- A Subject using an optimizer or custom configuration is responsible for understanding its effects, but the SSer must still establish a connection to the inspection. The use of an optimizer is not a substitute for evidence.
7.2 Closing Relevant Applications
Intentionally closing a relevant application, process, or remote connection after a clear preservation instruction is a violation. A genuine crash or non-user-caused outage must be evaluated separately. Logging out alone is not automatically a violation where relevant evidence is unaffected.
7.3 Refusing / Admitting
- Refusing means rejecting these Terms, declining the entire SS, or refusing an Approved SS Tool required to complete the SS, including refusal to accept that tool’s applicable Tool TOS, after the inspection’s authority and reasonable scope have been established and the required notice has been given. Any consequence must be published by the adopting organization in advance.
- Admitting means clearly acknowledging the relevant violation. The full context must be preserved, and independent corroboration should be obtained where possible.
- The Subject may reject these Terms and decline the entire SS. Once the Subject accepts these Terms and elects to continue the SS, however, the Subject may not selectively refuse an Approved SS Tool or its Tool TOS. Such selective refusal is treated as Refusing the entire SS, not as an automatic basis for continuing with a manual inspection.
- An objection is not Refusing where the tool has not been approved by the adopting organization, the current Tool TOS has not been made available, required disclosures have not been given, or the proposed operation exceeds the disclosed scope. The SSer must first cure the defect. Refusing does not itself revoke the presumption of innocence or prove Cheating or a Bypass Attempt.
7.4 Tampering
Tampering means deliberately making relevant material harder to locate, hiding or moving windows, altering search results, misdirecting a path, withdrawing necessary permissions, or changing relevant state during an SS. A confidentiality concern raised by the Subject must be handled through the limitations in Section 3.4. A claim that a file may be private does not permit unrestricted inspection of images, documents, text, or scripts.
7.5 Cheating
Cheating may be found where a cheat client, cheat application, macro, script, or other unfair functionality is discovered and the evidence establishes its existence, usability, and connection to the inspected matter. The finding must distinguish:
- whether the tool has self-destruction or alerting self-destruction functionality;
- whether Bypass or Anti-Forensics was used;
- whether the tool was merely concealed or its form, time, or evidence was altered; and
- whether any type of Bypass Attempt was also committed.
Where a Bypass Attempt exists, it must be recorded separately. A generic Cheating label must not conceal more serious evidence tampering.
8. Severe Offenses
8.1 Bypass Attempt
A Bypass Attempt may be found only on clear, reviewable evidence that the conduct was intended to obstruct or mislead an SS. The presence of software, ordinary legitimate use, or an isolated system anomaly is not sufficient by itself.
- Type I — Clearing or resetting evidence sources: restarting a relevant service to change its state; clearing Journal, Registry entries, Event Logs, Prefetch, or
shell:recent; using string cleaners or file shredders; tampering with NvAPPTimestamps; or intentionally giving the SSer false information about a relevant condition. - Type II — Replacing, overwriting, or reconnecting an environment: using PsExec or a scripting environment to alter evidence; overwriting or replacing files on FAT16/FAT32/exFAT media; reconnecting a mass-storage device; or changing Virtual Mounts. The ordinary presence of development tools, scripting environments, or external media is not a violation; a connection to evidence alteration must be established.
- Type III — Proximate or scheduled anti-forensic execution: scheduling or running PowerShell, PowerShell ISE, CMD, batch files, cleaners, optimizers, Process Hacker, System Informer, ProcMon, WMIC methods, Registry changes, or other scripts near an SS, where evidence establishes that the act was used to hide, clear, or alter relevant information. This Type also includes Unicode obfuscation of cheat tools or intentionally changing a default Downloads path to misdirect the inspection.
- Type IV — Identity, device, or data substitution: switching devices; having another person or account undergo the SS; using public Anti-Forensics; altering file data or metadata; or combining multiple distinct types of bypass conduct.
- A person who misrepresents the environment or deliberately selects a lesser offense description to evade the correct classification may be reclassified according to the actual conduct. Merely offering a different explanation does not establish a lie.
8.2 Illegal Modifications
Proxy clients, mouse macros, external macros, input automation, HitDelay modifications, Freelook, or similar features are Illegal Modifications where they provide an unfair advantage or evade inspection. A launcher or tool used only for graphics, performance, or accessibility optimization is not prohibited merely by category where it contains no banned functionality.
8.3 Ping Manipulation
The intentional use of a hotspot, proxy, VPN, or other method to falsify, manipulate, or conceal network conditions may be a violation where its purpose is to obtain an unfair advantage, evade an SS, or avoid an existing sanction. A VPN, enterprise network, Cloudflare WARP, or network fluctuation alone is not a violation.
8.4 Input Modification
An internal or external tool that changes mouse sensitivity, acceleration, or assistive input is allowed where it does not include CPS automation, HitDelay modification, macros, or other prohibited functionality.
8.5 Modified OS
- A Customized OS or Trimmed OS may be treated as a Modified OS where it disables many necessary services, makes key records unavailable, and cannot reasonably be restored. The SSer must attempt reasonable, low-risk alternatives before making a finding.
- Where more than three key services or record sources are affected, Inability to SS may also be evaluated, but the same evidentiary harm must not be counted twice.
- Boot Camp or another legitimate cross-platform environment is not a violation by itself.
- Trimming caused by a system optimizer must be evaluated according to the actual state, timing, and evidentiary impact. A brand or commercial relationship does not create automatic liability or immunity.
8.6 Deleting Relevant Files
Intentionally deleting, shredding, overwriting, or making a relevant file unrecoverable after notice of an inspection, or when an inspection is reasonably foreseeable, is a violation where it materially impairs the SS. Ordinary automated cleanup, storage failure, or deletion unrelated to the inspection must be evaluated with the timeline and other evidence.
9. Organized Bypass, Bribery, and Bypass Services
- Organized Bypass means organizing or assisting another person to evade an SS through device substitution, identity substitution, presentation of a clean device, concealment of information, or a coordinated false account.
- Bribing ScreenSharers means offering, promising, requesting, or accepting a benefit to influence an SSer, reviewer, evidence, or finding. An involved SSer must be recused immediately and independently investigated.
- Providing Bypass Services means creating, selling, distributing, teaching, or specifically supplying Anti-Forensics, camouflaged programs, cheat tools, or procedures intended to evade an SS.
- Receiving Bypass Services means knowingly purchasing, obtaining, or using a service intended to evade an SS.
- Membership in a group, viewing public material, association with a person, or expressed interest does not automatically revoke the presumption of innocence. Actual participation, provision, receipt, or use must be established.
10. Evidence, Findings, and Records
- Every finding must identify the applicable Term, material facts, timeline, evidence sources, evidence integrity, alternative explanations, and the SSer’s reasons.
- A system state that can occur naturally or through ordinary software must be evaluated for timing, causation, and user control. Correlation must not be treated as intent without supporting facts.
- A screenshot, scanner result, or tool alert must retain necessary context. Material whose source, time, or Subject cannot be verified must not be the sole basis of a finding.
- Where one act matches multiple Terms, the decision must identify the distinct interest and additional harm protected by each. Labels must not be duplicated solely to increase a sanction.
- A Permanent suspension, Server Ban, or other major sanction must be reviewed by a second authorized person who did not directly conduct the SS.
11. Penalties and Stacking
- An adopting organization may use the Penalty Schedule above or publish an alternative before adoption. A sanction must not be increased ad hoc after the event for an individual case.
- “First” through “Fifth” refer to finally sustained violations of the same category within the adopting organization’s published lookback period. A decision still under review must not count toward the next instance.
+7d stackingmeans seven days are added to the previous level for each later instance;Perm/Permanentmeans an indefinite suspension;Server Banmeans a platform-wide ban; andEvent Penaltymeans an additional participation restriction defined in the adopting organization’s published rules.- A blank cell means that the supplied schedule does not define that instance; no automatic escalation may be inferred.
- Force Majeure, insufficient evidence, or a procedural defect cannot be cured through stacking. Multiple labels arising from the same continuous act and protecting the same interest should not be punished more than once.
12. Review and Appeal
- The Subject must receive a written summary of the finding, applied Terms, sanction, effective time, and review deadline, except to the limited extent necessary to protect another person’s private data or a genuinely sensitive detection method.
- A review request may challenge identity, facts, evidence integrity, classification, procedure, Force Majeure, duplication, or sanction calculation.
- The reviewer must be independent of the original finding where reasonably possible and must record the result and reasons.
- A reversed or corrected finding must be removed from stacking calculations, and affected records must be corrected promptly.
13. Privacy, Security, and Retention
- Only data necessary to document the SS and support a finding may be collected. Passwords, authentication tokens, unrelated private messages, and unrelated personal files must not be retained.
- Access to SS material must be limited to authorized SSers, reviewers, and security personnel with a documented need.
- Recordings, exports, screenshots, and reports must be encrypted or otherwise reasonably protected, access-logged, and retained only for a published period.
- At the end of the retention period, material must be securely deleted unless preservation is required by law or an active review.
- Unauthorized access or disclosure must be handled under the adopting organization’s incident-response process, including notice where required.
14. Adoption and Amendments
- The adopting organization must publish its identity, authorized SS roles, approved tools, response intervals, retention period, review contact, lookback period, and any local variation to the Penalty Schedule.
- A material amendment applies prospectively from its published effective date unless it is more favorable to a Subject and the adopting organization expressly applies it to an open matter.
- If any provision is invalid or unenforceable, the remaining provisions continue to apply to the extent permitted.