Installed Application Matrix & Capability Isolation
Preset: Strict Privacy Hardened
Hardened Risk Index
28
Unrestricted Baseline
82
Revoked Capabilities
6
Intercepted Syscalls
14
| Application / Binary | Mic | Cam | Screen | Keys | FileSys | NetSock | Action |
|---|
Profile Custom Binary / Executable
Kernel Capability Interception
Engine Active
Exposure Risk Reduction
65.9% Safer
0 (Isolated)
Risk Score: 28 / 100
100 (Exposed)
Windows 11 Granular Control: Unlike older Win32 models where any process inherited full user rights, capability SIDs sandbox `NtUserRegisterHotKey`, `MediaCaptureService`, and raw device handles per binary hash.
Live Capability Interception Log
Generated Policy PowerShell Preview
# Enforceable Windows 11 AppCapability Policy Script
# Generated automatically from active workbench state