Where in scope, the tester must consider AV, EDR, IDS, and similar controls and use evasion techniques that mirror realistic threat actor tradecraft while leaving sufficient logs for blue team replay.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.