Contd. TSG’s Capabilities including HTTP, DNS, Email, TLS, QUIC, and SIP. TSG is designed to monitor both internet traffic and telephone censor specific (VPNs) and sessions in communications. applications other and methods realtime of through Additionally, websites, it as well as circumvention. TSG is techniques such as has to the capacity block Virtual to identify Private and Networks also capable of modifying spoofing redirect responses, HTTP altering headers, injecting scripts, replacing text, and overriding response bodies. TSG has the ability to block, monitor, intercept, or manipulate network traffic by matching a range of metadata, such as IP addresses, host names, built-in and user-defined categories, URLs, and TLS fingerprints. When the connection is not encrypted using TLS, it can even intercept HTTP header content. Furthermore, signatures, TSG can passwords, extract the email addresses, metadata for attachments, telephone and email communications, including both origin and destination phone numbers. TSG is capable methods. The of analyzing first method Transport involves Layer full Security decryption (TLS) using traffic the through two primary Man-in-the-Middle (MITM) technique, which requires the installation of a self-signed root Certificate Authority (CA) certificate by the subscriber. The second method employs deep packet inspection (DPI) and machine learning techniques to extract metadata from encrypted traffic. The latter approach is more commonly used, as it’s invisible to the internet user, thereby eliminating the need for the internet user to install a CA certificate or configure any proxy settings. Additionally, a hybrid operation is possible, where full decryption is restricted to a specific subset of domains. Decrypted traffic can also be mirrored to another device for further inspection. The component responsible for implementing the TLS MITM attacks is referred to as the Tiangou Frontend Engine (TFE). The company's use of these two distinct TLS analysis methods may stem from decisions made when deploying in one of Geedge’s first client countries, Kazakhstan. When Kazakhstan first attempted to implement nationwide censorship, long before Geedge was founded, Kazakhstan explored requiring all internet users to install a government-controlled TLS certificate authority. This approach would have enabled them to intercept all encrypted traffic by running their own CA and operating outside the global internet trust system. However, the method proved impractical—requiring manual installation on every device— and ultimately failed when international browser manufacturers blocked the root certificate. This example is described in more detail in the country deployment section. Blocking VPNs & Circumvention Tools TSG also employs deep packet inspection to comprehensively identify protocols associated with Virtual Private Networks (VPNs) and circumvention tools, such as OpenVPN WireGuard. It then allows clients to work with Geedge Networks to develop rulesets to... and

Select target paragraph3