What Bytesnare does not do
The page every security vendor could write and none of them does. These are things Bytesnare will not do, by decision rather than by omission.
It does not claim a capability it cannot perform
Every capability reports one of six states with a reason attached. A feature your hardware cannot support, or your policy will not permit, is a sentence you can read rather than a menu item that quietly does nothing — and there is no padlock on it, because a limit is a statement about the software rather than an upsell.
It publishes no performance figure without the hardware it came from
A benchmark without its machine is a decoration. Numbers appear here when they have been measured, naming what they were measured on.
It does not read your encrypted traffic
Bytesnare sees which program connected where, not what was said. Reading the contents of an encrypted connection means intercepting it, which this does not do — whatever a vendor claiming to see it passively tells you.
ATT&CK tags are not coverage
Technique tags are labels. They are never a verdict, never proof that anything is covered, and never change what the endpoint does.
Unreachable means unknown, not safe
If the app cannot reach the service it says protection status cannot be
determined — not at risk, and not a green tick. Both of those would
be conclusions nobody observed.