Product truth · Reviewed 2026-08-19
TaiGong Drill v1.3.4 support matrix.
Four states, one current version.
How to read this matrix
Core is available without a dedicated feature entitlement. Licensed requires the applicable server-side entitlement. Integration-only is a connector or adapter, not a native delivery capability. Unsupported means Drill v1.3.4 does not ship the stated runtime support.
This page was reviewed against the current TaiGong Drill 1.3.4 implementation tree on 19 August 2026. A SaaS plan, private license, provider configuration, signed order, or project scope can narrow what is available; it cannot turn an unsupported claim into a shipped feature.
Delivery channels and communication.
| Capability | Status | Current 1.3.4 boundary |
|---|---|---|
| SMTP email campaigns | Core | Native campaign delivery with templates, landing pages, event tracking, and evidence. |
| SMS campaigns | Licensed | Aliyun, Tencent Cloud, and Twilio providers. Console output is a test provider, not a carrier. |
| DingTalk | Licensed | Group-robot webhook, App direct messaging, and contact sync. |
| Feishu (China) | Licensed | Group-robot webhook, App direct messaging, and contact sync through the Feishu China endpoint. Feishu support does not imply Lark International support. |
| WeCom / WeChat Work | Licensed | Group-robot webhook only. No WeCom App direct messaging or directory sync. |
| QR code | Core | A generated content asset for templates or manual distribution, not an independent campaign channel. |
| Slack | Integration-only | Outbound TaiGong event notification formatting to a Slack webhook. Slack is not simulation delivery. |
| Microsoft Teams | Unsupported | No native campaign provider or Teams-specific event adapter. |
| Lark International | Unsupported | No Lark platform option or international Lark endpoint. |
Analysis, risk, training, and automation.
| Capability | Status | Current 1.3.4 boundary |
|---|---|---|
| Campaign funnel, timeline, comparison, retraining, and evidence | Core | Base sent, opened, clicked, submitted, reported, and campaign-evidence views. |
| Basic risk scoring | Core | Current base scoring and evidence context. |
| Advanced risk analytics, threat context, and PDF reports | Licensed | High-risk users, trends, department exposure, vulnerability views, rankings, and advanced reporting. |
| Awareness courses, batches, and built-in scenarios | Licensed | Training administration, assessment, completion statistics, and scenario library. |
| Automation rules, scheduled jobs, and multi-stage orchestration | Licensed | Rules, executions, time/event triggers, scheduled jobs, and campaign stages. |
| External HR REST connection | Integration-only | A configurable REST integration; TaiGong does not include an HR system. |
Governance and deployment.
| Capability | Status | Current 1.3.4 boundary |
|---|---|---|
| SaaS tenant isolation and API tokens | Core | Tenant-aware SaaS request handling and API-token management. |
| Outbound event webhooks | Integration-only | Connect TaiGong events to external systems; does not add a delivery channel. |
| RBAC and searchable/exportable audit console | Licensed | Role management and audit-log management endpoints are entitlement-gated. Underlying audit collection alone does not imply console access. |
| SAML, OIDC, SCIM, or LDAP enterprise SSO | Unsupported | No enterprise identity-provider integration. Simulating an SSO lure is not SSO support. |
| Private single-host deployment | Core | Shipped private deployment mode; SQLite is the default database configuration. |
| Multi-tenant SaaS deployment | Core | Shipped SaaS mode; MySQL is required for the SaaS runtime. |
| Kubernetes or Helm delivery | Unsupported | No supported Kubernetes manifests or Helm chart. |
AI, MCP, and advanced validation.
| Capability | Status | Current 1.3.4 boundary |
|---|---|---|
| AI-assisted email, SMS, IM, and insight generation | Licensed | Requires the AI entitlement plus an external model provider, endpoint, and key. TaiGong does not bundle a model. |
| Autonomous AI Agent | Unsupported | No autonomous planning, approval, or Agent runtime is shipped as a Drill 1.3.4 feature. |
| MCP adapter | Integration-only | API adapter with backend authentication and entitlement checks. Current MCP campaign creation is email-only; SMS and IM coverage is listing rather than end-to-end creation and delivery. |
| Burn links and target-platform filtering | Core | Native campaign controls with runtime enforcement. |
| Evasion controls, HTML smuggling, AiTM/phishlets, and captured sessions | Licensed | Restricted advanced-validation modules for written, authorized exercises. |
| Complete Evilginx compatibility | Unsupported | Partial phishlet YAML import is not full schema or runtime compatibility; unsupported keys are reported. |
Separate TaiGong platforms outside Drill 1.3.4.
| Direction | Status in Drill | Boundary |
|---|---|---|
| TaiGong Trace | Separate platform | Formal incident-response and attack-chain-tracing platform. It is not a Drill 1.3.4 core module; current version, license, integrations, and delivery scope are confirmed per project. |
| TaiGong MailLab | Separate platform | Formal email-sample-analysis and security-operations platform. It is not a Drill 1.3.4 core module; sample handling, license, collaboration, and delivery scope are confirmed per project. |
| v1.3.5 and broader Agent/MCP launch material | Future | Roadmap or future-release communication until a later public version is actually delivered and verified. |
Version policy
This page describes version 1.3.4 only and does not infer roadmap commitments. For procurement or private delivery, use it together with the active license and signed project scope.