Prosecution Insights
Last updated: October 01, 2026
Application No. 18/819,135

OBJECT INSPECTION VIA OPERATING SYSTEM SHARE FUNCTION

Non-Final OA §103
Filed
Aug 29, 2024
Priority
Sep 30, 2021 — continuation of 12/164,634
Examiner
JEUDY, JOSNEL
Art Unit
2438
Tech Center
2400 — Computer Networks
Assignee
McAfee LLC
OA Round
2 (Non-Final)
84%
Grant Probability
Favorable
2-3
OA Rounds
8m
Est. Remaining
68%
With Interview

Examiner Intelligence

Grants 84% — above average
84%
Career Allowance Rate
674 granted / 804 resolved
+25.8% vs TC avg
Minimal -16% lift
Without
With
+-16.1%
Interview Lift
resolved cases with interview
Typical timeline
2y 9m
Avg Prosecution
16 currently pending
Career history
817
Total Applications
across all art units

Statute-Specific Performance

§101
19.2%
-20.8% vs TC avg
§103
49.9%
+9.9% vs TC avg
§102
7.2%
-32.8% vs TC avg
§112
9.2%
-30.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 804 resolved cases

Office Action

§103
DETAILED ACTION Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . 1.This is a Final Office Action in response to applicant’s amendment filed on May 05, 2026. At this time, claims 1-66 have been cancelled. Claims 67-80 and 84 have been amended. Therefore, claims 67-86 are pending and addressed below. Response to Arguments Applicant’s Terminal Disclaimer is sufficient to overcome the Double Patenting Rejection set forth in the previous office action. Applicant’s amendment is sufficient to overcome the claims objection set forth in the previous office action for claims 68-79. Applicant argues with respect to independent claims that: I) Upon review, the cited references, taken alone or together, do not appear to disclose “based upon determining that a user has used the share function on a software object and selected the security scanner application as a target of the share function, cause a security agent to scan the software object to determine a security reputation of the software object “. Examiner respectfully disagrees and maintains that Kiehtreiber discloses as a result, in response to a subsequent request for invoking the extension associated with entry 650, newer version of extension 622 will be identified and launched… processing logic receives a request from a first application inquiring a particular extension service (e.g., identified by a particular UTI) associated with a particular extension point extended by one or more other applications. In response to the request, at block 652, processing logic identifies a list of one or more extensions installed and capable of providing the requested service via that particular extension point, including identifying the latest versions of the extensions. A number of methodologies have been used in an attempt to reduce or eliminate both the attacks and influence of malicious or defective code. Generally, these methodologies include detection, prevention, and mitigation. Specifically, these methodologies range from attempts to scan, identify, isolate, and possibly delete malicious code before it is introduced to the system or before it does harm (such as is the objective of anti-virus software, and the like), to restricting or containing the actions which may be taken by processes affected by malicious or defective code. However, there has been a lack of efficient ways for handling a plugin associated with an application that invokes another application in a secured manner. In addition, Nachenberg discloses (7) If the reputation/prevalence information for at least one of the shared objects is significantly lower than that of either the executable file or the majority of the remaining shared objects (e.g., if a shared object has a significantly lower reputation score and/or is much less prevalent than either the executable file or a majority of the remaining shared objects loaded by the process), then the client-side system may determine that this shared object represents a potential security risk. In this example, the client-side system may perform a security operation on the identified shared object by, for example, quarantining or removing the shared object, preventing the shared object from loading, flagging the shared object for further evaluation (i.e., including performing a security scan) and/or removing references to the shared object (e.g., load points for the shared object stored in a computing device's registry) from the computing device. All of this corresponds to based upon determining that a user has used the share function on a software object and selected the security scanner application as a target of the share function, cause a security agent to scan the software object to determine a security reputation of the software object. For further details, See Kiehtreiber, [0087-0088] and [0008] and Nachenberg, col 14, lines 32-47 and col 1, lines 48-62. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claims 67- 68, 80, 82, 83-85 are rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024). 67. Kiehtreiber discloses a computer-implemented method, (See Kiehtreiber, abstract; according to one embodiment, in response to an inquiry received from a first application for an extension service associated with a first of a plurality of extension points of an operating system, a list of one or more extensions is identified that have been registered for the first extension point with the operating system, where the first application is executed within a first sandboxed environment. ) comprising: registering a security scanner application with a share function of an operating system, wherein the share function provides a graphical menu to share or send items; (See Kiehtreiber, [0084-0087] FIG. 6A is a block diagram illustrating a system for registering an extension according to one embodiment of the invention. System 600 may be implemented as part of an operating system as described above. Referring to FIG. 6A, an extension framework, such as the one as shown in FIG. 3A, maintains extension registry 350 having described therein a list of extensions that has been installed and registered in the operating system. In one embodiment, extension registry 350 includes multiple entries, each corresponding one of the installed or registered extensions. Each extension entry includes, but is not limited to, extension ID 610, extension provider ID 602, and extension key 603. Extension ID 610 may uniquely identify a type or class of extension services that is defined and agreed upon between an operating system provider and extension providers, such as a UTI. Extension provider ID 611 may uniquely identify an extension provider that provides an extension service, which may be authorized or certified by a predetermined authority… Extension key 612 may represent a particular version or instance of an extension currently installed or registered with the system. it is assumed extensions 621-622 are provided by the same extension provider, where extension 621 is an earlier version while extension 622 is a newer version. When extension 621 was installed by installation module 320, a corresponding entry 650 was created, where field 610 stores an extension class ID (e.g., UTI) associated with the type of extension services that extension 621 provides, in this example, content sharing services.) based on determining that a user has used the share function on a software object and selected the security scanner application as a target of the share function, [[causing a security agent to scan the software object to determine a security reputation of the software object]]; (See Kiehtreiber, [0087-0088]; As a result, in response to a subsequent request for invoking the extension associated with entry 650, newer version of extension 622 will be identified and launched… processing logic receives a request from a first application inquiring a particular extension service (e.g., identified by a particular UTI) associated with a particular extension point extended by one or more other applications. In response to the request, at block 652, processing logic identifies a list of one or more extensions installed and capable of providing the requested service via that particular extension point, including identifying the latest versions of the extensions.) Kiehtreiber does not appear to explicitly disclose scanning the software object to determine a security reputation of the software object; and notifying the user of the security reputation. However, Nachenberg discloses causing a security agent to scan the software object to determine a security reputation of the software object; (See Nachenberg, col 14, lines 32-47 AND col 14, lines 32-47 and col 1, lines 48-62; one or more steps of an exemplary method for using reputation data to detect shared-object-based security threats. Such a method may comprise: 1) identifying a process, 2) identifying an executable file associated with the process, 3) identifying at least one shared object loaded by the process, 4) obtaining reputation data for both the executable file and the shared object from a reputation service, 5) determining that the shared object represents a potential security risk by a) comparing the reputation data for the executable file with the reputation data for the shared object and b) determining that the reputation data for the shared object is significantly different from the reputation data for the executable file, and then 6) performing a security operation on the shared object. (7) If the reputation/prevalence information for at least one of the shared objects is significantly lower than that of either the executable file or the majority of the remaining shared objects (e.g., if a shared object has a significantly lower reputation score and/or is much less prevalent than either the executable file or a majority of the remaining shared objects loaded by the process), then the client-side system may determine that this shared object represents a potential security risk. In this example, the client-side system may perform a security operation on the identified shared object by, for example, quarantining or removing the shared object, preventing the shared object from loading, flagging the shared object for further evaluation (i.e., including performing a security scan) and/or removing references to the shared object (e.g., load points for the shared object stored in a computing device's registry) from the computing device.) and notifying the user of the security reputation. (See Nachenberg, col 1, lines 48-55; then the client-side system may determine that this shared object represents a potential security risk. In this example, the client-side system may perform a security operation on the identified shared object by, for example, quarantining or removing the shared object, preventing the shared object from loading, flagging the shared object for further evaluation, and/or removing references to the shared object (e.g., load points for the shared object stored in a computing device's registry) from the computing device. See also Fig 6; Display device 624 generally represents any type or form of device capable of visually displaying information forwarded by display adapter 626. Similarly, display adapter 626 generally represents any type or form of device configured to forward graphics, text, and other data from communication infrastructure 612 (or from a frame buffer, as known in the art) for display-on-display device 624.) Kiehtreiber and Nachenberg are analogous art because they are from the same field of endeavor which is Operating system share function. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber with the teaching of Nachenberg to include the reputation service because it would have allowed to detect shared-object-based security threats. (See Nachenberg, col 1, lines 35-37) 68.The combination of Kiehtreiber and Nachenberg discloses the computer-implemented method of claim 67, wherein the security reputation includes a reputation for maliciousness. (See Nachenberg, col 4, lines 15-17; using reputation data to detect shared objects that represent potential security threats) Kiehtreiber and Nachenberg are analogous art because they are from the same field of endeavor which is Operating system share function. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber with the teaching of Nachenberg to include the reputation service because it would have allowed to detect shared-object-based security threats. (See Nachenberg, col 1, lines 35-37) 80. As to claim 80, the claim is rejected under the same rationale as claim 67. See the rejection of claim 67 above. 82. The combination of Kiehtreiber and Nachenberg discloses the one or more tangible, nontransitory computer-readable storage media of claim 80, wherein the software object comprises a browser extension. (See Kiehtreiber, [0005]) 83. The combination of Kiehtreiber and Nachenberg discloses the one or more tangible, nontransitory computer-readable storage media of claim 80, wherein the software object comprises a downloaded file. (See Kiehtreiber, [0089]) 84. As to claim 84, the claim is rejected under the same rationale as claim 67. See the rejection of claim 67 above. a hardware platform comprising a processor circuit and a memory and instructions encoded within the memory to instruct the processor circuit to (See Kiehtreiber, [0004]; desktop computers, notebook and handheld computers, and other similar devices utilizing a microprocessor, microcontroller, or a digital signal processor, to execute coded instructions) 85. As to claim 85, the claim is rejected under the same rationale as claim 68. See the rejection of claim 68 above. Claims 69-74, 76, 86 are rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024)in further view of Dixon, US 20060253584 A1. 69. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for data security. However, Dixon discloses wherein the security reputation includes a reputation for data security. (See Dixon, [0007-0008]) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Operating system share function. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 70. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for data privacy. However, Dixon discloses wherein the security reputation includes a reputation for data privacy. (See Dixon, [ 0329]; data privacy) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Operating system share function. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 71. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for phishing. However, Dixon discloses wherein the security reputation includes a reputation for phishing. (See Dixon, [0007]; reputation for phishing) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 72. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for adware. However, Dixon discloses wherein the security reputation includes a reputation for adware. (See Dixon, [0007]; reputation for adware) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 73. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for utility. However, Dixon discloses wherein the security reputation includes a reputation for utility. (See Dixon, [0283] ) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 74. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for spyware. However, Dixon discloses wherein the security reputation includes a reputation for spyware. (See Dixon, [0007]) ) Kiehtreiber, Nachenberg and Bui are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 76. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein scanning the software object comprises performing a local scan. However, Dixon discloses wherein scanning the software object comprises performing a local scan. (See Dixon, [0032]) Kiehtreiber, Nachenberg and Dixon are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Dixon to include the reputation service because it would have allowed real-time, reputation-based Web services. (See Dixon, [0004]) 86. As to claim 86, the claim is rejected under the same rationale as claim 69. See the rejection of claim 69 above. Claim 75 is rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024) in further view of VESCIO, US pat. No 20180069882 A1. 75. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein the security reputation includes a reputation for ransomware. However, VESCIO discloses wherein the security reputation includes a reputation for ransomware. (See VESCIO, [0069-0070] ) Kiehtreiber, Nachenberg and VESCIO are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of VESCIO to include the reputation service because it would have allowed for risk measurement and modeling may be understood. According to an exemplary embodiment, such a method and system may be used to improve the performance of one or more systems, such as information networks, belonging to a business or other organization, by improving the efficiency of resource allocation to address various threats to the one or more systems and improving the quality of information used to manage threats. (See VESCIO, [0008]) Claims 77 is rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024) in further view of Shavell, US 10404733 B1. 77. The combination of Kiehtreiber and Nachenberg does not appear to explicitly disclose the computer-implemented method of claim 67, wherein scanning the software object comprises causing a cloud-based scan to be performed. However, Shavell discloses wherein scanning the software object comprises causing a cloud-based scan to be performed. (See Shavell, col 8, lines 55-67) Kiehtreiber, Nachenberg and Shavell are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of Shavell to include the scanning service because it would have allowed for performing security remediation on a computing system in response to updates from a reputation service. (See Shavell, col 1, lines 7-10) Claims 78-79 are rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024) in further view of Shavell, US 10404733 B1 in further view of Rasanen, US pat.No 20180139216 A1. 78. The combination of Kiehtreiber, Nachenberg and Shavell does not appear to explicitly disclose the computer-implemented method of claim 77, wherein causing the cloud-based scan to be performed comprises sending a copy of the software object to a cloud scanning service. However, Rasanen discloses wherein causing the cloud-based scan to be performed comprises sending a copy of the software object to a cloud scanning service. (See Rasanen, [0048], [0065]; copy of file that has been scanned) Kiehtreiber, Nachenberg, Shavell and Rasanen are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg and Shavell with the teaching of Rasanen to include the scanning service because it would have allowed supplemental scan to be performed for protection of system. 79. The combination of Kiehtreiber, Nachenberg, Shavell and Rasanen discloses the computer-implemented method of claim 77, wherein causing the cloud-based scan to be performed comprises sending metadata about the software object to a cloud scanning service. (See Rasanen, [0016]-0024], [0059]; metadata of the file) Kiehtreiber, Nachenberg, Shavell and Rasanen are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg and Shavell with the teaching of Rasanen to include the scanning service because it would have allowed supplemental scan to be performed for protection of system. Claim 81 is rejected under 35 U.S.C 103 as being unpatentable over Kiehtreiber, US 20150347749 A1 in view of Nachenberg, US 8225406 B1 (IDS Submitted, 09/11/2024) in further view of Walker, US pat. No 20200104145 A1. 81. The combination Kiehtreiber and Nachenberg does not appear to explicitly disclose the one or more tangible, nontransitory computer-readable storage media of claim 80, wherein the software object comprises an application from an app store. However, Walker discloses wherein the software object comprises an application from an app store. (See Walker, [0042] ) Kiehtreiber, Nachenberg and Walker are analogous art because they are from the same field of endeavor which is Intrusion detection. It would have been obvious to a person of ordinary skill in the art before the effective filing date of the claim invention to modify the invention of Kiehtreiber and Nachenberg with the teaching of WALKER to include the app store because it would have allowed supplement app service to a user. Conclusion The prior art made of record and not relied upon is considered pertinent to applicant's disclosure. Rusakov, US 9122872 B1, title “System And Method For Treatment Of Malware Using Antivirus Driver. “ Hansen, US 20210152595 A1, title “ METHODS AND SYSTEMS FOR RANSOMWARE DETECTION, ISOLATION AND REMEDIATION.“ Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSNEL JEUDY whose telephone number is (571)270-7476. The examiner can normally be reached M-F 10:00-8:00. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Arani T Taghi can be reached at (571)272-3787. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. Date: 2/2/2026 /JOSNEL JEUDY/Primary Examiner, Art Unit 2438
Read full office action

Prosecution Timeline

Aug 29, 2024
Application Filed
Feb 05, 2026
Non-Final Rejection mailed — §103
May 05, 2026
Response Filed
Jul 13, 2026
Final Rejection mailed — §103
Sep 14, 2026
Response after Non-Final Action

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12737477
TRIGGERING A SECURITY ACTION BASED ON AN AI-GENERATED CODE PACKAGE RECOMMENDATION
2y 5m to grant Granted Sep 15, 2026
Patent 12724878
GENERATING INSTRUMENTATION FOR DATA INTEGRITY OF FUNCTION CALLS
2y 9m to grant Granted Sep 01, 2026
Patent 12711230
RANSOMWARE DISCOVERY BY DETECTION OF TRANSMIT/OVERWRITE PROCESSES
3y 4m to grant Granted Aug 18, 2026
Patent 12705615
SYSTEMS, METHODS AND APPARATUS FOR PAYMENT TERMINAL MANAGEMENT
3y 3m to grant Granted Aug 11, 2026
Patent 12694101
VIRTUAL CANARY FILES TO MITIGATE RANSOMWARE ATTACKS
2y 8m to grant Granted Jul 28, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

2-3
Expected OA Rounds
84%
Grant Probability
68%
With Interview (-16.1%)
2y 9m (~8m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 804 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month