drop containerd state dir + log · parse container lifecycle events · timeline + findings · runs locally
flags pause container tampering · snapshot deletes · exec / nsenter events · privileged runtime · exec bursts
heuristic screener · metadata.db is string-scanned not sqlite-decoded · format varies by distro/version · parses artifacts locally · not definitive proof