drop corelight export · parse conn + dns + http meta · runs locally
drop corelight export · local only
heuristic screener · vendor schema varies · not definitive proof