drop edr + iam exports · correlate process user to active accounts · runs locally
drop edr + iam exports · local only
heuristic screener · vendor schema varies · not definitive proof