drop deception + edr exports · correlate decoy hit to endpoint alert · runs locally
drop deception + edr exports · local only
heuristic screener · vendor schema varies · not definitive proof