drop threat feed + siem exports · correlate ioc to alert hits · runs locally
drop threat feed + siem exports · local only
heuristic screener · vendor schema varies · not definitive proof