drop crowdstrike rtr session log · parse remote commands · runs locally
rtr commands · remote shell · session audit · local export only
heuristic screener · vendor schema varies · not definitive proof