drop OT + IT log set · correlate kinetic event with cyber precursor · runs locally
ot logs · it logs · timeline · local only
heuristic screener · vendor schema varies · not definitive proof