drop darktrace incident export · parse model breaches + behaviours · runs locally
incident export · model breach · score · local only
heuristic screener · vendor schema varies · not definitive proof