drop process + loaded modules · detect signed binary loading unsigned sideload · runs locally
matches trusted publisher exe loading unsigned colocated DLL · csv/json module inventory
heuristic screener · parses exports locally · not definitive proof