drop dns query log export · detect high-entropy subdomain bursts · runs locally
drop dns query log export · local only
heuristic screener · vendor schema varies · not definitive proof