drop ntdll region scan · detect re-loaded clean copies of system dlls · runs locally
flags fresh disk mapping of ntdll/kernel32 · private executable mappings
heuristic screener · parses exports locally · not definitive proof