drop falco alert export · parse rule + pod + syscall · runs locally
drop falco alert export · local only
heuristic screener · vendor schema varies · not definitive proof