drop aws cloudhsm audit log · parse key + user events · runs locally
drop aws cloudhsm audit log · local only
heuristic screener · vendor schema varies · not definitive proof