drop defender xdr incident export · parse alert + entity + stage · runs locally
drop defender xdr incident export · local only
heuristic screener · vendor schema varies · not definitive proof