drop process memory · detect overwritten dll sections in memory · runs locally
duplicate PE for same DLL · RWX sections · abnormal section names · ReflectiveLoader
heuristic screener · parses artifacts locally · not definitive proof