drop mongodb auditLog.json · parse authn + privilege events · runs locally
drop mongodb auditLog.json · local only
heuristic screener · vendor schema varies · not definitive proof