drop 2+ siem incident exports · unified alert timeline graph · runs locally
drop 2+ siem incident exports · local only
heuristic screener · vendor schema varies · not definitive proof