drop ndr flow export · detect outbound data exfil bursts · runs locally
drop ndr flow export · local only
heuristic screener · vendor schema varies · not definitive proof