drop process memory · detect page-guard / veh-based api hooking · runs locally
AddVectoredExceptionHandler · PAGE_GUARD 0x100 · VirtualProtect setup · VEH+guard correlation
heuristic screener · parses artifacts locally · not definitive proof