drop file system + handle table · detect ghosting (deleted-before-mapped) · runs locally
SECTION_IMAGE from delete-pending file · MFT deleted executable · handle table cross-ref
heuristic screener · parses artifacts locally · not definitive proof of process ghosting