drop module rwx region scan · detect mockingjay regions · runs locally
RWX in signed DLL · msiexec/wer.dll regions · Volatility malfind · high-entropy module dumps
heuristic screener · parses artifacts locally · not definitive proof of mockingjay execution