drop ransom address + payment txid · trace flow + clustering + exchange touchpoint · runs locally
ransom address · payment txid · local only
heuristic screener · vendor schema varies · not definitive proof