drop insightidr investigation export · parse evidence + actor + timeline · runs locally
investigation timeline · assets · actors · local only
heuristic screener · vendor schema varies · not definitive proof