drop sophos central event export · parse threat + tamper events · runs locally
threat events · tamper protection · local export only
heuristic screener · vendor schema varies · not definitive proof