drop suspect device + comms · detect counter-investigation behavior pattern · runs locally
device + comms export · local only
heuristic screener · vendor schema varies · not definitive proof