drop process snapshot · detect threads created suspended + remote-buffer write pattern · runs locally
CREATE_SUSPENDED · cross-process remote write · sysmon 8 style exports
heuristic screener · parses exports locally · not definitive proof