drop canary incident export · parse token + attacker ip + action · runs locally
drop canary incident export · local only
heuristic screener · vendor schema varies · not definitive proof