drop volatility json/text plugin output · parse process + dll + network artifacts · runs locally
drop volatility json/text plugin output · local only
heuristic screener · vendor schema varies · not definitive proof