drop webauthn registration + assertion log · parse authenticator data + counter
flags signCount rollback/reuse · uv=false on sensitive ops · cross-rpId credential reuse hints
heuristic screener · log schema varies by rp export — field mapping is best-effort · not definitive proof