drop zeek dns.log · parse query + answer pairs + dga heuristics · runs locally
dns.log · query/answer · rcode · local only
heuristic screener · vendor schema varies · not definitive proof