drop zeek http.log · parse request/response + ua + uri anomalies · runs locally
http.log · uri · user-agent · status · local only
heuristic screener · vendor schema varies · not definitive proof