I like that the detection hinges on the 2 decisive signals, external IP and unfamiliar process, rather than the 3 that happily matched a benign backup, that's the difference between a rule and a heuristic that pages all night. Building it on agent memory so it recalls what actually worked is the part I'd want in my incident tooling. How do you keep those decisive signals from drifting as normal behavior changes?