- highlight legitimate and direct-syscall detection outputs prominently in the main README
- add supporting visuals for IOCTL event format and test validation flows in usage, API, and install guides
- replace legacy DDSS/DSS assets with updated detection and test imagery under diagram/
- keep documentation focus aligned with operator-facing detection outcomes and integration context
- update README/API/INSTALL/USAGE content for renamed surfaces and current workflows
- add and revise usage runbooks plus stdlib ETW/IOCTL consumer examples
- add direct syscall example and supporting examples README
- rename and expand architecture diagram assets to match current telemetry layout