IP Library Granted Patent US 12689636
Granted Patent B2
US 12689636 · App. 18/943,284 · Granted Jul 21, 2026

Techniques for incident response and static analysis representation in computing environments

Inventors: Alma Raziel (Tel Aviv-Jaffa, IL); George Pisha (Giv'atayim, IL); Michael Aminov (Givatayim, IL); Avi Tal Lichtenstein (Tel Aviv, IL); Tal Gilady (Brooklyn, NY); Amitai Cohen (Kfar Saba, IL)
Assignee: Wiz, Inc.
H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12689636
App. No.
18/943,284
Filed
Nov 11, 2024
Granted
Jul 21, 2026
Kind
B2
Art Unit
2494
USPC
726/23
Abstract

A system and method for detecting an attack path in a computing environment is presented. The method includes: detecting a forensic artifact in a computing environment, the forensic artifact including an identifier of a resource deployed in the computing environment; inspecting the resource for a cybersecurity object, the cybersecurity object indicating a cybersecurity issue; generating a representation of: the detected forensic artifact, the resource, and the cybersecurity object, in a security database, wherein the security database includes a representation of the computing environment; generating a potential lateral movement path between the resource and another resource; and generating a visualization based on the potential lateral movement, the forensic artifact, and the cybersecurity object.

Claims (68)

1 . A method for detecting an attack path in a computing environment, comprising:

detecting a forensic artifact in a computing environment, the forensic artifact including an identifier of a resource deployed in the computing environment;

generating an inspectable disk based on the resource;

inspecting the inspectable disk for a cybersecurity object, the cybersecurity object indicating a cybersecurity issue;

generating in a security database a representation of: the detected forensic artifact, the resource, and the cybersecurity object, wherein the security database further includes a representation of the computing environment;

determining a number of hops between the resource and another resource;

generating a potential lateral movement path between the resource and the another resource, the lateral movement path including at least another entity deployed in the computing environment between the resource and the another resource;

generating a visualization based on the potential lateral movement; and

initiating a remediation action based on the cybersecurity issue.

2 . The method of claim 1 , further comprising:

generating a forensic finding based on the forensic artifact.

3 . The method of claim 1 , further comprising:

inspecting the another resource for a cybersecurity object indicating the cybersecurity issue; and

determining that the potential lateral movement path is a confirmed lateral movement path in response to detecting the cybersecurity object on the another resource.

4 . The method of claim 1 , further comprising:

generating the visualization further based on: the forensic artifact, and the cybersecurity object.

5 . The method of claim 1 , further comprising:

generating a truncated forensic record; and

generating the visualization based on the potential lateral movement, the truncated forensic record and the cybersecurity object.

6 . The method of claim 1 , further comprising:

detecting the forensic artifact in a log of the computing environment, the log including a plurality of data records, each data record corresponding to an event.

7 . The method of claim 6 , further comprising:

parsing a data record of the plurality of data records; and

extracting a value from a predetermined data field detected based on the parsed data record.

8 . The method of claim 1 , further comprising:

traversing the security database to detect a representation of an entity of the computing environment; and

generating the visualization further based on another representation connected to the representation of the entity.

9 . A non-transitory computer-readable medium storing a set of instructions for detecting an attack path in a computing environment, the set of instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the device to:

detect a forensic artifact in a computing environment, the forensic artifact including an identifier of a resource deployed in the computing environment;

generate an inspectable disk based on the resource;

inspect the inspectable disk for a cybersecurity object, the cybersecurity object indicating a cybersecurity issue;

generate in a security database a representation of:

the detected forensic artifact, the resource, and the cybersecurity object, wherein the security database further includes a representation of the computing environment;

determine a number of hops between the resource and another resource;

generate a potential lateral movement path between the resource and the another resource, the lateral movement path including at least another entity deployed in the computing environment between the resource and the another resource;

generate a visualization based on the potential lateral movement; and

initiate a remediation action based on the cybersecurity issue.

10 . A system for detecting an attack path in a computing environment comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a forensic artifact in a computing environment, the forensic artifact including an identifier of a resource deployed in the computing environment;

generate an inspectable disk based on the resource;

inspect the inspectable disk for a cybersecurity object, the cybersecurity object indicating a cybersecurity issue;

generate in a security database a representation of:

the detected forensic artifact, the resource, and the cybersecurity object, wherein the security database further includes a representation of the computing environment;

determine a number of hops between the resource and another resource;

generate a potential lateral movement path between the resource and the another resource, the lateral movement path including at least another entity deployed in the computing environment between the resource and the another resource;

generate a visualization based on the potential lateral movement; and

initiate a remediation action based on the cybersecurity issue.

11 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a forensic finding based on the forensic artifact.

12 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

inspect the another resource for a cybersecurity object indicating the cybersecurity issue; and

determine that the potential lateral movement path is a confirmed lateral movement path in response to detecting the cybersecurity object on the another resource.

13 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate the visualization further based on: the forensic artifact, and the cybersecurity object.

14 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a truncated forensic record; and

generate the visualization based on the potential lateral movement, the truncated forensic record and the cybersecurity object.

15 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect the forensic artifact in a log of the computing environment, the log including a plurality of data records, each data record corresponding to an event.

16 . The system of claim 15 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

parse a data record of the plurality of data records; and

extract a value from a predetermined data field detected based on the parsed data record.

17 . The system of claim 10 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to

traverse the security database to detect a representation of an entity of the computing environment; and

generate the visualization further based on another representation connected to the representation of the entity.