IP Library Granted Patent US 12694106
Granted Patent B2
US 12694106 · App. 18/978,990 · Granted Jul 28, 2026

Incident driven automated investigation

Inventors: Eric Joseph Hammerle (Kirkland, WA); Xue Jun Wu (Seattle, WA); Colin James Phillips (Kirkland, WA); Alexander Gearhart Burner (Seattle, WA); Brian David Hatch (Seattle, WA); Tien-jui Lee (Seattle, WA)
Assignee: Dropzone.ai, Inc.
G06F21/554G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694106
App. No.
18/978,990
Granted
Jul 28, 2026
Kind
B2
Abstract

Embodiments monitor security environments. An assessment of events may be used to generate event data that includes findings associated with events. The event data may be employed to: determine users associated with an event based on a discovery agent provided a discovery prompt; determine findings that may be eligible for an interview based on a subject agent provided a subject prompt; employ the subject agent to generate questions based on the eligible findings such that each question requests additional information associated with the eligible findings; collecting the additional information for the eligible findings based on a questioner agent provided a questioner prompt to perform an interview. An updated assessment may be employed to display a report for security administrators.

Claims (129)

1 . A method for monitoring security environments in a computing environment using one or more processors to execute instructions that are configured to cause actions, comprising:

using an analytic agent to obtain an assessment based on an investigation of one or more events associated with activity in the computing environment, wherein the assessment is used to generate event data that includes a plurality of findings associated with the investigation of the one or more events;

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; and

using the event data to cause further actions, including:

using a discovery agent to collect one or more users associated with an event based on the event data, wherein the discovery agent generates a discovery prompt to train one or more discovery models to identify one or more of a user or a candidate user to interview about the activity based on one or more event metrics and the event data that is updated to include one or more identifiers associated with the one or more of the user or the candidate user, wherein the event metrics include one or more of a rate, a size, a type, or a scope of the one or more events;

using a subject agent to collect one or more of the plurality of findings that are eligible for an interview based on the event and the updated event data, wherein the collection by the subject agent generates a subject prompt to train one or more subject models to determine eligibility of the one or more findings based on the updated event data;

using the subject agent to retrain the one or more subject models to collect a plurality of questions based on the one or more eligible findings and the updated event data, wherein each question requests additional information associated with the one or more eligible findings, and wherein the analysis agent determines one or more answers for one or more portions of the plurality of questions;

collecting one or more mandatory questions based on one or more characteristics of the event, wherein the one or more characteristics include one or more of an event type, an event priority, an event source, an event target, or a time-of-day, a geographic location, wherein the one or more mandatory questions are included in the interview;

using one or more other portions of the plurality of questions that are unanswered by the analysis agent to obtain an interactive interface, wherein the interactive user interface presents the one or more eligible findings and the one or more unanswered questions in a web page with one or more fields to collect one or more responses from the one or more of the user or candidate user that is also related to the one or more eligible findings;

using the one or more responses to iteratively collect one or more new questions that request new information that is related to the one or more eligible findings, wherein the collection of the new information continues until either one or more sources are identified for the one or more events or completion of one or more conditions causes abandonment of the interview;

using a questioner agent to collect the additional information and the new information for the one or more eligible findings based on each response from the one or more of the user or the candidate user to the one or more questions and the one or more new questions that are collected in the interactive user interface;

employing the questioner agent to generate a questioner prompt to train one or more questioner models to perform an interview using the one or more unanswered questions, the one or more new questions and context in the interactive user interface to elicit the additional information and the new information from the one or more of the user or the candidate user, wherein the questioner agent evaluates the one or more responses by the one or more of the user or the candidate user in the interview, wherein questioner agent automatically terminates the interview based on one or more of uncooperativeness, lack of knowledge, or an incorrect response to the one or more new and unanswered questions; and

updating the assessment of the one or more events based on the additional information and the new information; and

using the updated assessment to display a report for one or more security administrators associated with the computing environment.

2 . The method of claim 1 , further comprising:

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; collecting one or more constraints based on one or more of a policy or the event data, wherein the one or more constraints include one or more of a type of user identifier to acknowledge or a user identifier to ignore; and

obtaining the discovery prompt based on the one or more artifacts and the one or more constraints.

3 . The method of claim 1 , further comprising:

using a large language model to generate a natural language summary of the event based on the updated event data;

collecting one or more constraints associated with the one or more questions based on one or more of a policy or the updated event data, wherein the one or more constraints include one or more of a date range, or a subject to ignore; and

including the event summary and the one or more constraints in the subject prompt.

4 . The method of claim 1 , further comprising:

collecting one or more directives based on one or more of a policy or the updated event data, wherein the one or more directives include one or more of a directive to include statements in the interview that convey a conversational tone, a directive to encourage a user to submit evidence or supporting documents, a directive to provide context associated with each question, or a directive to omit follow up questions that exceed a scope of a question; and

including the interview directives in the questioner prompt.

5 . The method of claim 1 , wherein collecting the additional information for the one or more eligible findings, further comprises:

collecting one or more communication methods for performing the interview based on one or more of a policy, a user preference, an event type, or an event priority, wherein the one or more communication methods include one or more of an instant message, an email, a short message service message, a rich communication services message, a dialog box, a web form, or a push notification; and

collecting one or more other communication methods based on a lack of response from the one or more users, wherein the one or more other communication methods are determined based on an escalation policy.

6 . The method of claim 1 , wherein performing the interview with the one or more users, further comprises:

obtaining the one or more questions using one or more natural language interrogative statements based on the one or more eligible findings, wherein a subject associated with the one or more questions is based on one or more facts that provide evidence to support the one or more eligible findings.

7 . The method of claim 1 , further comprising:

suspending the assessment of the one or more events based on a pending interview until the additional information is collected.

8 . A network computer for monitoring security environments in a computing environment, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that are configured to cause actions, including:

using an analytic agent to obtain an assessment based on an investigation of one or more events associated with activity in the computing environment, wherein the assessment is used to generate event data that includes a plurality of findings associated with the investigation of the one or more events;

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; and

using the event data to cause further actions, including:

using a discovery agent to collect one or more users associated with an event based on the event data, wherein the discovery agent generates a discovery prompt to train one or more discovery models to identify one or more of a user or a candidate user to interview about the activity based on one or more event metrics and the event data that is updated to include one or more identifiers associated with the one or more of the user or the candidate user, wherein the event metrics include one or more of a rate, a size, a type, or a scope of the one or more events;

using a subject agent to collect one or more of the plurality of findings that are eligible for an interview based on the event and the updated event data, wherein the collection by the subject agent generates a subject prompt to train one or more subject models to determine eligibility of the one or more findings based on the updated event data;

using the subject agent to retrain the one or more subject models to collect a plurality of questions based on the one or more eligible findings and the updated event data, wherein each question requests additional information associated with the one or more eligible findings, and wherein the analysis agent determines one or more answers for one or more portions of the plurality of questions;

collecting one or more mandatory questions based on one or more characteristics of the event, wherein the one or more characteristics include one or more of an event type, an event priority, an event source, an event target, or a time-of-day, a geographic location, wherein the one or more mandatory questions are included in the interview;

using one or more other portions of the plurality of questions that are unanswered by the analysis agent to obtain an interactive interface, wherein the interactive user interface presents the one or more eligible findings and the one or more unanswered questions in a web page with one or more fields to collect one or more responses from the one or more of the user or candidate user that is also related to the one or more eligible findings;

using the one or more responses to iteratively collect one or more new questions that request new information that is related to the one or more eligible findings, wherein the collection of the new information continues until either one or more sources are identified for the one or more events or completion of one or more conditions causes abandonment of the interview;

using a questioner agent to collect the additional information and the new information for the one or more eligible findings based on each response from the one or more of the user or the candidate user to the one or more questions and the one or more new questions that are collected in the interactive user interface;

employing the questioner agent to generate a questioner prompt to train one or more questioner models to perform an interview using the one or more unanswered questions, the one or more new questions and context in the interactive user interface to elicit the additional information and the new information from the one or more of the user or the candidate user, wherein the questioner agent evaluates the one or more responses by the one or more of the user or the candidate user in the interview, wherein questioner agent automatically terminates the interview based on one or more of uncooperativeness, lack of knowledge, or an incorrect response to the one or more new and unanswered questions; and

updating the assessment of the one or more events based on the additional information and the new information; and

using the updated assessment to display a report for one or more security administrators associated with the computing environment.

9 . The network computer of claim 8 , further comprising:

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; collecting one or more constraints based on one or more of a policy or the event data, wherein the one or more constraints include one or more of a type of user identifier to acknowledge or a user identifier to ignore; and

obtaining the discovery prompt based on the one or more artifacts and the one or more constraints.

10 . The network computer of claim 8 , further comprising:

using a large language model to generate a natural language summary of the event based on the updated event data;

collecting one or more constraints associated with the one or more questions based on one or more of a policy or the updated event data, wherein the one or more constraints include one or more of a date range, or a subject to ignore; and

including the event summary and the one or more constraints in the subject prompt.

11 . The network computer of claim 8 , further comprising:

collecting one or more directives based on one or more of a policy or the updated event data, wherein the one or more directives include one or more of a directive to include statements in the interview that convey a conversational tone, a directive to encourage a user to submit evidence or supporting documents, a directive to provide context associated with each question, or a directive to omit follow up questions that exceed a scope of a question; and

including the interview directives in the questioner prompt.

12 . The network computer of claim 8 , wherein collecting the additional information for the one or more eligible findings, further comprises:

collecting one or more communication methods for performing the interview based on one or more of a policy, a user preference, an event type, or an event priority, wherein the one or more communication methods include one or more of an instant message, an email, a short message service message, a rich communication services message, a dialog box, a web form, or a push notification; and

collecting one or more other communication methods based on a lack of response from the one or more users, wherein the one or more other communication methods are determined based on an escalation policy.

13 . The network computer of claim 8 , wherein performing the interview with the one or more users, further comprises:

obtaining the one or more questions using one or more natural language interrogative statements based on the one or more eligible findings, wherein a subject associated with the one or more questions is based on one or more facts that provide evidence to support the one or more eligible findings.

14 . The network computer of claim 8 , further comprising:

suspending the assessment of the one or more events based on a pending interview until the additional information is collected.

15 . A processor readable non-transitory storage media that includes instructions configured for monitoring security environments in a computing environment, wherein execution of the instructions by one or more processors on one or more network computers performs actions, comprising:

using an analytic agent to obtain an assessment based on an investigation of one or more events associated with activity in the computing environment, wherein the assessment is used to generate event data that includes a plurality of findings associated with the investigation of the one or more events;

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; and

using the event data to cause further actions, including:

using a discovery agent to collect one or more users associated with an event based on the event data, wherein the discovery agent generates a discovery prompt to train one or more discovery models to identify one or more of a user or a candidate user to interview about the activity based on one or more event metrics and the event data that is updated to include one or more identifiers associated with the one or more of the user or the candidate user, wherein the event metrics include one or more of a rate, a size, a type, or a scope of the one or more events;

using a subject agent to collect one or more of the plurality of findings that are eligible for an interview based on the event and the updated event data, wherein the collection by the subject agent generates a subject prompt to train one or more subject models to determine eligibility of the one or more findings based on the updated event data;

using the subject agent to retrain the one or more subject models to collect a plurality of questions based on the one or more eligible findings and the updated event data, wherein each question requests additional information associated with the one or more eligible findings, and wherein the analysis agent determines one or more answers for one or more portions of the plurality of questions;

collecting one or more mandatory questions based on one or more characteristics of the event, wherein the one or more characteristics include one or more of an event type, an event priority, an event source, an event target, or a time-of-day, a geographic location, where in the one or more mandatory questions are included in the interview;

using one or more other portions of the plurality of questions that are unanswered by the analysis agent to obtain an interactive interface, wherein the interactive user interface presents the one or more eligible findings and the one or more unanswered questions in a web page with one or more fields to collect one or more responses from the one or more of the user or candidate user that is also related to the one or more eligible findings;

using the one or more responses to iteratively collect one or more new questions that request new information that is related to the one or more eligible findings, wherein the collection of the new information continues until either one or more sources are identified for the one or more events or completion of one or more conditions causes abandonment of the interview;

using a questioner agent to collect the additional information and the new information for the one or more eligible findings based on each response from the one or more of the user or the candidate user to the one or more questions and the one or more new questions that are collected in the interactive user interface;

employing the questioner agent to generate a questioner prompt to train one or more questioner models to perform an interview using the one or more unanswered questions, the one or more new questions and context in the interactive user interface to elicit the additional information and the new information from the one or more of the user or the candidate user, wherein the questioner agent evaluates the one or more responses by the one or more of the user or the candidate user in the interview, wherein questioner agent automatically terminates the interview based on one or more of uncooperativeness, lack of knowledge, or an incorrect response to the one or more new and unanswered questions; and

updating the assessment of the one or more events based on the additional information and the new information; and

using the updated assessment to display a report for one or more security administrators associated with the computing environment.

16 . The media of claim 15 , further comprising:

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; collecting one or more constraints based on one or more of a policy or the event data, wherein the one or more constraints include one or more of a type of user identifier to acknowledge or a user identifier to ignore; and

obtaining the discovery prompt based on the one or more artifacts and the one or more constraints.

17 . The media of claim 15 , further comprising:

using a large language model to generate a natural language summary of the event based on the updated event data;

collecting one or more constraints associated with the one or more questions based on one or more of a policy or the updated event data, wherein the one or more constraints include one or more of a date range, or a subject to ignore; and

including the event summary and the one or more constraints in the subject prompt.

18 . The media of claim 15 , further comprising:

collecting one or more directives based on one or more of a policy or the updated event data, wherein the one or more directives include one or more of a directive to include statements in the interview that convey a conversational tone, a directive to encourage a user to submit evidence or supporting documents, a directive to provide context associated with each question, or a directive to omit follow up questions that exceed a scope of a question; and

including the interview directives in the questioner prompt.

19 . The media of claim 15 , wherein collecting the additional information for the one or more eligible findings, further comprises:

collecting one or more communication methods for performing the interview based on one or more of a policy, a user preference, an event type, or an event priority, wherein the one or more communication methods include one or more of an instant message, an email, a short message service message, a rich communication services message, a dialog box, a web form, or a push notification; and

collecting one or more other communication methods based on a lack of response from the one or more users, wherein the one or more other communication methods are determined based on an escalation policy.

20 . The media of claim 15 , wherein performing the interview with the one or more users, further comprises:

obtaining the one or more questions using one or more natural language interrogative statements based on the one or more eligible findings, wherein a subject associated with the one or more questions is based on one or more facts that provide evidence to support the one or more eligible findings.

21 . A system for monitoring security environments in a computing environment, comprising:

a network computer, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that are configured to cause performance of actions, including:

using an analytic agent to obtain an assessment based on an investigation of one or more events associated with activity in the computing environment, wherein the assessment is used to generate event data that includes a plurality of findings associated with the investigation of the one or more events;

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; and

using the event data to cause further actions, including:

using a discovery agent to collect one or more users associated with an event based on the event data, wherein the discovery agent generates a discovery prompt to train one or more discovery models to identify one or more of a user or a candidate user to interview about the activity based on one or more event metrics and the event data that is updated to include one or more identifiers associated with the one or more of the user or the candidate user, wherein the event metrics include one or more of a rate, a size, a type, or a scope of the one or more events;

using a subject agent to collect one or more of the plurality of findings that are eligible for an interview based on the event and the updated event data, wherein the collection by the subject agent generates a subject prompt to train one or more subject models to determine eligibility of the one or more findings based on the updated event data;

using the subject agent to retrain the one or more subject models to collect a plurality of questions based on the one or more eligible findings and the updated event data, wherein each question requests additional information associated with the one or more eligible findings, and wherein the analysis agent determines one or more answers for one or more portions of the plurality of questions;

collecting one or more mandatory questions based on one or more characteristics of the event, wherein the one or more characteristics include one or more of an event type, an event priority, an event source, an event target, or a time-of-day, a geographic location, wherein the one or more mandatory questions are included in the interview;

using one or more other portions of the plurality of questions that are unanswered by the analysis agent to obtain an interactive interface, wherein the interactive user interface presents the one or more eligible findings and the one or more unanswered questions in a web page with one or more fields to collect one or more responses from the one or more of the user or candidate user that is also related to the one or more eligible findings;

using the one or more responses to iteratively collect one or more new questions that request new information that is related to the one or more eligible findings, wherein the collection of the new information continues until either one or more sources are identified for the one or more events or completion of one or more conditions causes abandonment of the interview;

using a questioner agent to collect the additional information and the new information for the one or more eligible findings based on each response from the one or more of the user or the candidate user to the one or more questions and the one or more new questions that are collected in the interactive user interface;

employing the questioner agent to generate a questioner prompt to train one or more questioner models to perform an interview using the one or more unanswered questions, the one or more new questions and context in the interactive user interface to elicit the additional information and the new information from the one or more of the user or the candidate user, wherein the questioner agent evaluates the one or more responses by the one or more of the user or the candidate user in the interview, wherein questioner agent automatically terminates the interview based on one or more of uncooperativeness, lack of knowledge, or an incorrect response to the one or more new and unanswered questions; and

updating the assessment of the one or more events based on the additional information and the new information; and

using the updated assessment to display a report for one or more security administrators associated with the computing environment; and

a client computer, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that are configured to cause performance of other actions, including:

displaying a presentation of the one or more questions and the one or more new questions in the interactive user interface to the one or more users.

22 . The system of claim 21 , further comprising:

collecting one or more artifacts associated with the event based on information included in the event, wherein the one or more artifacts include one or more of a network address, a hostname, an email address, a username, an application, or a timestamp; collecting one or more constraints based on one or more of a policy or the event data, wherein the one or more constraints include one or more of a type of user identifier to acknowledge or a user identifier to ignore; and

obtaining the discovery prompt based on the one or more artifacts and the one or more constraints.

23 . The system of claim 21 , further comprising:

using a large language model to generate a natural language summary of the event based on the updated event data;

collecting one or more constraints associated with the one or more questions based on one or more of a policy or the updated event data, wherein the one or more constraints include one or more of a date range, or a subject to ignore; and

including the event summary and the one or more constraints in the subject prompt.

24 . The system of claim 21 , further comprising:

collecting one or more directives based on one or more of a policy or the updated event data, wherein the one or more directives include one or more of a directive to include statements in the interview that convey a conversational tone, a directive to encourage a user to submit evidence or supporting documents, a directive to provide context associated with each question, or a directive to omit follow up questions that exceed a scope of a question; and

including the interview directives in the questioner prompt.

25 . The system of claim 21 , wherein collecting the additional information for the one or more eligible findings, further comprises:

collecting one or more communication methods for performing the interview based on one or more of a policy, a user preference, an event type, or an event priority, wherein the one or more communication methods include one or more of an instant message, an email, a short message service message, a rich communication services message, a dialog box, a web form, or a push notification; and

collecting one or more other communication methods based on a lack of response from the one or more users, wherein the one or more other communication methods are determined based on an escalation policy.

26 . The system of claim 21 , wherein performing the interview with the one or more users, further comprises:

obtaining the one or more questions using one or more natural language interrogative statements based on the one or more eligible findings, wherein a subject associated with the one or more questions is based on one or more facts that provide evidence to support the one or more eligible findings.