IP Library Granted Patent US 12705349
Granted Patent B1
US 12705349 · App. 19/538,072 · Granted Aug 11, 2026

System and method for source trust-based detection of cybersecurity issues in a computing environment

Inventors: Liran Moysi (Kfar Saba, IL); Gilad Maymon (Tel Aviv, IL); Daniel Velikanski (Tel Aviv, IL); Pavel Resnianski (Tel Aviv, IL); Ofir Cohen (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/554G06F21/562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705349
App. No.
19/538,072
Granted
Aug 11, 2026
Kind
B1
Abstract

A system or method for trust-aware cybersecurity detection is presented. The method includes receiving from a computing environment a plurality of cybersecurity signals; detecting in a first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue; determining a trust score of the resource based at least on the identifier; selecting a response action based on the cybersecurity issue; adapting the response action based on the trust score; and initiating the adapted response action in the computing environment.

Claims (64)

1 . A method for trust-aware cybersecurity detection, comprising:

generating a representation of a computing environment including a plurality of entities;

determining a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;

detecting a disk of the resource;

generating an inspectable disk based on the detected disk;

statically analyzing the inspectable disk for a cybersecurity object associated with the resource;

receiving from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;

detecting in the first cybersecurity signal of the plurality of cybersecurity signals, a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;

selecting a response action based on the cybersecurity issue;

adapting the response action to the cybersecurity issue based on the determined trust score; and

initiating the adapted response action in the computing environment.

2 . The method of claim 1 , further comprising:

detecting a code repository in the computing environment, the code repository including a plurality of code objects; and

generating the static analysis result based on statically analyzing a code object of the plurality of code object.

3 . The method of claim 1 , further comprising:

detecting a software image repository in the computing environment, the software image repository including a plurality of software images; and

generating the static analysis result based on statically analyzing a software image of the plurality of software images.

4 . The method of claim 1 , further comprising:

detecting in the computing environment an event log, the event log including a plurality of event records;

extracting the plurality of event records from the event log; and

receiving a second cybersecurity signal of the plurality of cybersecurity signals based on the extracted plurality of event records.

5 . The method of claim 1 , further comprising:

selecting the response action from a plurality of response actions, each response action corresponding to the cybersecurity issue.

6 . The method of claim 5 , further comprising:

selecting the response action further based on the trust score.

7 . A non-transitory computer-readable medium storing a set of instructions for trust-aware cybersecurity detection, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

generate a representation of a computing environment including a plurality of entities;

determine a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;

detect a disk of the resource;

generate an inspectable disk based on the detected disk;

statically analyze the inspectable disk for a cybersecurity object associated with the resource;

receive from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;

detect in the first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;

select a response action based on the cybersecurity issue;

adapt the response action to the cybersecurity issue based on the determined trust score; and

initiate the adapted response action in the computing environment.

8 . A system for trust-aware cybersecurity detection comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

generate a representation of a computing environment including a plurality of entities;

determine a trust score for each entity of the plurality of entities, wherein a first entity of the plurality of entities is a resource deployed in the computing environment;

detect a disk of the resource;

generate an inspectable disk based on the detected disk;

statically analyze the inspectable disk for a cybersecurity object associated with the resource;

receive from a computing environment a plurality of cybersecurity signals, including: a first cybersecurity signal based on runtime detections from a sensor deployed on a resource in the computing environment, and a second cybersecurity signal based on the static analysis result;

detect in the first cybersecurity signal of the plurality of cybersecurity signals a cybersecurity issue and an identifier of a resource associated with the cybersecurity issue;

select a response action based on the cybersecurity issue;

adapt the response action to the cybersecurity issue based on the determined trust score; and

initiate the adapted response action in the computing environment.

9 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a code repository in the computing environment, the code repository including a plurality of code objects; and

generate the static analysis result based on statically analyzing a code object of the plurality of code object.

10 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a software image repository in the computing environment, the software image repository including a plurality of software images; and

generate the static analysis result based on statically analyzing a software image of the plurality of software images.

11 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect in the computing environment an event log, the event log including a plurality of event records;

extract the plurality of event records from the event log; and

receive a second cybersecurity signal of the plurality of cybersecurity signals based on the extracted plurality of event records.

12 . The system of claim 8 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

select the response action from a plurality of response actions, each response action corresponding to the cybersecurity issue.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

select the response action further based on the trust score.