IP Library Granted Patent US 12,568,114
Granted Patent B2
US 12,568,114 · App. 17/170,591 · Granted Mar 3, 2026

Systems and methods for aida based second chance

Inventors: Alin Irimie (Clearwater, FL); Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL); Eric Sites (Clearwater, FL)
H04L63/1483G06F21/552G06F21/554G06F21/577G06N3/082H04L67/535
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,568,114
App. No.
17/170,591
Granted
Mar 3, 2026
Kind
B2
Abstract

Methods and systems are described in which a system provides a user interface to confirm whether to review or take an action associated with an untrusted email. A driver on a device monitors the startup of any processes. Responsive to monitoring, the driver detects an application process that was created that indicates than an application was launched, and notifies a user console about the creation of the application process. The user console determines if the application process is of significance, if so, it injects a monitor library into the process. Once injected into the process, the monitor library detects if the application process receives an action of a user to access a domain that is not identified as trusted. The monitor library notifies the user console of the user's URL-access request.

Claims (39)

1 . A method comprising:

receiving, by one or more processors, information identifying one or more actions that one or more users reverted back to a point in an application at which the one or more users initiated actions that were determined to be associated with a domain being suspect and intercepted;

storing, by the one or more processors to a database, the information identifying one or more actions that the one or more users reverted back to the point in the application at which the one or more users initiated actions were intercepted;

training, by the one or more processors, a first model using one or more attributes of the one or more users and the information from the database identifying one or more actions that the one or more users reverted back to the point in the application at which the one or more users initiated actions were intercepted as input, the first model configured to identify a template for creating a simulated phishing communication; and

creating, by the one or more processors using the template identified by the first model for a user the simulated phishing communication; and

communicating, by the one or more processors, the simulated phishing communication to a device of the user.

2 . The method of claim 1 , wherein the domain being suspect comprises the domain being identified as untrusted.

3 . The method of claim 1 , wherein the domain being suspect comprises the domain not being identified as trusted.

4 . The method of claim 1 , wherein the one or more users reverted back to the point in the application at which the one or more users initiated actions that were intercepted prior to accessing the domain.

5 . The method of claim 1 , wherein the first model is an artificial intelligence model.

6 . The method of claim 1 , further comprising training, by the one or more processors, the first model using machine learning.

7 . The method of claim 1 , further comprising identifying, by the one or more processors, the template selected from a plurality of templates to use to create the simulated phishing communication.

8 . The method of claim 1 , wherein the information comprises one or more of the following: a type of action, a type of exploit, an identifier of the application and an identifier of the domain.

9 . A system comprising:

a memory;

one or more processors, coupled to the memory and configured to:

receive an input identifying that one or more users reverted back to a point in an application at which the one or more users initiated actions that were determined to be associated with a domain being suspect;

store to a database, the information identifying one or more actions that the one or more users reverted back to the point in the application at which the one or more users initiated actions were intercepted;

train, using one or more attributes of the one or more users and the information from the database identifying one or more actions that the one or more users reverted back to the point in the application at which the one or more users initiated actions were intercepted a, a model configured to identify a template for creating a simulated phishing communication; and

using the template identified by the model for a user to create the simulated phishing communication; and

communicate the simulated phishing communication to a device of the user.

10 . The system of claim 9 , wherein the domain being suspect comprises the domain being identified as untrusted.

11 . The system of claim 9 , wherein the domain being suspect comprises the domain not being identified as trusted.

12 . The system of claim 9 , wherein the input comprises information identifying that one or more users reverted back to the point in the application at which the one or more users initiated actions that were intercepted prior to accessing the domain.

13 . The system of claim 9 , wherein the model is an artificial intelligence model.

14 . The system of claim 9 , wherein the one or more processors are further configured to train the model using machine learning.

15 . The system of claim 9 , wherein the one or more processors are further configured to use the model to select a template from a plurality of templates to use to create the simulated phishing communication.

16 . The system of claim 9 , wherein the information comprises one or more of the following: a type of action, a type of exploit, an identifier of the application and an identifier of the domain.

17 . A system comprising:

a memory;

a database identifying information identifying one or more actions that the one or more users reverted back to a point in an application at which the one or more users initiated actions that were determined to be associated with a domain being suspect and intercepted;

one or more processors, coupled to the memory and configured to:

receive a first model trained with one or more attributes of one or more users and information from the database identifying one or more actions that the one or more users reverted back to a point in an application at which the one or more users initiated actions that were determined to be associated with a domain being suspect and intercepted;

use the first model to identify a template for a user to create a simulated phishing communication for the user;

create the simulated phishing communication using the template; and

communicate the simulated phishing communication to a device of the user.

18 . The system of claim 17 , wherein the domain being suspect comprises the domain being one of identified as untrusted or not identified as trusted.

19 . The system of claim 17 , wherein the one or more processors are further configured to use the template to create content for the simulated phishing communication.

20 . The system of claim 17 , wherein the information comprises one or more of the following: a type of action, a type of exploit, an identifier of the application and an identifier of the domain.

Assignments (6)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS RECORDED AT REEL/FRAME NO.: 056885/0889 Recorded Feb 2, 2023
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: KNOWBE4, INC.
Reel/Frame 062625/0841 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Mar 12, 2021
From: KNOWBE4, INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 056885/0889 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 9, 2021
From: IRIMIE, ALIN; SJOUWERMAN, STU; KRAS, GREG; SITES, ERIC
To: KNOWBE4, INC.
Reel/Frame 055197/0517 →
Continuity (3)
Continuation 17070370 · Oct 14, 2020
Continuation 15829747 · Dec 1, 2017
Related Publication 20210160282A1 · May 27, 2021
References Cited (126)
US 7599992B2 · Nakajima · 2009 [cited by applicant]
US 8041769B2 · Shraim et al. · 2011 [cited by applicant]
US 8464346B2 · Barai et al. · 2013 [cited by applicant]
US 8484741B1 · Chapman · 2013 [cited by examiner]
US 8561188B1 · Wang et al. · 2013 [cited by applicant]
US 8615807B1 · Higbee · 2013 [cited by examiner]
US 8635703B1 · Belani · 2014 [cited by examiner]
US 8719940B1 · Higbee · 2014 [cited by examiner]
US 8793799B2 · Fritzson et al. · 2014 [cited by applicant]
US 8910287B1 · Belani et al. · 2014 [cited by applicant]
US 8966637B2 · Belani et al. · 2015 [cited by applicant]
US 9053326B2 · Higbee · 2015 [cited by examiner]
US 9224117B2 · Chapman · 2015 [cited by examiner]
US 9246936B1 · Belani et al. · 2016 [cited by applicant]
US 9253207B2 · Higbee et al. · 2016 [cited by applicant]
US 9262629B2 · Belani · 2016 [cited by examiner]
US 9325730B2 · Higbee · 2016 [cited by examiner]
US 9356948B2 · Higbee et al. · 2016 [cited by applicant]
US 9373267B2 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 9398029B2 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 9398038B2 · Higbee · 2016 [cited by examiner]
US 9591017B1 · Higbee et al. · 2017 [cited by applicant]
US 9635052B2 · Hadnagy · 2017 [cited by examiner]
US 9667645B1 · Belani et al. · 2017 [cited by applicant]
US 9674221B1 · Higbee et al. · 2017 [cited by applicant]
US 9729573B2 · Gatti · 2017 [cited by applicant]
US 9813454B2 · Sadeh-Koniecpol et al. · 2017 [cited by applicant]
US 9838417B1 · Khalid · 2017 [cited by examiner]
US 9870715B2 · Sadeh-Koniecpol et al. · 2018 [cited by applicant]
US 9876753B1 · Hawthorn · 2018 [cited by applicant]
US 9894092B2 · Irimie et al. · 2018 [cited by applicant]
US 9906539B2 · Higbee et al. · 2018 [cited by applicant]
US 9906554B2 · Higbee et al. · 2018 [cited by applicant]
US 9912687B1 · Wescoe et al. · 2018 [cited by applicant]
US 9942249B2 · Gatti · 2018 [cited by applicant]
US 9998480B1 · Gates et al. · 2018 [cited by applicant]
US 10243904B1 · Wescoe et al. · 2019 [cited by applicant]
US 10581868B2 · Kras · 2020 [cited by examiner]
US 10749887B2 · Hawthorn · 2020 [cited by examiner]
US 10904186B1 · Everton et al. · 2021 [cited by applicant]
US 10986122B2 · Bloxham et al. · 2021 [cited by applicant]
US 11044267B2 · Jakobsson et al. · 2021 [cited by applicant]
US 11184393B1 · Gendre et al. · 2021 [cited by applicant]
US 11297094B2 · Huda · 2022 [cited by applicant]
US 20070142030A1 · Sinha et al. · 2007 [cited by applicant]
US 20070282945A1 · Bisht · 2007 [cited by examiner]
US 20090157827A1 · Bangalore · 2009 [cited by examiner]
US 20100211641A1 · Yih et al. · 2010 [cited by applicant]
US 20100269175A1 · Stolfo et al. · 2010 [cited by applicant]
US 20110283356A1 · Fly · 2011 [cited by examiner]
US 20120124671A1 · Fritzson et al. · 2012 [cited by applicant]
US 20120258437A1 · Sadeh-Koniecpol et al. · 2012 [cited by applicant]
US 20120317467A1 · Cahill · 2012 [cited by examiner]
US 20130198846A1 · Chapman · 2013 [cited by applicant]
US 20130203023A1 · Sadeh-Koniecpol et al. · 2013 [cited by applicant]
US 20130219495A1 · Kulaga et al. · 2013 [cited by applicant]
US 20130297375A1 · Chapman · 2013 [cited by applicant]
US 20140033307A1 · Schmidtler · 2014 [cited by applicant]
US 20140173726A1 · Varenhorst · 2014 [cited by examiner]
US 20140199663A1 · Sadeh-Koniecpol et al. · 2014 [cited by applicant]
US 20140199664A1 · Sadeh-Koniecpol et al. · 2014 [cited by applicant]
US 20140201835A1 · Emigh et al. · 2014 [cited by applicant]
US 20140230061A1 · Higbee et al. · 2014 [cited by applicant]
US 20140230065A1 · Belani et al. · 2014 [cited by applicant]
US 20150163242A1 · Laidlaw et al. · 2015 [cited by applicant]
US 20150180896A1 · Higbee et al. · 2015 [cited by applicant]
US 20150229664A1 · Hawthorn et al. · 2015 [cited by applicant]
US 20160036829A1 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 20160142439A1 · Goutal · 2016 [cited by applicant]
US 20160164898A1 · Belani et al. · 2016 [cited by applicant]
US 20160173510A1 · Harris et al. · 2016 [cited by applicant]
US 20160234245A1 · Chapman · 2016 [cited by applicant]
US 20160261618A1 · Koshelev · 2016 [cited by applicant]
US 20160269402A1 · Carter · 2016 [cited by examiner]
US 20160301705A1 · Higbee · 2016 [cited by examiner]
US 20160301716A1 · Sadeh-Koniecpol et al. · 2016 [cited by applicant]
US 20160308897A1 · Chapman · 2016 [cited by applicant]
US 20160330238A1 · Hadnagy · 2016 [cited by applicant]
US 20170026410A1 · Gatti · 2017 [cited by applicant]
US 20170078310A1 · Hunt · 2017 [cited by examiner]
US 20170078322A1 · Seiver et al. · 2017 [cited by applicant]
US 20170104778A1 · Shabtai et al. · 2017 [cited by applicant]
US 20170140663A1 · Sadeh-Koniecpol et al. · 2017 [cited by applicant]
US 20170237776A1 · Higbee et al. · 2017 [cited by applicant]
US 20170244746A1 · Hawthorn et al. · 2017 [cited by applicant]
US 20170251009A1 · Irimie et al. · 2017 [cited by applicant]
US 20170251010A1 · Irimie et al. · 2017 [cited by applicant]
US 20170318046A1 · Weidman · 2017 [cited by applicant]
US 20170331848A1 · Alsaleh et al. · 2017 [cited by applicant]
US 20180034804A1 · Steiner · 2018 [cited by examiner]
US 20180041537A1 · Bloxham · 2018 [cited by examiner]
US 20180075243A1 · Thomas et al. · 2018 [cited by applicant]
US 20180089014A1 · Smith · 2018 [cited by examiner]
US 20180103052A1 · Choudhury et al. · 2018 [cited by applicant]
US 20180191754A1 · Higbee · 2018 [cited by examiner]
US 20180324201A1 · Lowry · 2018 [cited by examiner]
US 20190073693A1 · Moukaddem · 2019 [cited by examiner]
US 20190173819A1 · Wescoe et al. · 2019 [cited by applicant]
US 20190215335A1 · Benishti · 2019 [cited by applicant]
US 20190245885A1 · Starink et al. · 2019 [cited by applicant]
US 20190245894A1 · Epple et al. · 2019 [cited by applicant]
US 20200250303A1 · Lowry · 2020 [cited by examiner]
US 20200311260A1 · Klonowski et al. · 2020 [cited by applicant]
US 20210021612A1 · Higbee · 2021 [cited by examiner]
US 20210185075A1 · Adams · 2021 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20220078207A1 · Chang et al. · 2022 [cited by applicant]
US 20220094702A1 · Saad Ahmed et al. · 2022 [cited by applicant]
US 20220100332A1 · Haworth et al. · 2022 [cited by applicant]
US 20220116419A1 · Kelm et al. · 2022 [cited by applicant]
US 20220130274A1 · Krishna Raju et al. · 2022 [cited by applicant]
US 20220286419A1 · Stetzer et al. · 2022 [cited by applicant]
EP 3582468A1 · 2019 [cited by applicant]
WO WO2016164844A1 · 2016 [cited by applicant]
Abu-Nimeh et al., “A Comparison of Machine Learning Techniques for Phishing Detection,” eCrime '07: Proceedings of the anti-phishing working groups 2nd annual eCrime researchers summit, 2007, pp. 60-69, ACM Digital Libr… [cited by applicant]
Final Office Action on U.S. Appl. No. 15/829,747 dated Apr. 20, 2020. [cited by applicant]
Final Office Action on U.S. Appl. No. 15/829,747 dated Jun. 18, 2019. [cited by applicant]
Final Office Action on U.S. Appl. No. 15/829,747 dated Sep. 21, 2018. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 15/829,747 dated Feb. 7, 2019. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 15/829,747 dated Dec. 5, 2019. [cited by applicant]
Non-Final Office Action on U.S. Appl. No. 17/070,370 dated Nov. 17, 2020. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 15/829,747 dated Sep. 10, 2020. [cited by applicant]
Notice of Allowance on U.S. Appl. No. 17/070,370 dated Dec. 17, 2020. [cited by applicant]
Palka et al., “Dynamic phishing content using generative grammars,” Software Testing, Verification and Validation Workshops (ICSTW), 2015 IEEE Eighth International Conference, Date of Conference: Apr. 13-17, 2015, IEEE … [cited by applicant]
US Office Action on U.S. Appl. No. 15/829,747 dated Apr. 27, 2018. [cited by applicant]
US Office Action on U.S. Appl. No. 15/829,747 dated Sep. 21, 2018. [cited by applicant]