IP Library Granted Patent US 11,720,669
Granted Patent B1
US 11,720,669 · App. 17/348,671 · Granted Aug 8, 2023

Interactive shell event detection

Inventor: Brandon M. Edwards (Brooklyn, NY)
Assignee: Capsule8, Inc.
G06F21/554G06F11/3636
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,720,669
App. No.
17/348,671
Granted
Aug 8, 2023
Kind
B1
Abstract

Telemetry associated with an Exec( ) Event denoting that a program has been invoked via a process is received. A determination is made that the process is a shell. Subsequent to determining that the invoked program is a shell, additional information comprising information that the program has attempted to obtain terminal information is received. Based at least in part on the received additional information, a determination is made that the program is an interactive shell. An action is taken in response to the determination that the program is an interactive shell.

Claims (40)

1. A system, comprising:

a first processor; and

a memory coupled to the first processor, the memory storing instructions that configure the first processor to:

receive telemetry denoting that a program has been invoked on a node via a process;

determine that the invoked program is a shell based at least on a program path and name information associated with the process;

subsequent to determining that the invoked program is a shell, receive additional information including timing information associated with commands entered into the shell;

based at least in part on the received additional information, determine that the program is an interactive shell interactively operated by a user;

in response to determining that the program is an interactive shell, configure the node to tag one or more commands entered into the interactive shell for storage and query with a tag identifying the one or more commands as interactive shell commands associated with the program; and

manage a security policy for the node based on the tagged interactive shell commands.

2. The system of claim 1 wherein the first processor is further configured to insert data associated with the process into a process tree.

3. The system of claim 2 wherein the data includes the current state of the program executing.

4. The system of claim 1 wherein determining that the program is a shell includes determining if the program is descendent of another program.

5. The system of claim 4 wherein determining that the program is a shell includes matching a program path against a list of known shell programs.

6. The system of claim 1 wherein, in response to determining that that program is a shell, a shell tag is associated with the process in a process tree.

7. The system of claim 1 wherein the additional information comprises a system input/output control event.

8. The system of claim 1 wherein the additional information is obtained using a programmatic filter that collects process data.

9. The system of claim 1 wherein the additional information is obtained through kernel subsystem data collection.

10. The system of claim 1 wherein the additional information comprises a keystroke timing of a command.

11. The system of claim 1 wherein the first processor is further configured to propagate a tag associated with the process on at least one of an invocation of the process or an invocation of a child process.

12. The system of claim 1 wherein the first processor is configured to generate an alert in response to determining that the program is an interactive shell.

13. The system of claim 1 wherein the first processor is further configured to determine a command being executed in the interactive shell.

14. The system of claim 1 further comprising a second processor configured by computer executable code to display the interactive shell commands for the node in real time based on the one or more tags.

15. The system of claim 1 further comprising a second processor configured by computer executable code to query the interactive shell commands based on the one or more tags.

16. The system of claim 1 wherein the memory stores instructions that configure the first processor to analyze keystroke timing of commands entered into the interactive shell.

17. The system of claim 1 wherein the memory stores instructions that configure the first processor to tag the interactive shell with a tag that stores state information related to the interactive shell.

18. The system of claim 17 , wherein the tag includes propagation logic permitting subsequent interactive shells descending from the interactive shell based on one or more predetermined process events.

19. A method, comprising:

receiving telemetry denoting that a program has been invoked on a node via a process;

determining that the invoked program is a shell based at least on a program path and name information associated with the process;

subsequent to determining that the invoked program is a shell, receiving additional information including timing information associated with commands entered into the shell;

based at least in part on the received additional information, determining that the program is an interactive shell interactively operated by a user;

in response to determining that the program is an interactive shell, configuring the node to tag one or more commands entered into the interactive shell for storage and query with a tag identifying the one or more commands as interactive shell commands associated with the program; and

managing a security policy for the node based on the tagged interactive shell commands.

20. A computer program product embodied in a non-transitory computer readable storage medium and comprising computer instructions executable on one or more computing devices to perform the steps of for:

receiving telemetry denoting that a program has been invoked on a node via a process;

determining that the invoked program is a shell based at least on a program path and name information associated with the process;

subsequent to determining that the invoked program is a shell, receiving additional information including timing information associated with commands entered into the shell;

based at least in part on the received additional information, determining that the program is an interactive shell interactively operated by a user;

in response to determining that the program is an interactive shell, configuring the node to tag one or more commands entered into the interactive shell for storage and query with a tag identifying the one or more commands as interactive shell commands associated with the program; and

managing a security policy for the node based on the tagged interactive shell commands.

Assignments (4)
MERGER Recorded Nov 19, 2025
From: CAPSULE8, LLC
To: SOPHOS INC.
Reel/Frame 072966/0801 →
CHANGE OF NAME Recorded Nov 19, 2025
From: CAPSULE8, INC.
To: CAPSULE8, LLC
Reel/Frame 073333/0484 →
SECURITY INTEREST Recorded Oct 29, 2021
From: CAPSULE8, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 057966/0648 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 30, 2021
From: EDWARDS, BRANDON M.
To: CAPSULE8, INC.
Reel/Frame 057325/0974 →
Continuity (3)
Continuation 16698920 · Nov 27, 2019
Provisional Application 62773892 · Nov 30, 2018
Provisional Application 62825737 · Mar 28, 2019
Cited By (2)
US 12,189,774 US 12,284,195