IP Library Granted Patent US 12,519,806
Granted Patent B2
US 12,519,806 · App. 17/729,938 · Granted Jan 6, 2026

Systems and methods for determination of indicators of malicious elements within messages

Inventors: Stu Sjouwerman (Bellair, FL); Greg Kras (Dunedin, FL)
Assignee: Knowbe4, Inc.
H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,519,806
App. No.
17/729,938
Granted
Jan 6, 2026
Kind
B2
Abstract

Systems and methods are described for determination of indicators of malicious elements within messages. A report of a malicious message is received from a user of an organization, the malicious message having traversed an endpoint security system of the organization. After receiving the report of the malicious message, one or more indicators of one or more malicious elements of the malicious message are identified. Further, an identification of the endpoint security system and a dangerousness score of the malicious message are determined. The one or more indicators, the identification of the endpoint security system, and the dangerousness score are stored into a threat database that is able to be queried to generate an endpoint-specific threat data set.

Claims (31)

1 . A method comprising

receiving, by a determination unit of a threat detection platform executing on one or more servers, from a user of an organization, a report of a malicious message, the malicious message having traversed and evaded an endpoint security system of the organization, the determination unit configured to analyze messages reported by user to detect any cybersecurity attacks from phishing attacks via malicious messages;

identifying, by the threat detection platform executing on the one or more servers, from a threat database one or more indicators of one or more malicious elements of the malicious message;

identifying, by the threat detection platform executing on the one or more servers, an identification of the endpoint security system from one or more headers of the malicious message;

generating, by a dangerousness score calculator executing on the one or more servers, a dangerousness score of the malicious message, the dangerousness score calculator configured to determine the dangerousness score based at least on a number and severity of the one or more malicious elements that evaded the endpoint security system; and

storing, by the threat detection platform executing on the one or more servers, the one or more indicators that have evaded the endpoint security system, the identification of the endpoint security system, and the dangerousness score into the threat database that is configured to generate an endpoint-specific threat data set responsive to a query.

2 . The method of claim 1 , further comprising classifying, by the determination unit of the threat detection platform executing on the one or more servers, the malicious message as a threat and the classification having a level of confidence.

3 . The method of claim 2 , further comprising storing, by the one or more servers, the level of confidence with the one or more indicators, the identification of the endpoint security system, and the dangerousness score into the threat database.

4 . The method of claim 1 , further comprising determining, by the one or more servers, the identification of the endpoint security system from one or more headers of the malicious message.

5 . The method of claim 1 , further comprising determining, by the one or more servers, the identification of the endpoint security system from input received from a system administrator.

6 . The method of claim 1 , further comprising receiving, by the threat database, a query for indicators that evaded the endpoint security system and providing, by the threat database, the indicators in a format used by the endpoint security system.

7 . The method of claim 1 , further comprising receiving, by the threat database, a query for indicators with a minimum level of the dangerousness score for the endpoint security system and providing, by the threat database, the indicators meeting the minimum level of the dangerousness score for the endpoint security system.

8 . The method of claim 1 , further comprising generating from the threat database responsive to one or more queries a circulated threat data set comprising a sub-set of the threat database.

9 . The method of claim 8 , further comprising generating the circulated threat data set into the endpoint-specific threat data set having a format used by the endpoint security system.

10 . The method of claim 1 , wherein the endpoint-specific threat data set is used by one or more of the endpoint security systems to protect against malicious messages having the one or more indicators.

11 . A system comprising

a threat detection platform configured on one or more servers having one or more processors, coupled to memory and configured to analyze messages reported by user to detect any cybersecurity attacks from phishing attacks via malicious messages;

a determination unit of the threat detection platform configured to receive from a user of an organization, a report of a malicious message, the malicious message having traversed and evaded an endpoint security system of the organization;

wherein the threat detection platform is configured to identify, from a threat database, one or more indicators of one or more malicious elements of the malicious message; and

identify an identification of the endpoint security system from one or more headers of the malicious message;

a dangerousness score calculator configured to generate a dangerousness score of the malicious message based at least on a number and severity of the one or more malicious elements that evaded the endpoint security system; and

wherein the threat detection platform is configured to store one or more indicators that have evaded the endpoint security system, the identification of the endpoint security system and the dangerousness score into the threat database that is configured to generate an endpoint-specific threat data set responsive to a query.

12 . The system of claim 11 , wherein the determination unit of the threat detection platform configured on the one or more servers is further configured to classify the malicious message as a threat and the classification having a level of confidence.

13 . The system of claim 12 , wherein the one or more servers are further configured to store the level of confidence with the one or more indicators, the identification of the endpoint security system and the dangerousness score into the threat database.

14 . The system of claim 11 , wherein the one or more servers are further configured to determine the identification of the endpoint security system from one or more headers of the malicious message.

15 . The system of claim 11 , wherein the one or more servers are further configured to determine the identification of the endpoint security system from input received from a system administrator.

16 . The system of claim 11 , wherein the threat database is further configured to receive a query for indicators that evaded the endpoint security system and provide the indicators in a format used by the endpoint security system.

17 . The system of claim 11 , wherein the threat database is further configured to receive, a query for indicators with a minimum level of the dangerousness score for the endpoint security system and provide the indicators meeting the minimum level of the dangerousness score for the endpoint security system.

18 . The system of claim 11 , wherein the threat database is further configured to generate, responsive to one or more queries, a circulated threat data set comprising a sub-set of the threat database.

19 . The system of claim 18 , wherein the circulated threat data set is generated into the endpoint-specific threat data set having a format used by the endpoint security system.

20 . The system of claim 11 , wherein the endpoint-specific threat data set is used by one or more of the endpoint security systems to protect against malicious messages having the one or more indicators.

Assignments (5)
PATENT SECURITY AGREEMENT Recorded Aug 8, 2025
From: KNOWBE4, INC.
To: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
Reel/Frame 072337/0277 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL RECORDED AT REEL/FRAME: 062627/0001 Recorded Jul 28, 2025
From: BLUE OWL CREDIT INCOME CORP. (FORMERLY KNOWN AS OWL ROCK CORE INCOME CORP.)
To: KNOWBE4, INC.
Reel/Frame 072108/0205 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: SJOUWERMAN, STU; KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 062801/0035 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 24, 2023
From: SJOUWERMAN, STU; KRAS, GREG
To: KNOWBE4, INC.
Reel/Frame 062802/0017 →
PATENT SECURITY AGREEMENT Recorded Feb 2, 2023
From: KNOWBE4, INC.
To: OWL ROCK CORE INCOME CORP., AS COLLATERAL AGENT
Reel/Frame 062627/0001 →
Continuity (2)
Provisional Application 63181573 · Apr 29, 2021
Related Publication 20220353279A1 · Nov 3, 2022
References Cited (119)
US 6088804A · Hill · 2000 [cited by examiner]
US 6119236A · Shipley · 2000 [cited by examiner]
US 6321338B1 · Porras · 2001 [cited by examiner]
US 7594270B2 · Church · 2009 [cited by examiner]
US 7949716B2 · Alperovitch · 2011 [cited by examiner]
US 8578480B2 · Judge · 2013 [cited by examiner]
US 8615807B1 · Higbee et al. · 2013 [cited by applicant]
US 8635703B1 · Belani et al. · 2014 [cited by applicant]
US 8719940B1 · Higbee et al. · 2014 [cited by applicant]
US 8813236B1 · Saha · 2014 [cited by examiner]
US 8910287B1 · Belani et al. · 2014 [cited by applicant]
US 8966637B2 · Belani et al. · 2015 [cited by applicant]
US 9047441B2 · Xie · 2015 [cited by examiner]
US 9053326B2 · Higbee et al. · 2015 [cited by applicant]
US 9060024B2 · Patel · 2015 [cited by examiner]
US 9246936B1 · Belani et al. · 2016 [cited by applicant]
US 9253207B2 · Higbee et al. · 2016 [cited by applicant]
US 9262629B2 · Belani et al. · 2016 [cited by applicant]
US 9325730B2 · Higbee et al. · 2016 [cited by applicant]
US 9356948B2 · Higbee et al. · 2016 [cited by applicant]
US 9363280B1 · Rivlin · 2016 [cited by examiner]
US 9392003B2 · Amsler · 2016 [cited by examiner]
US 9398038B2 · Higbee et al. · 2016 [cited by applicant]
US 9571512B2 · Ray · 2017 [cited by examiner]
US 9591017B1 · Higbee et al. · 2017 [cited by applicant]
US 9596266B1 · Coleman · 2017 [cited by examiner]
US 9609011B2 · Muddu · 2017 [cited by examiner]
US 9641550B2 · Kraitsman · 2017 [cited by examiner]
US 9661017B2 · Alperovitch · 2017 [cited by examiner]
US 9667645B1 · Belani et al. · 2017 [cited by applicant]
US 9774626B1 · Himler · 2017 [cited by examiner]
US 9912687B1 · Wescoe et al. · 2018 [cited by applicant]
US 9967264B2 · Harris · 2018 [cited by examiner]
US 10122748B1 · Currie · 2018 [cited by examiner]
US 10129270B2 · Doctor · 2018 [cited by examiner]
US 10158677B1 · DiCorpo · 2018 [cited by examiner]
US 10185465B1 · Capano · 2019 [cited by examiner]
US 10218697B2 · Cockerill · 2019 [cited by examiner]
US 10341377B1 · Dell'Amico · 2019 [cited by examiner]
US 10419458B2 · Moscovici · 2019 [cited by examiner]
US 10511621B1 · Thomson · 2019 [cited by examiner]
US 10721252B2 · Murphy · 2020 [cited by examiner]
US 10904186B1 · Everton et al. · 2021 [cited by applicant]
US 10924503B1 · Pereira · 2021 [cited by examiner]
US 10986122B2 · Bloxham et al. · 2021 [cited by applicant]
US 11044267B2 · Jakobsson et al. · 2021 [cited by applicant]
US 11184393B1 · Gendre et al. · 2021 [cited by applicant]
US 11252168B2 · Mehta · 2022 [cited by examiner]
US 11297094B2 · Huda · 2022 [cited by applicant]
US 11528295B2 · Meriot · 2022 [cited by examiner]
US 11595437B1 · Mushtaq · 2023 [cited by examiner]
US 11677786B1 · Vashisht · 2023 [cited by examiner]
US 11711381B2 · Muthuswamy · 2023 [cited by examiner]
US 11856009B2 · Mishra · 2023 [cited by examiner]
US 11915178B2 · Carpenter · 2024 [cited by examiner]
US 11936688B2 · Irimie · 2024 [cited by examiner]
US 11997115B1 · Higbee · 2024 [cited by examiner]
US 20020087882A1 · Schneier · 2002 [cited by examiner]
US 20090089859A1 · Cook · 2009 [cited by examiner]
US 20090276843A1 · Patel · 2009 [cited by examiner]
US 20110061089A1 · O'Sullivan · 2011 [cited by examiner]
US 20110138471A1 · Van De Weyer · 2011 [cited by examiner]
US 20120060207A1 · Mardikar · 2012 [cited by examiner]
US 20120066759A1 · Chen · 2012 [cited by examiner]
US 20130333028A1 · Hagar · 2013 [cited by examiner]
US 20140007238A1 · Magee · 2014 [cited by examiner]
US 20140380456A1 · Demopoulos · 2014 [cited by examiner]
US 20150261951A1 · Abuelsaad · 2015 [cited by examiner]
US 20160006749A1 · Cohen · 2016 [cited by examiner]
US 20160164898A1 · Belani et al. · 2016 [cited by applicant]
US 20160164917A1 · Friedrichs · 2016 [cited by examiner]
US 20160301705A1 · Higbee · 2016 [cited by examiner]
US 20160337384A1 · Jansson · 2016 [cited by examiner]
US 20160344758A1 · Cohen · 2016 [cited by examiner]
US 20160350531A1 · Harris · 2016 [cited by examiner]
US 20170171231A1 · Reybok, Jr. · 2017 [cited by examiner]
US 20170180396A1 · Finnig · 2017 [cited by examiner]
US 20170289179A1 · Dubuc · 2017 [cited by examiner]
US 20170353484A1 · Knapp · 2017 [cited by examiner]
US 20180004942A1 · Martin · 2018 [cited by examiner]
US 20180046799A1 · Kohavi · 2018 [cited by examiner]
US 20180124090A1 · Koren · 2018 [cited by examiner]
US 20180124098A1 · Carver · 2018 [cited by examiner]
US 20180191754A1 · Higbee · 2018 [cited by examiner]
US 20190068632A1 · Foster · 2019 [cited by examiner]
US 20190173819A1 · Wescoe et al. · 2019 [cited by applicant]
US 20190245885A1 · Starink et al. · 2019 [cited by applicant]
US 20200074078A1 · Saxe · 2020 [cited by examiner]
US 20200311260A1 · Klonowski et al. · 2020 [cited by applicant]
US 20200366712A1 · Onut · 2020 [cited by examiner]
US 20210051162A1 · Taylor · 2021 [cited by examiner]
US 20210058428A1 · Arlitt · 2021 [cited by examiner]
US 20210075827A1 · Grealish · 2021 [cited by applicant]
US 20210136089A1 · Costea · 2021 [cited by examiner]
US 20210168161A1 · Dunn · 2021 [cited by examiner]
US 20210185075A1 · Adams · 2021 [cited by applicant]
US 20210194924A1 · Heinemeyer et al. · 2021 [cited by applicant]
US 20210200870A1 · Yavo · 2021 [cited by examiner]
US 20210243204A1 · Taylor · 2021 [cited by examiner]
US 20210250369A1 · Åvist · 2021 [cited by examiner]
US 20210407308A1 · Brubaker et al. · 2021 [cited by applicant]
US 20220005373A1 · Nelson et al. · 2022 [cited by applicant]
US 20220006830A1 · Wescoe · 2022 [cited by applicant]
US 20220078207A1 · Chang et al. · 2022 [cited by applicant]
US 20220094702A1 · Saad Ahmed et al. · 2022 [cited by applicant]
US 20220100332A1 · Haworth · 2022 [cited by examiner]
US 20220109681A1 · Hamdi · 2022 [cited by examiner]
US 20220116419A1 · Kelm et al. · 2022 [cited by applicant]
US 20220130274A1 · Krishna Raju et al. · 2022 [cited by applicant]
US 20220207140A1 · Mooney, III · 2022 [cited by examiner]
US 20220210168A1 · Yavo · 2022 [cited by examiner]
US 20220210190A1 · Weber · 2022 [cited by examiner]
US 20220255961A1 · Reiser · 2022 [cited by examiner]
US 20220286419A1 · Stetzer et al. · 2022 [cited by applicant]
US 20240089273A1 · Aslaner · 2024 [cited by examiner]
US 20250030716A1 · Cross · 2025 [cited by examiner]
US 20250036756A1 · Cotiga · 2025 [cited by examiner]
EP 3582468A1 · 2019 [cited by applicant]
WO WO2016164844A1 · 2016 [cited by applicant]