IP Library Granted Patent US 12,563,087
Granted Patent B2
US 12,563,087 · App. 17/966,720 · Granted Feb 24, 2026

Endpoint agent and system

Inventors: Thomas Jenkinson (Ashford, GB); David Sansom (Cambridge, GB); Maximilian Heinemeyer (Lower Saxony, DE); Jack Stockdale (Cambridge, GB)
Assignee: Darktrace Holdings Limited
H04L63/1441G06F18/232G06F21/554G06F21/556H04L43/045H04L63/14H04L63/1416H04L63/1425H04L63/1433H04L51/224H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,087
App. No.
17/966,720
Granted
Feb 24, 2026
Kind
B2
Abstract

The endpoint agent detects a cyber threat on an end-point computing device. The endpoint agent on the computing device has a communications module that communicates with a cyber defense appliance. A collections module monitors and collects pattern of life data on processes executing on the end-point computing-device and users of the end-point computing-device. The communications module sends the pattern of life data to the cyber defense appliance installed on a network. The cyber defense appliance at least contains one or more machine-learning models to analyze the pattern of life data for each endpoint agent connected to that cyber defense appliance. The endpoint agent and the cyber defense appliance may trigger one or more actions to be autonomously taken to contain a detected cyber threat when a cyber-threat risk score is indicative of a likelihood of a cyber-threat is equal to or above an actionable threshold.

Claims (54)

1 . An endpoint agent configured to enable detection of a cyber threat on an end-point computing-device, comprising:

a communications module configured to communicate with a cyber security appliance,

a collections module configured to monitor and collect a pattern of life data of software processes executing on the end-point computing-device and one or more users of the end-point computing-device, and

an autonomous response module;

wherein the endpoint agent is configured to be resident on the end-point computing-device,

wherein the communications module and the collections module cooperate to send the pattern of life data, via the communications module, to the cyber security appliance;

wherein the cyber security appliance is configured to contain at least one or more machine-learning models to analyze the pattern of life data for two or more computing devices, where the end-point agent is configured to securely communicate with the cyber security appliance;

wherein instructions implemented in software of the communications module, the collections module, and the autonomous response module are configured to be stored in an executable format in one or more memories and to be executed by one or more processors of the end-point computing-device,

wherein the communications and collections modules in the endpoint agent and one or more memories and one or more processors in the end-point computing-device are part of the endpoint agent, and

wherein the communications and collections modules are configured to cooperate with the machine-learning models in the cyber security appliance to collect a data indicative of a pattern of life for that end-point computing-device so that the machine-learning models can model the pattern of life to enable a detection of the cyber threat on that end-point computing-device, where an unsupervised first machine-learning model is configured to continuously model the pattern of life data for the endpoint device; and

wherein when the endpoint agent is not connected to a network where the cyber security appliance is installed or when the cyber security appliance is unavailable, the communications module is configured to send collected pattern of life data to one or more memories of the end-point computing-device, and the autonomous response module is configured to autonomously cause one or more actions to be taken to contain a detected cyber threat.

2 . The endpoint agent of claim 1 , further comprising a cyber threat module that references one or more machine-learning models trained on potential cyber threats to analyze for potential cyber threats on the end-point computing-device based on the collected pattern of life data that deviates from a normal pattern of life for that end-point computing-device.

3 . The endpoint agent of claim 1 , wherein the communications module is further configured to send the collected pattern of life data to the cyber security appliance, and the cyber security appliance is configured to initially match a type of computing-device and operating system belonging to the end-point computing-device to apply and route the collected pattern of life data to a corresponding set of the one or more machine-learning models trained on that end-point computing-device.

4 . The endpoint agent of claim 1 , wherein the cyber security appliance is further configured with a second autonomous response module to cause one or more actions by the endpoint agent to contain the cyber threat when the cyber threat is detected, wherein the autonomous response module has a user programmable interface with any of i) fields, ii) menus, and iii) icons to allow a user to preauthorize the autonomous response module to take actions to contain the cyber threat, and wherein the autonomous response module is configured to cooperate with the communications module in the endpoint agent to cause the one or more actions to contain the detected cyber threat when a cyber-threat risk score, indicative of a likelihood of the cyber threat, is equal to or above an actionable threshold.

5 . The endpoint agent of claim 1 , wherein the collections module is configured to cooperate with at least one or more probes that include: i) a first probe configured to collect data about an operating system of the end-point computing-device as well as ii) a second probe configured to collect data about an individual process executing on the end-point computing-device, and iii) a third probe configured to monitor and record events occurring on the end-point computing-device and collaborate with system event logging tools, wherein the collected data regarding the operating system and individual processes along with the recorded events are sent in the collected pattern of life data by the collections module to the cyber security appliance.

6 . The endpoint agent of claim 1 , wherein the cyber security appliance is configured to receive collected pattern of life data from two or more endpoint agents, including the endpoint agent, each of the two or more endpoint agents is configured to be resident on their own end-point computing-device in the network, wherein the cyber security appliance has a graphical user interface to display the endpoint agents and their end-point computing-device connecting to that cyber security appliance, wherein the graphical user interface is configured to visually highlight end-point computing-devices with anomalies occurring compared to a normal pattern of life for that end-point computing-device.

7 . The endpoint agent of claim 1 , wherein the pattern of life data includes at least one of metadata, events, and alerts regarding at least i) the users, ii) the software processes, iii) relationships between the software processes, iv) device operation, v) operating system configuration changes, and vi) combinations of these, and the pattern of life data is sent by the communications module to the cyber security appliance installed in the network.

8 . An endpoint agent configured to enable detection of a cyber threat on an end-point computing-device, comprising:

a communications module configured to communicate with a cyber security appliance,

a collections module configured to monitor and collect a pattern of life data of software processes executing on the end-point computing-device and one or more users of the end-point computing-device,

wherein the endpoint agent is configured to be resident on the end-point computing-device,

wherein the communications module and the collections module cooperate to send the pattern of life data, via the communications module, to the cyber security appliance;

where the cyber security appliance is configured to contain at least one or more machine-learning models to analyze the pattern of life data for two or more computing-devices, where the end-point agent is configured to securely communicate with the cyber security appliance,

wherein instructions implemented in software of the communications module, the collections module, and an autonomous response module are configured to be stored in an executable format in one or more memories and to be executed by one or more processors of the end-point computing-device,

wherein the communications and collections modules in the endpoint agent and the one or more memories and one or more processors in the end-point computing-device are part of the endpoint agent,

wherein the communications module is further configured to send collected pattern of life data to the cyber security appliance at periodic intervals when the endpoint agent is connected to a network where the cyber security appliance is installed,

wherein the communications module is further configured to send collected pattern of life data to the one or more memories of the end-point computing-device i) when not connected to the network where the cyber security appliance is installed as well as ii) when the cyber security appliance is unavailable; wherein in either situation, the collected pattern of life data is stored in the memories when possible; and

where the autonomous response module is configured to cause one or more actions to contain the cyber threat when detected and when i) the endpoint agent is not connected to the network where the cyber security appliance is installed, when ii) the cyber security appliance is unavailable to communicate with the endpoint agent, and any combination of i) and ii),

wherein the autonomous response module is located in the endpoint agent and uses a decision engine to take one or more actions preapproved by a user to autonomously attempt to contain a potential cyber threat when predefined conditions of suspicious behavior and/or anomaly level are met, and

wherein the autonomous response module is configured to cooperate with the communications module in the endpoint agent to detect when i) the endpoint agent is not connected to the network where the cyber security appliance is installed, when ii) the cyber security appliance is unavailable to communicate with the endpoint agent, and any combination of i) and ii).

9 . The endpoint agent of claim 8 , wherein the pattern of life data includes at least one of metadata, events, and alerts regarding at least i) the users, ii) the software processes, iii) relationships between the software processes, iv) device operation, v) operating system configuration changes, and vi) combinations of these, and the pattern of life data is sent by the communications module to the cyber security appliance installed in the network.

10 . A method for an endpoint agent configured to enable a detection of a cyber threat on an end-point computing-device, comprising:

configuring the endpoint agent to be resident on the end-point computing-device to communicate with a cyber security appliance;

configuring the endpoint agent to monitor and collect pattern of life data of software processes executing on the end-point computing-device and one or more users of the end-point computing-device;

configuring the endpoint agent to send the pattern of life data via a communications module to the cyber security appliance, configuring the endpoint agent to be installed on the end-point computing-device,

configuring the cyber security appliance to contain at least one or more machine-learning models to analyze the pattern of life data for two or more endpoint computing-devices securely communicating to the cyber security appliance;

configuring the communications and collections modules in the endpoint agent to cooperate with the machine-learning models in cyber security appliance to collect a data indicative of a pattern of life for that end-point computing-device so that the machine-learning models can model the pattern of life to enable a detection of the cyber threat on that end-point computing-device; and

configuring communication with existing third-party endpoint security processes on the endpoint computing-device by having a unifying translator to understand and exchange communications with the third-party endpoint security processes on the end-point computing-device, where the unifying translator is configured to map conveyed information from a plurality of different known third-party endpoint security processes with an application programming interface.

11 . The method for an endpoint agent of claim 10 , wherein the pattern of life data includes at least one of metadata, events, and alerts regarding at least i) one or more users of the end-point computing-device, ii) multiple software processes operating on the end-point computing-device, iii) relationships between the software processes, iv) device operation, v) operating system configuration changes, and vi) combinations of these, and then the collected the pattern of life data is sent to the cyber security appliance, wherein the cyber security appliance uses the one or more machine-learning models trained on the end-point computing-device to analyze the collected pattern of life data for the endpoint agent passed to the cyber security appliance against a normal pattern of life for the end-point computing-device.

12 . The method for an endpoint agent of claim 10 , further comprising using a cyber threat module that references one or more machine-learning models trained on potential cyber threats to analyze for potential cyber threats on the end-point computing-device in light of the collected pattern of life data that deviates from a normal pattern of life for that end-point computing-device to detect the cyber threat.

13 . The method of claim 10 , further comprising:

configuring an autonomous response module to cause one or more actions to contain a detected cyber threat when a cyber-threat risk score, indicative of a likelihood of a cyber-threat, is equal to or above an actionable threshold, wherein the cyber threat module is configured to generate the cyber-threat risk score based on an analysis of potential cyber threats on the end-point computing-device in light of the collected pattern of life data that deviates from a normal pattern of life for that end-point computing-device.

14 . The method of claim 10 , further comprising:

configuring the endpoint agent to send collected pattern of life data to the cyber security appliance, and further configuring the cyber security appliance to initially match a type of computing-device and operating system belonging to the end-point computing-device to apply and route the collected pattern of life data to a corresponding set of the one or more machine-learning models trained on the end-point computing-device.

15 . The method of claim 10 , further comprising:

configuring the endpoint agent to send collected pattern of life data to the cyber security appliance at periodic intervals when the endpoint agent is connected to a network where the cyber security appliance is installed; and

configuring the endpoint agent to send collected pattern of life data to one or more memories of the end-point computing-device when i) the end-point computing-device is not connected to the network where the cyber security appliance is installed as well as when ii) the cyber security appliance is unavailable; wherein in either situation, the collected pattern of life data is stored in the memories when possible.

16 . The method of claim 10 , further comprising:

configuring an autonomous response module to cause one or more actions to contain the cyber threat when a potential cyber threat is detected and when i) the endpoint agent is not connected to a network where the cyber security appliance is installed, when ii) the cyber security appliance is unavailable to communicate with the endpoint agent, and any combination of i) and ii), wherein the autonomous response module is configured to be located in the endpoint agent and uses a decision engine to take one or more actions preapproved by a user to autonomously attempt to contain the potential cyber threat when predefined conditions of suspicious behavior and/or anomaly level are met.

17 . The method of claim 10 , further comprising:

configuring an autonomous response module on the cyber security appliance to cause one or more actions by the endpoint agent to contain the cyber threat when detected, wherein the autonomous response module has a user programmable interface with any of i) fields, ii) menus, and iii) icons to allow a user to preauthorize the autonomous response module to take actions to contain the cyber threat.

18 . The method of claim 10 , further comprising:

configuring the collections module to cooperate with one or more probes that include at least: i) a first probe configured to collect data about an operating system of the end-point computing-device as well as ii) a second probe configured to collect data about an individual process executing on the end-point computing-device, and iii) a third probe to monitor and record events occurring on the end-point computing-device and collaborate with system event logging tool, wherein the collected data regarding the operating system and individual processes along with the recorded events are sent in the collected pattern of life data by the collections module to the cyber security appliance.

19 . A non-transitory computer readable medium comprising computer readable code operable that when executed by one or more processing apparatuses in the cyber security appliance, instruct a computing-device to perform the method of claim 10 .

Assignments (2)
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0576 →
SECURITY INTEREST Recorded Apr 7, 2025
From: DARKTRACE HOLDINGS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 070762/0592 →
Continuity (3)
Continuation 16279039 · Feb 19, 2019
Provisional Application 62632623 · Feb 20, 2018
Related Publication 20230080471A1 · Mar 16, 2023
References Cited (107)
US 6154844A · Touboul et al. · 2000 [cited by applicant]
US 6965968B1 · Touboul · 2005 [cited by applicant]
US 7307999B1 · Donaghey · 2007 [cited by applicant]
US 7418731B2 · Touboul · 2008 [cited by applicant]
US 7448084B1 · Apap et al. · 2008 [cited by applicant]
US 8312540B1 · Kahn et al. · 2012 [cited by applicant]
US 8819803B1 · Richards et al. · 2014 [cited by applicant]
US 8879803B2 · Ukil et al. · 2014 [cited by applicant]
US 8966036B1 · Asgekar et al. · 2015 [cited by applicant]
US 9043905B1 · Allen et al. · 2015 [cited by applicant]
US 9106687B1 · Sawhney et al. · 2015 [cited by applicant]
US 9185095B1 · Moritz et al. · 2015 [cited by applicant]
US 9213990B2 · Adjaoute · 2015 [cited by applicant]
US 9401925B1 · Guo et al. · 2016 [cited by applicant]
US 9516039B1 · Yen et al. · 2016 [cited by applicant]
US 9516053B1 · Muddu et al. · 2016 [cited by applicant]
US 9641544B1 · Treat et al. · 2017 [cited by applicant]
US 9712548B2 · Shmueli et al. · 2017 [cited by applicant]
US 9727723B1 · Kondaveeti et al. · 2017 [cited by applicant]
US 10341391B1 · Pandey · 2019 [cited by examiner]
US 20020186698A1 · Ceniza · 2002 [cited by applicant]
US 20030070003A1 · Chong et al. · 2003 [cited by applicant]
US 20030131143A1 · Myers · 2003 [cited by examiner]
US 20040083129A1 · Herz · 2004 [cited by applicant]
US 20040167893A1 · Matsunaga et al. · 2004 [cited by applicant]
US 20050065754A1 · Schaf et al. · 2005 [cited by applicant]
US 20070118909A1 · Hertzog et al. · 2007 [cited by applicant]
US 20070294187A1 · Scherrer · 2007 [cited by applicant]
US 20080005137A1 · Surendran et al. · 2008 [cited by applicant]
US 20080109730A1 · Coffman et al. · 2008 [cited by applicant]
US 20090106174A1 · Battisha et al. · 2009 [cited by applicant]
US 20090254971A1 · Herz et al. · 2009 [cited by applicant]
US 20100009357A1 · Nevins et al. · 2010 [cited by applicant]
US 20100095374A1 · Gillum et al. · 2010 [cited by applicant]
US 20100125908A1 · Kudo · 2010 [cited by applicant]
US 20100235908A1 · Eynon et al. · 2010 [cited by applicant]
US 20100299292A1 · Collazo · 2010 [cited by applicant]
US 20110093428A1 · Wisse · 2011 [cited by applicant]
US 20110213742A1 · Lemmond et al. · 2011 [cited by applicant]
US 20110261710A1 · Chen et al. · 2011 [cited by applicant]
US 20120096549A1 · Amini et al. · 2012 [cited by applicant]
US 20120137367A1 · Dupont et al. · 2012 [cited by applicant]
US 20120151582A1 · Reasor et al. · 2012 [cited by applicant]
US 20120209575A1 · Barbat et al. · 2012 [cited by applicant]
US 20120210388A1 · Kolishchak · 2012 [cited by applicant]
US 20120284791A1 · Miller et al. · 2012 [cited by applicant]
US 20120304288A1 · Wright et al. · 2012 [cited by applicant]
US 20130091539A1 · Khurana et al. · 2013 [cited by applicant]
US 20130198119A1 · Eberhardt, III et al. · 2013 [cited by applicant]
US 20130198840A1 · Drissi et al. · 2013 [cited by applicant]
US 20130254885A1 · Devost · 2013 [cited by applicant]
US 20140007237A1 · Wright et al. · 2014 [cited by applicant]
US 20140074762A1 · Campbell · 2014 [cited by applicant]
US 20140165207A1 · Engel et al. · 2014 [cited by applicant]
US 20140215618A1 · Amit · 2014 [cited by applicant]
US 20140325643A1 · Bart et al. · 2014 [cited by applicant]
US 20150067835A1 · Chari et al. · 2015 [cited by applicant]
US 20150081431A1 · Akahoshi et al. · 2015 [cited by applicant]
US 20150161394A1 · Ferragut et al. · 2015 [cited by applicant]
US 20150163121A1 · Mahaffey et al. · 2015 [cited by applicant]
US 20150172300A1 · Cochenour · 2015 [cited by applicant]
US 20150180893A1 · Im et al. · 2015 [cited by applicant]
US 20150213358A1 · Shelton et al. · 2015 [cited by applicant]
US 20150286819A1 · Coden et al. · 2015 [cited by applicant]
US 20150310195A1 · Bailor et al. · 2015 [cited by applicant]
US 20150319185A1 · Kirti et al. · 2015 [cited by applicant]
US 20150341379A1 · Lefebvre et al. · 2015 [cited by applicant]
US 20150363699A1 · Nikovski · 2015 [cited by applicant]
US 20150379110A1 · Marvasti et al. · 2015 [cited by applicant]
US 20160062950A1 · Brodersen et al. · 2016 [cited by applicant]
US 20160078365A1 · Baumard · 2016 [cited by applicant]
US 20160149941A1 · Thakur et al. · 2016 [cited by applicant]
US 20160164902A1 · Moore · 2016 [cited by applicant]
US 20160173509A1 · Ray et al. · 2016 [cited by applicant]
US 20160241576A1 · Rathod et al. · 2016 [cited by applicant]
US 20160285858A1 · Li et al. · 2016 [cited by applicant]
US 20160352768A1 · Lefebvre et al. · 2016 [cited by applicant]
US 20160373476A1 · Dell'Anno et al. · 2016 [cited by applicant]
US 20170063907A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063910A1 · Muddu et al. · 2017 [cited by applicant]
US 20170063911A1 · Muddu et al. · 2017 [cited by applicant]
US 20170099310A1 · Di Pietro · 2017 [cited by examiner]
US 20170169360A1 · Veeramachaneni et al. · 2017 [cited by applicant]
US 20170220801A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170230391A1 · Ferguson et al. · 2017 [cited by applicant]
US 20170230392A1 · Stockdale · 2017 [cited by applicant]
US 20170251012A1 · Stockdale et al. · 2017 [cited by applicant]
US 20170270422A1 · Sorakado · 2017 [cited by applicant]
US 20180018456A1 · Chen · 2018 [cited by examiner]
US 20180027006A1 · Zimmermann et al. · 2018 [cited by applicant]
US 20180167402A1 · Scheidler et al. · 2018 [cited by applicant]
US 20180176260A1 · Palumbo · 2018 [cited by examiner]
US 20180183680A1 · Chen et al. · 2018 [cited by applicant]
US 20180255076A1 · Paine · 2018 [cited by applicant]
US 20180332053A1 · Weis · 2018 [cited by examiner]
US 20180332054A1 · Ford · 2018 [cited by applicant]
EP 2922268A1 · 2015 [cited by applicant]
WO 2001031420A2 · 2001 [cited by applicant]
WO 2008121945A2 · 2008 [cited by applicant]
WO 2013053407A1 · 2013 [cited by applicant]
WO 2014088912A1 · 2014 [cited by applicant]
WO 2015027828A1 · 2015 [cited by applicant]
WO 2016020660A1 · 2016 [cited by applicant]
Abdallah Abbey Sebyala et al., “Active Platform Security through Intrusion Detection Using Naive Bayesian Network for Anomaly Detection,” Department of Electronic and Electrical Engineering, 5 pages, University College … [cited by applicant]
Marek Zachara et al., “Detecting Unusual User Behavior to Identify Hijacked Internet Auctions Accounts,” Lecture Notes in Computer Science, 2012, vol. 7465, Springer, Berlin, Heidelberg, Germany. [cited by applicant]
Non-Final Office Action for U.S. Appl. No. 16/279,039 mailed Jun. 18, 2021, 22 pages. [cited by applicant]
Final Office Action for U.S. Appl. No. 16/279,039 mailed Jan. 24, 2022, 17 pages. [cited by applicant]