IP Library Patent Application 18811493
Patent Application
App. No. 18/811,493

SYSTEMS AND METHODS FOR INTELLIGENT CYBER SECURITY THREAT DETECTION AND MITIGATION THROUGH AN EXTENSIBLE AUTOMATED INVESTIGATIONS AND THREAT MITIGATION PLATFORM

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/811,493
Abstract

A cybersecurity system and method for handling a cybersecurity event includes identifying a cybersecurity alert; selectively initializing automated threat intelligence workflows based on computing a cybersecurity alert type, wherein the automated threat intelligence workflows include a plurality of automated investigative tasks that, when executed by one or more computers, derive cybersecurity alert intelligence data; and executing the plurality of automated investigative tasks includes automatically sourcing a corpus of investigative data; deriving the cybersecurity alert intelligence data based on extracting selective pieces of data from the corpus of investigative data, wherein the cybersecurity alert intelligence data informs an inference of a cybersecurity alert severity of the cybersecurity alert; and automatically routing the cybersecurity alert to one of a plurality of distinct threat mitigation or threat disposal routes based on the cybersecurity alert severity of the cybersecurity alert.

Claims (10)

1 . A method comprising:

producing a plurality of automated investigation tasks based on detecting a security event, wherein producing each of the plurality of automated investigation tasks includes configuring one or more application programming interface (API) calls based on a set of API call parameters of a target external data source;

generating a corpus of investigation findings data associated with the security event based on executing the plurality of automated investigation tasks;

configuring an investigation findings artifact based on one or more pieces of data included in the corpus of investigation findings data; and

executing one or more event handling actions or one or more event disposal actions that resolve or mitigate a threat of the security event based on an assessment of the investigation findings artifact.

2 . A computer program product that, when executed by one or more processors, performs operations comprising:

producing a plurality of automated investigation tasks based on detecting a security event, wherein producing each of the plurality of automated investigation tasks includes configuring one or more application programming interface (API) calls based on a set of API call parameters of a target external data source;

generating a corpus of investigation findings data associated with the security event based on executing the plurality of automated investigation tasks;

configuring an investigation findings artifact based on one or more pieces of data included in the corpus of investigation findings data; and

executing one or more event handling actions or one or more event disposal actions that resolve or mitigate a threat of the security event based on an assessment of the investigation findings artifact.

Assignments (2)
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2026
From: EXPEL, INC.
To: HERCULES CAPITAL, INC.
Reel/Frame 075041/0970 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 22, 2024
From: PETERS, MATT; WEBER, ELISABETH; SILBERMAN, PETER; BEGEMAN, JOHN; WHALEN, DAN; HENCINSKI, JON
To: EXPEL, INC.
Reel/Frame 068363/0881 →