IP Library Patent Application 18823011
Patent Application
App. No. 18/823,011

SECURITY THREAT INVESTIGATION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/823,011
Filed
Sep 3, 2024
Examiner
SU, SARAH
Art Unit
2431
USPC
726/23
Abstract

In certain aspects, a computer-implemented method includes receiving an analysis request based on a suspicious activity alert. The method includes extracting, responsive to receiving the analysis request and based on the suspicious activity alert, key details from process data associated with the suspicious activity alert. The method includes identifying telemetry data during a predefined period prior to and after the suspicious activity alert. The method includes retrieving contextual data and organizational data associated with the process data. The method includes generating a prompt based on at least the telemetry data, the contextual data, and the organizational data. The method includes receiving an analysis report, wherein the analysis report identifies, based on the prompt, potential threats and remediation steps.

Claims (40)

1 . A computer-implemented method for security threat investigation, comprising:

receiving an analysis request based on a suspicious activity alert;

extracting, responsive to receiving the analysis request and based on the suspicious activity alert, key details from process data associated with the suspicious activity alert;

identifying telemetry data during a predefined period prior to and after the suspicious activity alert;

retrieving contextual data and organizational data associated with the process data;

generating a prompt based on at least the telemetry data, the contextual data, and the organizational data; and

receiving an analysis report, wherein the analysis report identifies, based on the prompt, potential threats and remediation steps.

2 . The computer-implemented method of claim 1 , wherein generating the prompt is based on derived context and guidance of at least the telemetry data, the contextual data, and the organizational data.

3 . The computer-implemented method of claim 1 , wherein the key details comprise one of process IDs, code signing information, users, and command line arguments for each process associated with the suspicious activity alert.

4 . The computer-implemented method of claim 1 , wherein identifying the telemetry data comprises focusing on relevant factors comprising one of related processes, users, and network activity.

5 . The computer-implemented method of claim 1 , further comprising searching a threat feed service to retrieve related information associated with the process data.

6 . The computer-implemented method of claim 5 , wherein the related information comprises one of security research and malware tactics, techniques, and procedures.

7 . The computer-implemented method of claim 1 , wherein the prompt comprises a system message and a user message, wherein the system message is static and the user message is dynamically generated based on a detected event that triggers the suspicious activity alert.

8 . A system comprising:

a memory comprising instructions; and

a processor configured to execute the instructions which, when executed, cause the processor to:

receive an analysis request based on a suspicious activity alert;

extract, responsive to receiving the analysis request and based on the suspicious activity alert, key details from process data associated with the suspicious activity alert;

identify telemetry data during a predefined period prior to and after the suspicious activity alert;

retrieve contextual data and organizational data associated with the process data;

generate a prompt based on at least the telemetry data, the contextual data, and the organizational data; and

receive an analysis report, wherein the analysis report identifies, based on the prompt, potential threats and remediation steps.

9 . The system of claim 8 , wherein the prompt is based on derived context and guidance of at least the telemetry data, the contextual data, and the organizational data.

10 . The system of claim 8 , wherein the key details comprise one of process IDs, code signing information, users, and command line arguments for each process associated with the suspicious activity alert.

11 . The system of claim 8 , wherein identifying the telemetry data comprises focusing on relevant factors comprising one of related processes, users, and network activity.

12 . The system of claim 8 , wherein the processor is further configured to execute the instructions which, when executed, cause the processor to search a threat feed service to retrieve related information associated with the process data.

13 . The system of claim 12 , wherein the related information comprises one of security research and malware tactics, techniques, and procedures.

14 . The system of claim 8 , wherein the prompt comprises a system message and a user message, wherein the system message is static and the user message is dynamically generated based on a detected event that triggers the suspicious activity alert.

15 . A non-transitory machine-readable storage medium comprising machine-readable instructions for causing a processor to execute a method, the method comprising:

receiving an analysis request based on a suspicious activity alert;

extracting, responsive to receiving the analysis request and based on the suspicious activity alert, key details from process data associated with the suspicious activity alert;

identifying telemetry data during a predefined period prior to and after the suspicious activity alert;

retrieving contextual data and organizational data associated with the process data;

generating a prompt based on at least the telemetry data, the contextual data, and the organizational data; and

receiving an analysis report, wherein the analysis report identifies, based on the prompt, potential threats and remediation steps.

16 . The non-transitory machine-readable storage medium of claim 15 , wherein generating the prompt is based on derived context and guidance of at least the telemetry data, the contextual data, and the organizational data.

17 . The non-transitory machine-readable storage medium of claim 15 , wherein the key details comprise one of process IDs, code signing information, users, and command line arguments for each process associated with the suspicious activity alert.

18 . The non-transitory machine-readable storage medium of claim 15 , wherein identifying the telemetry data comprises focusing on relevant factors comprising one of related processes, users, and network activity.

19 . The non-transitory machine-readable storage medium of claim 15 , further comprising searching a threat feed service to retrieve related information associated with the process data.

20 . The non-transitory machine-readable storage medium of claim 15 , wherein the prompt comprises a system message and a user message, wherein the system message is static and the user message is dynamically generated based on a detected event that triggers the suspicious activity alert.

Assignments (2)
PATENT SECURITY AGREEMENT Recorded Mar 3, 2026
From: JAMF SOFTWARE, LLC
To: BLUE OWL CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 075025/0447 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 20, 2025
From: BENYO, MATTHEW
To: JAMF SOFTWARE, LLC
Reel/Frame 072596/0584 →