IP Library Patent Application 18941731
Patent Application
App. No. 18/941,731

SYSTEMS AND METHODS FOR CLOUD-BASED COLLECTION AND PROCESSING OF DIGITAL FORENSIC EVIDENCE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/941,731
Abstract

Systems and methods for conducting a cloud-based forensic investigation of electronically-stored information are provided. The system includes an investigation requestor device configured to request a forensic investigation including selecting search criteria for the investigation, at least one remote system of the target, wherein the at least one remote system comprises electronically-stored information; a cloud server for storing forensic artifacts collected from the at least one remote system, wherein the forensic artifacts are collected based on the search criteria; and a cloud-based evidence-processing service configured to analyze the forensic artifacts and generate an initial report.

Claims (39)

1 . A system for conducting a cloud-based forensic investigation of electronically-stored information, the system comprising:

an investigation requestor device configured to request a forensic investigation including selecting search criteria for the investigation;

at least one remote system of the target, wherein the at least one remote system comprises electronically-stored information;

a cloud server for storing forensic artifacts collected from the at least one remote system, wherein the forensic artifacts are collected based on the search criteria; and

a cloud-based evidence-processing service configured to analyze the forensic artifacts and generate an initial report.

2 . The system of claim 1 , wherein the at least one remote system is a target endpoint device, and wherein a deployable agent comprising an executable program embedded with the search criteria is deployed to the target endpoint device to search for the forensic artifacts.

3 . The system of claim 2 , wherein the deployable agent automatically deletes from the target endpoint system.

4 . The system of claim 1 , wherein the at least one remote system is a cloud service.

5 . The system of claim 1 , wherein the investigation requestor device logs in to a website to request the forensic investigation and to select the search criteria.

6 . The system of claim 1 , wherein the cloud-based evidence-processing service automatically analyzes the forensic artifacts upon collection of the forensic artifacts from the remote system.

7 . The system of claim 1 , wherein the forensic artifacts are flagged by the cloud-based evidence-processing service within the initial report.

8 . The system of claim 1 , wherein the initial report is generated automatically by the cloud-based evidence-processing service and sent to the forensic service provider.

9 . A method of conducting a cloud-based forensic investigation of electronically-stored information, the method comprising:

receiving at a cloud server search criteria for forensic artifacts within electronically-stored information of a remote system of a target from an investigation requestor device;

scanning the remote system for the forensic artifacts using the search criteria;

collecting the forensic artifacts from the remote system, wherein the forensic artifacts are collected to a cloud server;

processing the forensic artifacts using a cloud-based evidence processing service; and

generating a digital report based on the processed forensic artifacts.

10 . The method of claim 9 , wherein the search criteria is selected by the client.

11 . The method of claim 10 , wherein the client logs into a forensic service provider website to select the search criteria.

12 . The method of claim 9 , wherein selecting search criteria by a client further includes selecting search criteria from pre-determined options provided by the forensic service provider.

13 . The method of claim 9 , wherein the remote system is an endpoint device, and wherein the search criteria is embedded in a deployable agent and scanning the endpoint device further includes:

deploying the deployable agent to the endpoint device; and

scanning the endpoint device by the deployable agent.

14 . The method of claim 13 , wherein the deployable agent autodeletes from the endpoint device.

15 . The method of claim 9 , wherein the remote system is at least one cloud service.

16 . The method of claim 15 , wherein the client provides access to the at least one cloud service.

17 . The method of claim 15 , wherein the forensic artifacts are collected from the at least one cloud service by a collection service.

18 . The method of claim 9 , wherein the initial report is generated automatically.

19 . The method of claim 9 , wherein at least one artifact of interest is flagged for review.

20 . A system for conducting a cloud-based forensic investigation of electronically-stored information, the system comprising:

a target device storing electronically-stored information;

a cloud server configured to:

receive search criteria from an investigation requestor device, the investigation requestor device being a client device or a forensic provider device;

configure an evidence collection module using the received search criteria;

initiate evidence collection from the target device using the configured evidence collection module;

store a forensic artifact collected by the configured evidence collection module;

analyze the forensic artifact using an evidence processing module; and

generate a digital report from an output of the evidence processing module.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2024
From: SALIBA, JAD JOHN; MACCARTHY, RANDY SHAWN; UZUN, TAYFUN
To: MAGNET FORENSICS INC.
Reel/Frame 069209/0894 →