IP Library Patent Application 19088619
Patent Application
App. No. 19/088,619

THREAT MITIGATION SYSTEM AND METHOD

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/088,619
Abstract

A computer-implemented method, computer program product and computing system for: a computer-implemented method is executed on a computing device and includes: obtaining object information concerning one or more initial objects within a computing platform in response to a security event; identifying an event type for the security event; and executing a response script based, at least in part, upon the event type.

Claims (71)

1 .- 31 . (canceled)

32 . A computer-implemented method, executed on a computing device, comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring artifacts gathered by the third party during the investigation of the security event;

monitoring objects reviewed by the third party during the investigation of the security event; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

33 . The computer-implemented method of claim 32 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

34 . The computer-implemented method of claim 33 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

35 . The computer-implemented method of claim 34 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

36 . The computer-implemented method of claim 32 further comprising executing a response script based, at least in part, upon the event type.

37 . The computer-implemented method of claim 36 , wherein executing the response script includes one or more of:

obtaining object information concerning one or more additional objects.

obtaining artifacts concerning the security event.

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

executing a remedial action in response to the security event.

38 . The computer-implemented method of claim 37 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

39 . A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon which, when executed by a processor, cause the processor to perform operations comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring artifacts gathered by the third party during the investigation of the security event;

monitoring objects reviewed by the third party during the investigation of the security event; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

40 . The computer program product of claim 39 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

41 . The computer program product of claim 40 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

42 . The computer program product of claim 40 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

43 . The computer program product of claim 39 further comprising executing a response script based, at least in part, upon the event type.

44 . The computer program product of claim 43 , wherein executing the response script includes one or more of:

obtaining object information concerning one or more additional objects.

obtaining artifacts concerning the security event.

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

executing a remedial action in response to the security event.

45 . The computer program product of claim 44 wherein the artifacts include one or more of:

raw data;

screen shots;

graphics;

notes;

annotations;

audio recordings; and

video recordings.

46 . A computing system including a processor and memory configured to perform operations comprising:

obtaining object information concerning one or more initial objects within a computing platform in response to a security event;

identifying an event type for the security event;

monitoring artifacts gathered by the third party during the investigation of the security event;

monitoring objects reviewed by the third party during the investigation of the security event; and

providing suggestions concerning additional actions to be taken concerning investigating the security event based upon, at least in part, the gathered artifacts and the reviewed objects.

47 . The computing system of claim 46 further comprising:

detecting the security event based upon identified suspect activity within the computing platform.

48 . The computing system of claim 47 wherein detecting the security event based upon identified suspect activity within the computing platform includes:

establishing connectivity with a plurality of security-relevant subsystems within the computing platform.

49 . The computing system of claim 47 wherein detecting the security event based upon identified suspect activity within the computing platform further includes:

monitoring the plurality of security-relevant subsystems to identify suspect activity within the computing platform.

50 . The computing system of claim 46 further comprising executing a response script based, at least in part, upon the event type.

51 . The computing system of claim 50 , wherein executing the response script includes one or more of:

obtaining object information concerning one or more additional objects.

obtaining artifacts concerning the security event.

providing suggestions to a third-party concerning a remedial action to be taken by the third-party in response to the security event.

executing a remedial action in response to the security event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2025
From: MURPHY, BRIAN P.; PARTLOW, JOE; O'CONNOR, COLIN; PFEIFFER, JASON; MURPHY, BRIAN PHILIP
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 070657/0695 →