IP Library Granted Patent US 12,499,243
Granted Patent B1
US 12,499,243 · App. 19/296,653 · Granted Dec 16, 2025

Automated threat hunting

Inventors: Eric Joseph Hammerle (Kirkland, WA); Xue Jun Wu (Seattle, WA); Colin James Phillips (Kirkland, WA); Changhwan Oh (Shoreline, WA); Robert Rowland Foley (Long Island City, NY); Michael Francis Buono (McLean, VA)
Assignee: Dropzone.ai, Inc.
G06F21/577G06F21/316
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,499,243
App. No.
19/296,653
Granted
Dec 16, 2025
Kind
B1
Abstract

Embodiments perform automated threat hunting in computing environments. A threat hunt plan is obtained to guide collection of candidate evidence items from evidence sources. Portions of candidate evidence items are discarded based on relevance scores, and evidence items are determined from non-discarded portions. Threat indicators associated with the evidence items are identified based on criteria in the threat hunt plan. Threat profiles are obtained based on the evidence items and threat indicators such that threat profiles include threat assessment metrics and are included in a report. Collection agents may interface with system logs, network traffic captures, endpoints, databases, email services, or user activity records to gather evidence items based on time ranges, filtering criteria, or sampling rates.

Claims (71)

1 . A method for managing security in a computing environment using one or more processors to execute instructions that are configured to cause actions, comprising:

obtaining a threat hunt plan to collect a plurality of candidate evidence items from one or more evidence sources;

discarding one or more portions of the plurality of candidate evidence items based on a relevance score associated with each candidate evidence item;

collecting one or more evidence items based on one or more non-discarded portions of the plurality of candidate evidence items;

identifying one or more threat indicators associated with the one or more evidence items based on one or more criteria in the threat hunt plan;

obtaining one or more threat profiles based on the one or more evidence items and the one or more threat indicators, wherein the one or more threat profiles include one or more threat assessment metrics associated with the one or more threat indicators, and wherein the one or more threat profiles are included in a report; and

obtaining a user interface that includes one or more display panels for content that includes the report and other information associated with the one or more threat assessments, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

2 . The method of claim 1 , further comprises:

collecting threat intelligence data from one or more external threat sources including one or more of a security vendor advisory, a government alert, an industry threat report, or a vulnerability disclosure.

3 . The method of claim 1 , wherein collecting the one or more candidate evidence items, further comprises:

obtaining one or more collection agents to interface with one or more of a system log, a network traffic capture, an endpoint, a database, an email service, or a user activity record, wherein the one or more collection agents collect the plurality of candidate evidence items from the one or more evidence sources based on one or more of a time range, a filtering criterion, or a sampling rate.

4 . The method of claim 1 , further comprising:

obtaining the threat hunt plan from a threat hunt plan repository based on a threat hunt hypothesis, wherein the threat hunt plan includes one or more of an evidence collection strategy, an investigation methodology, an analysis framework, or a reporting requirement; and

modifying the threat hunt plan based on one or more of an organizational environment, an available evidence source, a security configuration, or a network architecture.

5 . The method of claim 1 , further comprising:

discarding one or more other portions of candidate evidence items of the plurality of candidate evidence items based on one or more filters that include one or more of a relevance filter, a quality filter, a format validator, or a duplicate detector; and

normalizing one or more of a data format, a timestamp format, an entity identifier, or a metadata structure associated with each non-discarded candidate evidence item.

6 . The method of claim 1 , further comprising:

obtaining one or more authentication actions associated with the one or more evidence items, wherein the one or more authentication actions include one or more of a login frequency, an access timing pattern, a credential usage pattern, or a session management activity; and

correlating the one or more authentication actions with one or more of a user role, a geographic location, a device characteristic, or a network context to identify one or more security concerns, wherein the one or more security concerns are included in the threat profile.

7 . The method of claim 1 , wherein obtaining the one or more threat profiles further comprises:

obtaining one or more metrics that include one or more of a threat severity rating, a confidence score, a risk indicator, or an evidence correlation that are associated with the one or more evidence items, wherein the one or more threat profiles include the one or more metrics.

8 . The method of claim 1 , further comprising:

detecting one or more threats, wherein one or more descriptions of the one or more detected threats include one or more of evidence documentation, an attack vector description, a compromise indicator summary, or a threat actor attribution analysis;

obtaining one or more response recommendations associated with the one or more threats including one or more of an immediate containment measure, a threat mitigation strategy, a system hardening procedure, or an incident response escalation protocol; and

updating the report to include the one or more descriptions and the one or more response recommendations.

9 . The method of claim 1 , further comprising:

obtaining one or more other response recommendations including one or more of a complementary threat hunting plan, an expanded evidence collection activity, a related threat vector analysis, or a continuous monitoring requirement; and

collecting one or more detection rule proposals that incorporate one or more of a discovered threat indicator, an attack pattern, a behavioral anomaly, or a compromise signature into one or more automated monitoring systems; and

updating the report to include the one or more other response recommendations and the one or more detection rule proposals.

10 . The method of claim 1 , further comprising:

obtaining a threat hunt hypothesis based on one or more of a user input, a scheduled task, or a notice associated with one or more potential security threats, wherein the threat hunt plan is based on the threat hunt hypothesis.

11 . A network computer for managing security in a computing environment, comprising:

a memory that stores at least instructions; and

one or more processors that execute instructions that are configured to cause actions, including:

obtaining a threat hunt plan to collect a plurality of candidate evidence items from one or more evidence sources;

discarding one or more portions of the plurality of candidate evidence items based on a relevance score associated with each candidate evidence item;

collecting one or more evidence items based on one or more non-discarded portions of the plurality of candidate evidence items;

identifying one or more threat indicators associated with the one or more evidence items based on one or more criteria in the threat hunt plan;

obtaining one or more threat profiles based on the one or more evidence items and the one or more threat indicators, wherein the one or more threat profiles include one or more threat assessment metrics associated with the one or more threat indicators, and wherein the one or more threat profiles are included in a report; and

obtaining a user interface that includes one or more display panels for content that includes the report and other information associated with the one or more threat assessments, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

12 . The network computer of claim 11 , wherein collecting the one or more candidate evidence items, further comprises:

obtaining one or more collection agents to interface with one or more of a system log, a network traffic capture, an endpoint, a database, an email service, or a user activity record, wherein the one or more collection agents collect the plurality of candidate evidence items from the one or more evidence sources based on one or more of a time range, a filtering criterion, or a sampling rate.

13 . The network computer of claim 11 , further comprising:

obtaining the threat hunt plan from a threat hunt plan repository based on a threat hunt hypothesis, wherein the threat hunt plan includes one or more of an evidence collection strategy, an investigation methodology, an analysis framework, or a reporting requirement; and

modifying the threat hunt plan based on one or more of an organizational environment, an available evidence source, a security configuration, or a network architecture.

14 . The network computer of claim 11 , further comprising:

discarding one or more other portions of candidate evidence items of the plurality of candidate evidence items based on one or more filters that include one or more of a relevance filter, a quality filter, a format validator, or a duplicate detector; and

normalizing one or more of a data format, a timestamp format, an entity identifier, or a metadata structure associated with each non-discarded candidate evidence item.

15 . The network computer of claim 11 , further comprising:

obtaining one or more authentication actions associated with the one or more evidence items, wherein the one or more authentication actions include one or more of a login frequency, an access timing pattern, a credential usage pattern, or a session management activity; and

correlating the one or more authentication actions with one or more of a user role, a geographic location, a device characteristic, or a network context to identify one or more security concerns, wherein the one or more security concerns are included in the threat profile.

16 . The network computer of claim 11 , wherein obtaining the one or more threat profiles further comprises:

obtaining one or more metrics that include one or more of a threat severity rating, a confidence score, a risk indicator, or an evidence correlation that are associated with the one or more evidence items, wherein the one or more threat profiles include the one or more metrics.

17 . The network computer of claim 11 , further comprising:

detecting one or more threats, wherein one or more descriptions of the one or more detected threats include one or more of evidence documentation, an attack vector description, a compromise indicator summary, or a threat actor attribution analysis;

obtaining one or more response recommendations associated with the one or more threats including one or more of an immediate containment measure, a threat mitigation strategy, a system hardening procedure, or an incident response escalation protocol; and

updating the report to include the one or more descriptions and the one or more response recommendations.

18 . The network computer of claim 11 , further comprising:

obtaining one or more other response recommendations including one or more of a complementary threat hunting plan, an expanded evidence collection activity, a related threat vector analysis, or a continuous monitoring requirement; and

collecting one or more detection rule proposals that incorporate one or more of a discovered threat indicator, an attack pattern, a behavioral anomaly, or a compromise signature into one or more automated monitoring systems; and

updating the report to include the one or more other response recommendations and the one or more detection rule proposals.

19 . A processor readable non-transitory storage media that includes instructions configured for managing security in a computing environment, wherein execution of the instructions by one or more processors on one or more network computers performs actions, comprising:

obtaining a threat hunt plan to collect a plurality of candidate evidence items from one or more evidence sources;

discarding one or more portions of the plurality of candidate evidence items based on a relevance score associated with each candidate evidence item;

collecting one or more evidence items based on one or more non-discarded portions of the plurality of candidate evidence items;

identifying one or more threat indicators associated with the one or more evidence items based on one or more criteria in the threat hunt plan;

obtaining one or more threat profiles based on the one or more evidence items and the one or more threat indicators, wherein the one or more threat profiles include one or more threat assessment metrics associated with the one or more threat indicators, and wherein the one or more threat profiles are included in a report; and

obtaining a user interface that includes one or more display panels for content that includes the report and other information associated with the one or more threat assessments, wherein the content is dynamically transformed and arranged for display to a user based on one or more of user interaction telemetry, user feedback or telemetry metrics.

20 . The media of claim 19 , wherein collecting the one or more candidate evidence items, further comprises:

obtaining one or more collection agents to interface with one or more of a system log, a network traffic capture, an endpoint, a database, an email service, or a user activity record, wherein the one or more collection agents collect the plurality of candidate evidence items from the one or more evidence sources based on one or more of a time range, a filtering criterion, or a sampling rate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 11, 2025
From: HAMMERLE, ERIC JOSEPH; WU, XUE JUN; PHILLIPS, COLIN JAMES; OH, CHANGHWAN; FOLEY, ROBERT ROWLAND; BUONO, MICHAEL FRANCIS
To: DROPZONE.AI, INC.
Reel/Frame 071988/0462 →
References Cited (74)
US 7330817B1 · Exall et al. · 2008 [cited by applicant]
US 9600659B1 · Bird et al. · 2017 [cited by applicant]
US 10198433B2 · Weston et al. · 2019 [cited by applicant]
US 10666666B1 · Saurabh · 2020 [cited by applicant]
US 10694026B2 · Chandrasekaran et al. · 2020 [cited by applicant]
US 11916767B1 · Wu et al. · 2024 [cited by applicant]
US 11943387B1 · Wolinsky et al. · 2024 [cited by applicant]
US 11960515B1 · Pallakonda et al. · 2024 [cited by applicant]
US 12008332B1 · Gardner et al. · 2024 [cited by applicant]
US 12034616B1 · Wu et al. · 2024 [cited by applicant]
US 12105746B1 · Wu et al. · 2024 [cited by applicant]
US 12229313B1 · Shastry et al. · 2025 [cited by applicant]
US 12248501B1 · Wu et al. · 2025 [cited by applicant]
US 20030093276A1 · Miller et al. · 2003 [cited by applicant]
US 20130343205A1 · Dolan et al. · 2013 [cited by applicant]
US 20150347569A1 · Allen et al. · 2015 [cited by applicant]
US 20160171068A1 · Hardin · 2016 [cited by applicant]
US 20160342317A1 · Lim et al. · 2016 [cited by applicant]
US 20180240043A1 · Majumdar et al. · 2018 [cited by applicant]
US 20190138879A1 · Hu et al. · 2019 [cited by applicant]
US 20200184072A1 · Ikeda · 2020 [cited by applicant]
US 20200387816A1 · Rodriguez Bravo et al. · 2020 [cited by applicant]
US 20210174095A1 · Kong et al. · 2021 [cited by applicant]
US 20220263858A1 · Bargnesi · 2022 [cited by examiner]
US 20220263860A1 · Crabtree · 2022 [cited by examiner]
US 20220295008A1 · Nold et al. · 2022 [cited by applicant]
US 20220391595A1 · Shevelev et al. · 2022 [cited by applicant]
US 20230208971A1 · Te Booij et al. · 2023 [cited by applicant]
US 20230244869A1 · Neumann · 2023 [cited by applicant]
US 20230359789A1 · Andre et al. · 2023 [cited by applicant]
US 20240045990A1 · Boyer et al. · 2024 [cited by applicant]
US 20240054233A1 · Ohayon et al. · 2024 [cited by applicant]
US 20240070251A1 · Maizels et al. · 2024 [cited by applicant]
US 20240098105A1 · Kanady · 2024 [cited by examiner]
US 20240134865A1 · Bierner et al. · 2024 [cited by applicant]
US 20240260892A1 · Haas et al. · 2024 [cited by applicant]
US 20240281472A1 · Larhette et al. · 2024 [cited by applicant]
US 20240291779A1 · Catalano et al. · 2024 [cited by applicant]
US 20240291853A1 · Murphy et al. · 2024 [cited by applicant]
US 20240323152A1 · Rosenberg et al. · 2024 [cited by applicant]
US 20240355337A1 · Altaf et al. · 2024 [cited by applicant]
US 20240363099A1 · Altaf et al. · 2024 [cited by applicant]
US 20240363103A1 · Altaf et al. · 2024 [cited by applicant]
US 20240393750A1 · Malladi et al. · 2024 [cited by applicant]
US 20240402664A1 · Sudhakar et al. · 2024 [cited by applicant]
US 20240403416A1 · Sharpe et al. · 2024 [cited by applicant]
US 20240403634A1 · Hawes et al. · 2024 [cited by applicant]
US 20240411994A1 · Siracusano et al. · 2024 [cited by applicant]
US 20240412031A1 · Rayman · 2024 [cited by applicant]
US 20240412839A1 · Tang et al. · 2024 [cited by applicant]
US 20240414211A1 · Boyer et al. · 2024 [cited by applicant]
US 20250037107A1 · Abdelrahman et al. · 2025 [cited by applicant]
US 20250047578A1 · Wu et al. · 2025 [cited by applicant]
US 20250053273A1 · Uva · 2025 [cited by applicant]
US 20250209156A1 · Sankaran · 2025 [cited by examiner]
CN 115981240B · 2023 [cited by applicant]
WO 2025029346A1 · 2025 [cited by applicant]
Office Communication for U.S. Appl. No. 18/230,123 mailed Sep. 25, 2023, 9 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/230,123 mailed Dec. 12, 2023, 22 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/587,712 mailed May 14, 2024, 14 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/652,093 mailed Jul. 31, 2024, 21 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/753,778 mailed Sep. 5, 2024, 16 Pages. [cited by applicant]
International Search Report and Written Opinion for International Patent Application No. PCT/US2024/028612 mailed Aug. 6, 2024, 14 Pages. [cited by applicant]
Sreake Division, “Achieving operational efficiency in Kubernetes with ChatGPT-4: Troubleshooting”, Three Shakes Inc., Blog; May 23, 2023, 57 pages. [cited by applicant]
Fixpoint Inc., “Decision to release fault notification service using LLM”, PR Times, Jul. 18, 2023, 4 pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/902,566 mailed Dec. 6, 2024, 21 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/753,778 mailed Dec. 30, 2024, 10 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/753,778 mailed Mar. 20, 2025, 4 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/978,990 mailed Mar. 12, 2025, 23 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/753,778 mailed Apr. 23, 2025, 11 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/978,990 mailed Jul. 7, 2025, 18 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/753,778 mailed Sep. 18, 2025, 10 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 18/978,990 mailed Sep. 30, 2025, 4 Pages. [cited by applicant]
Office Communication for U.S. Appl. No. 19/296,689 mailed Oct. 24, 2025, 10 Pages. [cited by applicant]