IP Library › Granted Patent US 12,488,100
Granted Patent B2
US 12,488,100 · App. 18/179,202 · Granted Dec 2, 2025

Techniques for system feedback in remediating cybersecurity risks

Inventors: Itay Arbel (Tel Aviv, IL); Mattan Shalev (Tel Aviv, IL); Yaniv Shaked (Tel Aviv, IL); Alon Schindel (Tel Aviv, IL); Ami Luttwak (Binyamina, IL); Roy Reznik (Tel Aviv, IL); Yinon Costica (Tel Aviv, IL); Gal Kozoshnik (Petah Tikva, IL)
Assignee: Wiz, Inc.
G06F21/554G06F21/566G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,488,100
App. No.
18/179,202
Granted
Dec 2, 2025
Kind
B2
Abstract

A system and method for iterative cybersecurity remediation based on a digital forensic finding is disclosed. In an embodiment, the method includes detecting a forensic finding, the forensic finding based on a forensic artifact detected on a disk of a resource in a computing environment; generating an inspectable disk based on the disk of the resource; inspecting the inspectable disk for a cybersecurity object based on the forensic artifact; and initiating a remediation action on the disk based on the cybersecurity object detected on the inspectable disk.

Claims (51)

1 . A method for iterative cybersecurity remediation based on a digital forensic finding, comprising:

detecting a forensic finding, the forensic finding based on a forensic artifact detected on a disk of a resource in a computing environment;

generating an inspectable disk based on the disk of the resource;

inspecting the inspectable disk for a cybersecurity object based on the forensic artifact; and

initiating a remediation action on the disk based on the cybersecurity object detected on the inspectable disk.

2 . The method of claim 1 , further comprising:

generating a second inspectable disk based on the disk of the resource after the remediation action is complete; and

inspecting the second inspectable disk for the cybersecurity object.

3 . The method of claim 2 , further comprising:

determining that a cybersecurity threat corresponding to the cybersecurity object is resolved in response to determining that the cybersecurity object is not detected by inspecting the second inspectable disk.

4 . The method of claim 2 , further comprising:

deprovisioning the inspectable disk.

5 . The method of claim 2 , further comprising:

initiating a second remediation action, in response to detecting the cybersecurity object on the second inspectable disk.

6 . The method of claim 1 , further comprising:

initiating the remediation action on the inspectable disk prior to initiating the remediation action on the disk;

inspecting the inspectable disk for the cybersecurity object after completing the remediation action; and

initiating the remediation action on the disk only in response to determining that the cybersecurity object is not detected on the inspectable disk after completing the remediation action on the inspectable disk.

7 . The method of claim 1 , wherein the remediation action includes any one of: generating a notification, generating a ticket in a ticketing system, adding a rule to a policy, updating a rule to a policy, deleting a cryptographic key, removing a permission associated with the resource, revoking network access to the resource, revoking network access from the resource, sandboxing the disk, and any combination thereof.

8 . The method of claim 1 , wherein the forensic finding includes any one of: a file containing metadata, a file containing content of a deleted file, a cookie, a content extracted from a cache memory, a content extracted from a cache storage, website data, a disk image, a file attribute value, a record in a network log, a record in a cloud log, and any combination thereof.

9 . The method of claim 1 , further comprising:

detecting the forensic finding by traversing a security graph to detect a node representing the forensic finding, the node representing the finding connected to a node representing the disk, wherein the security graph includes a representation of the computing environment.

10 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

detecting a forensic finding, the forensic finding based on a forensic artifact detected on a disk of a resource in a computing environment;

generating an inspectable disk based on the disk of the resource;

inspecting the inspectable disk for a cybersecurity object based on the forensic artifact; and

initiating a remediation action on the disk based on the cybersecurity object detected on the inspectable disk.

11 . A system for iterative cybersecurity remediation based on a digital forensic finding, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

detect a forensic finding, the forensic finding based on a forensic artifact detected on a disk of a resource in a computing environment;

generate an inspectable disk based on the disk of the resource;

inspect the inspectable disk for a cybersecurity object based on the forensic artifact; and

initiate a remediation action on the disk based on the cybersecurity object detected on the inspectable disk.

12 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

generate a second inspectable disk based on the disk of the resource after the remediation action is complete; and

inspect the second inspectable disk for the cybersecurity object.

13 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

determine that a cybersecurity threat corresponding to the cybersecurity object is resolved in response to determining that the cybersecurity object is not detected by inspecting the second inspectable disk.

14 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

deprovision the inspectable disk.

15 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

initiate a second remediation action, in response to detecting the cybersecurity object on the second inspectable disk.

16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

initiate the remediation action on the inspectable disk prior to initiating the remediation action on the disk;

inspect the inspectable disk for the cybersecurity object after completing the remediation action; and

initiate the remediation action on the disk only in response to determining that the cybersecurity object is not detected on the inspectable disk after completing the remediation action on the inspectable disk.

17 . The system of claim 11 , wherein the remediation action includes any one of: generating a notification, generating a ticket in a ticketing system, adding a rule to a policy, updating a rule to a policy, deleting a cryptographic key, removing a permission associated with the resource, revoking network access to the resource, revoking network access from the resource, sandboxing the disk, and any combination thereof.

18 . The system of claim 11 , wherein the forensic finding includes any one of: a file containing metadata, a file containing content of a deleted file, a cookie, a content extracted from a cache memory, a content extracted from a cache storage, website data, a disk image, a file attribute value, a record in a network log, a record in a cloud log, and any combination thereof.

19 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configures the system to:

detect the forensic finding by traversing a security graph to detect a node representing the forensic finding, the node representing the finding connected to a node representing the disk, wherein the security graph includes a representation of the computing environment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 5, 2023
From: ARBEL, ITAY; SHALEV, MATTAN; SHAKED, YANIV; SCHINDEL, ALON; LUTTWAK, AMI; REZNIK, ROY; KOZOSHNIK, GAL; COSTICA, YINON
To: WIZ, INC.
Reel/Frame 063227/0098 →
Continuity (1)
Related Publication 20240303326A1 · Sep 12, 2024
References Cited (8)
US 8904525B1 · Hodgman · 2014 [cited by examiner]
US 10148675B1 · Brandwine · 2018 [cited by examiner]
US 10552610B1 · Vashisht · 2020 [cited by examiner]
US 11663340B2 · Wu · 2023 [cited by examiner]
US 20100241977A1 · Greetham · 2010 [cited by examiner]
US 20220255957A1 · Campbell et al. · 2022 [cited by applicant]
US 20230089313A1 · Shua · 2023 [cited by examiner]
US 20240086525A1 · Orazio · 2024 [cited by examiner]