IP Library Granted Patent US 12,556,571
Granted Patent B2
US 12,556,571 · App. 18/449,992 · Granted Feb 17, 2026

Agentless workload vulnerability scanning

Inventors: Abhijeet Singh Rawat (Hyderabad, IN); Abhiram Barik (Hyderabad, IN); Chandar Dayakar Singh Gadi (Bangalore, IN); Krishnakumar C (Bangalore, IN)
Assignee: Zscaler, Inc.
H04L63/1433H04L41/22H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,556,571
App. No.
18/449,992
Granted
Feb 17, 2026
Kind
B2
Abstract

Systems and methods for agentless workload vulnerability scanning include creating a snapshot of a workload in a cloud environment and analyzing workload data from the snapshot to identify one or more characteristics of the workload. The characteristics can be used to identify vulnerabilities present in the workload by correlation. These identified vulnerabilities can be persisted in a database and displayed to users for alerting and remediation.

Claims (28)

1 . A method comprising steps of:

creating a snapshot of a workload in a cloud environment, wherein the snapshot includes data within a root disk of the workload, files making up the workload, and posture control data of the workload at a specific point in time;

analyzing workload data from the snapshot to identify one or more characteristics of the workload;

identifying vulnerabilities present in the workload by correlating the one or more characteristics of the workload; and

persisting the identified vulnerabilities in a database.

2 . The method of claim 1 , wherein the workload is a virtual machine instance, and wherein the steps are performed without an agent installed on the workload.

3 . The method of claim 2 , wherein the virtual machine instance is associated with one of a plurality of Cloud Service Providers (CSPs), and wherein the snapshot is performed by a snapshot manager executing outside of an environment of the CSP.

4 . The method of claim 1 , wherein the identified vulnerabilities are persisted in the database on a per-workload basis.

5 . The method of claim 1 , wherein prior to the creating, the steps include configuring one or more discovery modules.

6 . The method of claim 1 , wherein the one or more characteristics include any of an Operating System (OS) of the workload and packages present in the workload.

7 . The method of claim 1 , wherein the steps are performed in response to a user initiated trigger or based on an automated schedule.

8 . The method of claim 1 , wherein the steps further include providing a Graphical User Interface (GUI) for displaying the identified vulnerabilities.

9 . The method of claim 8 , wherein the GUI includes actionable steps describing how to remediate the identified vulnerabilities.

10 . The method of claim 8 , wherein the GUI includes a risk level associated with each identified vulnerability.

11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:

creating a snapshot of a workload in a cloud environment, wherein the snapshot includes data within a root disk of the workload, files making up the workload, posture control data of the workload at a specific point in time;

analyzing workload data from the snapshot to identify one or more characteristics of the workload;

identifying vulnerabilities present in the workload by correlating the one or more characteristics of the workload; and

persisting the identified vulnerabilities in a database.

12 . The non-transitory computer-readable medium of claim 11 , wherein the workload is a virtual machine instance, and wherein the steps are performed without an agent installed on the workload.

13 . The non-transitory computer-readable medium of claim 12 , wherein the virtual machine instance is associated with one of a plurality of Cloud Service Providers (CSPs), and wherein the snapshot is performed by a snapshot manager executing outside of an environment of the CSP.

14 . The non-transitory computer-readable medium of claim 11 , wherein the identified vulnerabilities are persisted in the database on a per-workload basis.

15 . The non-transitory computer-readable medium of claim 11 , wherein prior to the creating, the steps include configuring one or more discovery modules.

16 . The non-transitory computer-readable medium of claim 11 , wherein the one or more characteristics include any of an Operating System (OS) of the workload and packages present in the workload.

17 . The non-transitory computer-readable medium of claim 11 , wherein the steps are performed in response to a user initiated trigger or based on an automated schedule.

18 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include providing a Graphical User Interface (GUI) for displaying the identified vulnerabilities.

19 . The non-transitory computer-readable medium of claim 18 , wherein the GUI includes actionable steps describing how to remediate the identified vulnerabilities.

20 . The non-transitory computer-readable medium of claim 18 , wherein the GUI includes a risk level associated with each identified vulnerability.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2023
From: RAWAT, ABHIJEET SINGH; BARIK, ABHIRAM; GADI, CHANDAR DAYAKAR SINGH; C, KRISHNAKUMAR
To: ZSCALER, INC.
Reel/Frame 064593/0913 →
Priority Claims (1)
IN 202311044668 · Jul 3, 2023 · national
Continuity (1)
Related Publication 20250016190A1 · Jan 9, 2025
References Cited (15)
US 20110119742A1 · Maguire · 2011 [cited by examiner]
US 20210377210A1 · Singh et al. · 2021 [cited by applicant]
US 20220210195A1 · Parekh · 2022 [cited by examiner]
US 20220279012A1 · Seetharamaiah · 2022 [cited by examiner]
US 20220286428A1 · Howe et al. · 2022 [cited by applicant]
US 20220286429A1 · Howe et al. · 2022 [cited by applicant]
US 20220286854A1 · Howe et al. · 2022 [cited by applicant]
US 20220286860A1 · Howe et al. · 2022 [cited by applicant]
US 20220286894A1 · Howe et al. · 2022 [cited by applicant]
US 20220286911A1 · Howe et al. · 2022 [cited by applicant]
US 20220329442A1 · Bulusu et al. · 2022 [cited by applicant]
US 20220408255A1 · Howe et al. · 2022 [cited by applicant]
US 20230129466A1 · Moore · 2023 [cited by applicant]
US 20230164184A1 · Kothari et al. · 2023 [cited by applicant]
US 20240080329A1 · Reed · 2024 [cited by examiner]