IP Library Granted Patent US 12,563,089
Granted Patent B1
US 12,563,089 · App. 19/258,509 · Granted Feb 24, 2026

Techniques for cybersecurity incident investigation utilizing timeline generation based on entity queries

Inventors: Yehonatan Amnon Hornstein (Tel Aviv, IL); Matan Haim (Tel Aviv, IL); Ofir Brukner (Tenafly, NJ)
Assignee: Wiz, Inc.
H04L63/1441H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,563,089
App. No.
19/258,509
Granted
Feb 24, 2026
Kind
B1
Abstract

A system and method for entity-based timeline generation in cybersecurity investigation and remediation of detected issues thereof is presented. The method includes: receiving an incident record, wherein the incident record is generated based on a cybersecurity incident in a cloud computing environment; extracting a plurality of entities from the incident record, each entity deployed in at least the cloud computing environment; generating an entity-specific query for each of the plurality of entities extracted from the incident record; generating a timeline data structure based on at least a result of executing an entity-specific query, wherein the timeline data structure includes a user interface configured to receive a user input; and initiating a remediation action in the cloud computing environment, the remediation action selected from the user interface.

Claims (50)

1 . A method for entity-based timeline generation in cybersecurity investigation and remediation of detected issues thereof, comprising:

receiving an incident record, wherein the incident record is generated based on a cybersecurity incident in a cloud computing environment;

extracting a plurality of entities from the incident record, each entity deployed in at least the cloud computing environment;

generating an entity-specific query for each of the plurality of entities extracted from the incident record;

generating a timeline data structure based on analyzing at least a result of executing an entity-specific query, wherein the timeline data structure includes a user interface configured to receive a user input, and wherein analyzing at least the result includes initiating cross-cloud correlation between an entity extracted from the incident record and another entity deployed in a second cloud computing environment; and

initiating a remediation action in the cloud computing environment, the remediation action selected from the user interface.

2 . The method of claim 1 , further comprising:

detecting that an entity of the plurality of entities is an assumed role based on an event in a log of the cloud computing environment;

unchaining the detected entity to retrieve an originating entity; and

generating an entity-specific query based on the originating entity.

3 . The method of claim 2 , further comprising:

initiating the remediation action based on the originating entity.

4 . The method of claim 1 , further comprising:

generating the timeline data structure further based on any one of: metadata, computing environment data, a rule which triggered detection of the incident record, or any combination thereof.

5 . The method of claim 1 , further comprising:

receiving the incident record, wherein the incident record includes a plurality of event records.

6 . The method of claim 1 , wherein analyzing the result further comprises:

aggregating a plurality of results from at least a portion of the entity-specific queries.

7 . The method of claim 1 , wherein analyzing the result further comprises:

generating a summarization based on a plurality of results from at least a portion of the entity-specific queries.

8 . A non-transitory computer-readable medium storing a set of instructions for entity-based timeline generation in cybersecurity investigation and remediation of detected issues thereof, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

receive an incident record, wherein the incident record is generated based on a cybersecurity incident in a cloud computing environment;

extract a plurality of entities from the incident record, each entity deployed in at least the cloud computing environment;

generate an entity-specific query for each of the plurality of entities extracted from the incident record;

generate a timeline data structure based on analyzing at least a result of executing an entity-specific query, wherein the timeline data structure includes a user interface configured to receive a user input, and wherein analyzing at least the result includes initiating cross-cloud correlation between an entity extracted from the incident record and another entity deployed in a second cloud computing environment; and

initiate a remediation action in the cloud computing environment, the remediation action selected from the user interface.

9 . A system for entity-based timeline generation in cybersecurity investigation and remediation of detected issues thereof, comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

receive an incident record, wherein the incident record is generated based on a cybersecurity incident in a cloud computing environment;

extract a plurality of entities from the incident record, each entity deployed in at least the cloud computing environment;

generate an entity-specific query for each of the plurality of entities extracted from the incident record;

generate a timeline data structure based on analyzing at least a result of executing an entity-specific query, wherein the timeline data structure includes a user interface configured to receive a user input, and wherein analyzing at least the result includes initiating cross-cloud correlation between an entity extracted from the incident record and another entity deployed in a second cloud computing environment; and

initiate a remediation action in the cloud computing environment, the remediation action selected from the user interface.

10 . The system of claim 9 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

detect that an entity of the plurality of entities is an assumed role based on an event in a log of the cloud computing environment;

unchain the detected entity to retrieve an originating entity; and

generate an entity-specific query based on the originating entity.

11 . The system of claim 10 , wherein the memory contains further instructions which, when executed by the processing circuitry, further configure the system to:

initiate the remediation action based on the originating entity.

12 . The system of claim 9 , wherein the memory contains further instructions which, when executed by the processing circuitry further configure the system to:

generate the timeline data structure further based on any one of:

metadata, compute environment data, a rule which triggered detection of the incident record, or any combination thereof.

13 . The system of claim 9 , wherein the memory contains further instructions which, when executed by the processing circuitry further configure the system to:

receive the incident record, wherein the incident record includes a plurality of event records.

14 . The system of claim 9 , wherein the memory contains further instructions that, when executed by the processing circuitry for analyzing the result, further configure the system to:

aggregate a plurality of results from at least a portion of the entity-specific queries.

15 . The system of claim 9 , wherein the memory contains further instructions that, when executed by the processing circuitry for analyzing the result, further configure the system to:

generate a summarization based on a plurality of results from at least a portion of the entity-specific queries.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: AMNON HORNSTEIN, YEHONATAN; HAIM, MATAN; BRUKNER, OFIR
To: WIZ, INC.
Reel/Frame 072043/0631 →
References Cited (9)
US 11949692B1 · Glyer · 2024 [cited by examiner]
US 12019740B2 · Trost · 2024 [cited by examiner]
US 12047400B2 · Thompson · 2024 [cited by examiner]
US 20060235833A1 · Smith · 2006 [cited by examiner]
US 20150341389A1 · Kurakami · 2015 [cited by examiner]
US 20170279846A1 · Osterweil · 2017 [cited by examiner]
US 20200220885A1 · Will · 2020 [cited by examiner]
US 20200285737A1 · Kraus · 2020 [cited by examiner]
US 20220334904A1 · Chesneau · 2022 [cited by examiner]