IP Library › Granted Patent US 12,730,932
Granted Patent B1
US 12,730,932 · App. 19/247,792 · Granted Sep 8, 2026

Techniques for remediating deleted data cybersecurity risks

Inventors: Nir Ohfeld (Tel Aviv, IL); Shir Tamari (Tel Aviv, IL)
Assignee: Wiz, Inc.
G06F21/6245G06F3/0623G06F3/0652G06F3/0674G06F8/63G06F9/45558G06F21/577G06F21/602G06F2009/45562
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,932
App. No.
19/247,792
Granted
Sep 8, 2026
Kind
B1
Abstract

A system and method for remediating exposed deleted client data in a cloud computing virtualization is presented. The method includes accessing a disk of a virtualization in a computing environment, the disk including deleted data; recovering at least a file from the deleted data; detecting client data on the at least a file, wherein the client data is untied to any functionality provided by the virtualization; and permanently deleting the detected client data from the disk.

Claims (75)

1 . A method for remediating exposed deleted client data in a cloud computing virtualization, comprising:

accessing a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;

analyzing the one or more blocks at a low level, wherein the low level bypasses a file system;

reconstructing a file based on the analyzed one or more blocks;

detecting data in the file unutilized by the virtualization;

determining the data is client data in response to the detected data is unutilized; and

permanently deleting the client data from the disk.

2 . The method of claim 1 , wherein permanently deleting the client data further comprises:

detecting a storage block among the one or more blocks containing thereon at least a portion of the client data; and

overwriting the detected storage block.

3 . The method of claim 1 , further comprising:

generating a representation of the client data;

generating a representation of the virtualization; and

storing the representation of the client data and the representation of the virtualization in a security database, wherein the security database includes a representation of the computing environment.

4 . The method of claim 1 , further comprising:

detecting a storage block among the one or more blocks containing thereon at least a portion of the detected client data;

detecting an encryption key associated with the storage block; and

deleting the encryption key prior to permanently deleting the client data from the disk.

5 . The method of claim 1 , further comprising:

shredding the file.

6 . The method of claim 1 , further comprising:

detecting a software image based on which the virtualization is deployed;

generating a new software image based on the virtualization after the client data is permanently deleted; and

replacing the software image with the new software image.

7 . The method of claim 1 , further comprising:

detecting a code object based on which the virtualization is deployed;

generating a new code object based on the virtualization after the client data is permanently deleted; and

replacing the code object with the new code object.

8 . The method of claim 7 , further comprising:

instantiating a new virtualization based on the new code object.

9 . The method of claim 1 , further comprising:

identifying a file header in the analyzed one or more blocks, wherein reconstructing the file is further based on the identified file header.

10 . The method of claim 1 , further comprising:

identifying, on the disk, block storage including deleted files; and

generating an inspectable disk based only on the identified block storage.

11 . A non-transitory computer-readable medium storing a set of instructions for remediating exposed deleted client data in a cloud computing virtualization, the set of instructions comprising:

one or more instructions that, when executed by one or more processing circuitries of a device, cause the device to:

access a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;

analyze the one or more blocks at a low level, wherein the low level bypasses a file system;

reconstruct a file based on the analyzed one or more blocks;

detect data in the file unutilized by the virtualization;

determine the data is client data in response to the detected data is unutilized; and

permanently delete the client data from the disk.

12 . A system for remediating exposed deleted client data in a cloud computing virtualization comprising:

a processing circuitry;

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

access a disk of a virtualization in a computing environment, the disk including deleted data, wherein the deleted data is one or more blocks;

analyze the one or more blocks at a low level, wherein the low level bypasses a file system;

reconstruct a file based on the analyzed one or more blocks;

detect data in the file unutilized by the virtualization;

determine the data is client data in response to the detected data is unutilized; and

permanently delete the client data from the disk.

13 . The system of claim 12 , wherein the memory contains further instructions that, when executed by the processing circuitry for permanently deleting the client data, further configure the system to:

detect a storage block among the one or more blocks containing thereon at least a portion of the client data; and

overwrite the detected storage block.

14 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

generate a representation of the client data;

generate a representation of the virtualization; and

store the representation of the client data and the representation of the virtualization in a security database, wherein the security database includes a representation of the computing environment.

15 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a storage block among the one or more blocks containing thereon at least a portion of the detected client data;

detect an encryption key associated with the storage block; and

delete the encryption key prior to permanently deleting the client data from the disk.

16 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

shred the file.

17 . The system of claim 12 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a software image based on which the virtualization is deployed;

generate a new software image based on the virtualization after the client data is permanently deleted; and

replace the software image with the new software image.

18 . The system of claim 11 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

detect a code object based on which the virtualization is deployed;

generate a new code object based on the virtualization after the client data is permanently deleted; and

replace the code object with the new code object.

19 . The system of claim 18 , wherein the memory contains further instructions which when executed by the processing circuitry further configure the system to:

instantiate a new virtualization based on the new code object.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 18, 2025
From: OHFELD, NIR; TAMARI, SHIR
To: WIZ, INC.
Reel/Frame 072044/0021 →
References Cited (19)
US 7865536B1 · Ghemawat · 2011 [cited by examiner]
US 8639214B1 · Fujisaki · 2014 [cited by examiner]
US 8682867B2 · Barton et al. · 2014 [cited by applicant]
US 20060288044A1 · Kashiwagi · 2006 [cited by examiner]
US 20080307414A1 · Alpern · 2008 [cited by examiner]
US 20090196417A1 · Beaver et al. · 2009 [cited by applicant]
US 20100008551A9 · Schiller · 2010 [cited by examiner]
US 20140201151A1 · Kumarasamy · 2014 [cited by examiner]
US 20200264791A1 · Sasson et al. · 2020 [cited by applicant]
US 20220035556A1 · Cashman et al. · 2022 [cited by applicant]
US 20220147272A1 · Sasson · 2022 [cited by examiner]
US 20230297542A1 · Shinkle · 2023 [cited by examiner]
US 20230376455A1 · Subramanian · 2023 [cited by examiner]
US 20230400955A1 · Barsky · 2023 [cited by examiner]
US 20240176770A1 · Parmar · 2024 [cited by examiner]
US 20250077256A1 · Farley · 2025 [cited by examiner]
US 20250165349A1 · Bhargava M.R. · 2025 [cited by examiner]
NPL Search Terms (Year: 2025). [cited by examiner]
NPL Search Terms (Year: 2026). [cited by examiner]