How to Secretly Collect Digital Evidence from Computers
This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.
Original patent title: “Remote operations forensics”
This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis. Granted in 2026.
Coverage
What does this patent actually cover?
The patent describes a system for monitoring computers and collecting digital evidence, called "forensic artifacts." It uses a single software program, or "agent," installed on the target computer, known as an "endpoint." This agent is designed to run entirely "in memory," meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or "chunked," prior to being sent to a "cloud server." This cloud server then organizes the data by "category," processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.
The gap
What does this patent NOT cover?
- Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
- Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.
- Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.
- Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.
- Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts.
These exclusions are unique to PatentBrief — derived from the actual claim language, not patent-office boilerplate.
Key facts
What made this novel
The truly clever part is the "in memory" operation of the agent, which allows it to collect sensitive "forensic artifacts" and monitoring data without leaving persistent traces on the target computer's disk. This stealthy approach significantly reduces the risk of detection and evidence tampering during an investigation.
Schematic visualization of the patent's claim structure. Hand-drawn diagrams in progress for each landmark patent.
Where you've seen this
Real-world examples
Endpoint Detection and Response (EDR) platforms
Incident response tools
Cloud-based security analytics services
Digital forensics software
Why it matters
The bigger picture
This technology matters because it allows for more discreet and efficient cybersecurity investigations. By operating "in memory" and avoiding disk writes, the system makes it harder for sophisticated attackers to detect and tamper with the evidence collection process. The integrated agent and cloud-based analysis, including natural language queries, streamline the process of understanding complex security incidents, helping organizations respond faster to threats.
Filed
August 28, 2024
Granted
September 15, 2026
Market context
Who's building on this
Companies in this space
Major cybersecurity companies like CrowdStrike, SentinelOne, and Microsoft (with Defender for Endpoint) are actively developing and deploying advanced endpoint monitoring and forensic collection capabilities. Cloud security providers such as Amazon Web Services and Google Cloud also offer services that integrate similar analytics and natural language processing for security data.
Market impact
This type of technology has significantly improved the speed and effectiveness of incident response in the cybersecurity market. It has enabled security teams to conduct more thorough and stealthy investigations, reducing the dwell time of attackers within networks. The integration of cloud-based analysis and natural language queries has also made complex security data more accessible and actionable for a wider range of security professionals.
Claim 1 — Plain English
What this patent covers
The patent describes a system for monitoring computers and collecting digital evidence, called "forensic artifacts." It uses a single software program, or "agent," installed on the target computer, known as an "endpoint." This agent is designed to run entirely "in memory," meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or "chunked," prior to being sent to a "cloud server." This cloud server then organizes the data by "category," processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.
The clever bit
The truly clever part is the "in memory" operation of the agent, which allows it to collect sensitive "forensic artifacts" and monitoring data without leaving persistent traces on the target computer's disk. This stealthy approach significantly reduces the risk of detection and evidence tampering during an investigation.
What it does not cover
- Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
- Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.
- Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.
- Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.
- Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts.
Patent timeline
Application submitted to the patent office
Patent officially issued
PatentBrief Score
Impact Score
Early stage
Citation count
0/40
No citations yet
Claim breadth
0/20
Narrow claimsclaimsThe numbered statements at the end of a patent that legally define what the inventor owns.Read more →
Recency
20/20
Granted within 5 years
Assignee scale
0/20
Independent or smaller assigneeassigneeThe entity that owns the patent — usually the inventor's employer or a company.Read more →
PatentBrief Impact Score — based on citation count, claim breadth, recency, and assignee scale. Not a legal assessment.
Heuristic Value Estimate
What this patent might be worth
$17K – $54K
Midpoint $34K · 17.9 yr remaining · industry ×1.4
Heuristic only — blends forward/backward citation counts, claim scope, time remaining, litigation history, and CPC-derived industry baseline. Real valuations need a professional appraisal.
Claim text not yet imported for this patent
Concepts involved
Cite this patent
(2026). How to Secretly Collect Digital Evidence from Computers (U.S. Patent No. 12,739,263). U.S. Patent and Trademark Office. https://patentbrief.org/patent/us/12739263/remote-operations-forensics
Auto-generated from the patent record. Double-check author order and the issue date against the official USPTO document before submitting.
Embed
Add this patent to your site
Drop this plain-English patent card into any blog post or article — free, no signup. It always links back to the full breakdown here.
<div data-patentlens-widget data-patent-number="US12739263"></div> <script src="https://patentbrief.org/embed.js" async></script>
Stay in the loop
Get a weekly digest of new patents.
One email per week. No spam. Unsubscribe anytime.
Keep exploring
Related patents you should know
US 4683195 · 1987
How to Make Billions of Copies of a DNA Segment
This patent describes the Polymerase Chain Reaction (PCR), a method to rapidly create many copies of a specific piece of DNA or RNA, enabling its detection and analysis.
Cetus Corp
US 8697359 · 2014
How to Edit Genes in Human Cells Using an Engineered CRISPR System
This patent describes an engineered CRISPR-Cas9 system for precisely cutting DNA in eukaryotic cells to change how genes work, opening the door for gene editing in complex organisms.
Massachusetts Institute of Technology
US 7657849 · 2010
How the iPhone's Slide-to-Unlock Gesture Works
Apple's 2010 patent describes unlocking a device by dragging a specific graphical image across the touchscreen along a predefined path, a gesture that became iconic with the original iPhone.
Apple Inc
US 4733665 · 1988
How Doctors Implant a Permanent Stent Using a Balloon
This patent describes the method for placing a permanent, expandable wire mesh tube inside a blood vessel or other body tube using a balloon-tipped catheter to widen it and keep it open.
Expandable Grafts Partnership
US 4965188 · 1990
How to Make Many Copies of a DNA Piece with Heat
This patent describes the Polymerase Chain Reaction (PCR) method, a technique to make millions of copies of a specific DNA segment using a heat-resistant enzyme and repeated temperature changes.
Cetus Corp
US 4235871 · 1980
How to Encapsulate Active Materials in Lipid Bubbles Efficiently
This patent describes a method for trapping biologically active substances inside tiny, multi-layered fat bubbles called liposomes, using a specific water-in-oil emulsion and gel-forming process to improve how much material gets captured.
Individual
Semantically similar
You might also find these interesting
US 12244567 · 2025 · CDW LLC
How to Monitor Secure Government Computer Networks Automatically
US 11876858 · 2024 · Armada Systems
Managing and Updating AI on Many Smart Devices from the Cloud
US 8112476 · 2012 · Confluence Commons Inc
How Software Automatically Collects and Organizes Data from Multiple Websites
US 9430664 · 2016 · Microsoft Technology Licensing LLC
How Microsoft Protects Corporate Data on Employee Devices
More to explore
More in Software & Internet
US 4405829 · 1983 · Massachusetts Institute of Technology
How RSA Public-Key Encryption Keeps Digital Messages Secret
US 6285999 · 2001 · Leland Stanford Junior University
How Websites Get Ranked by Importance
US 5960411 · 1999 · Amazon com Inc
How Amazon's One-Click Ordering Works for Online Purchases
US 7669123 · 2010 · Facebook Inc
Displaying Friends' Activities in a Social Network Feed
New to patents?
Common Questions
Frequently Asked Questions
What does How to Secretly Collect Digital Evidence from Computers cover?
This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.
When does this patent expire?
This patent is expected to expire on September 15, 2046, when the invention enters the public domain.
What problem does this patent solve?
This technology matters because it allows for more discreet and efficient cybersecurity investigations. By operating "in memory" and avoiding disk writes, the system makes it harder for sophisticated attackers to detect and tamper with the evidence collection process. The integrated agent and cloud-based analysis, including natural language queries, streamline the process of understanding complex security incidents, helping organizations respond faster to threats.
What does this patent NOT cover?
Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
Patent monitoring




