Skip to content
PatentBrief
Get alertsTop ↑

How to Secretly Collect Digital Evidence from Computers

This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.

Granted 2026ActiveExpires 2044

Original patent title: “Remote operations forensics”

Plain-English explanation by SahiLast reviewed · October 5, 2026

This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis. Granted in 2026.

Coverage

What does this patent actually cover?

The patent describes a system for monitoring computers and collecting digital evidence, called "forensic artifacts." It uses a single software program, or "agent," installed on the target computer, known as an "endpoint." This agent is designed to run entirely "in memory," meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or "chunked," prior to being sent to a "cloud server." This cloud server then organizes the data by "category," processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.

The gap

What does this patent NOT cover?

  • Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
  • Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.
  • Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.
  • Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.
  • Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts.

These exclusions are unique to PatentBrief — derived from the actual claim language, not patent-office boilerplate.

Key facts

Patent numberUS 12739263
StatusActive
FieldSoftware & Internet
Filed2024
Granted2026
Times cited0
LitigationNone on record
Value · $17K–$54KMinimal

What made this novel

The truly clever part is the "in memory" operation of the agent, which allows it to collect sensitive "forensic artifacts" and monitoring data without leaving persistent traces on the target computer's disk. This stealthy approach significantly reduces the risk of detection and evidence tampering during an investigation.

Remote operations forensics(Primary claim)softwarecybersecuritycloud computingtelecommunications

Schematic visualization of the patent's claim structure. Hand-drawn diagrams in progress for each landmark patent.

Where you've seen this

Real-world examples

01

Endpoint Detection and Response (EDR) platforms

02

Incident response tools

03

Cloud-based security analytics services

04

Digital forensics software

Why it matters

The bigger picture

This technology matters because it allows for more discreet and efficient cybersecurity investigations. By operating "in memory" and avoiding disk writes, the system makes it harder for sophisticated attackers to detect and tamper with the evidence collection process. The integrated agent and cloud-based analysis, including natural language queries, streamline the process of understanding complex security incidents, helping organizations respond faster to threats.

Filed

August 28, 2024

Granted

September 15, 2026

Market context

Who's building on this

Companies in this space

Major cybersecurity companies like CrowdStrike, SentinelOne, and Microsoft (with Defender for Endpoint) are actively developing and deploying advanced endpoint monitoring and forensic collection capabilities. Cloud security providers such as Amazon Web Services and Google Cloud also offer services that integrate similar analytics and natural language processing for security data.

Market impact

This type of technology has significantly improved the speed and effectiveness of incident response in the cybersecurity market. It has enabled security teams to conduct more thorough and stealthy investigations, reducing the dwell time of attackers within networks. The integration of cloud-based analysis and natural language queries has also made complex security data more accessible and actionable for a wider range of security professionals.

Claim 1 — Plain English

What this patent covers

The patent describes a system for monitoring computers and collecting digital evidence, called "forensic artifacts." It uses a single software program, or "agent," installed on the target computer, known as an "endpoint." This agent is designed to run entirely "in memory," meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or "chunked," prior to being sent to a "cloud server." This cloud server then organizes the data by "category," processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.

The clever bit

The truly clever part is the "in memory" operation of the agent, which allows it to collect sensitive "forensic artifacts" and monitoring data without leaving persistent traces on the target computer's disk. This stealthy approach significantly reduces the risk of detection and evidence tampering during an investigation.

What it does not cover

  • Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.
  • Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.
  • Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.
  • Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.
  • Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts.

Patent timeline

Filing

Application submitted to the patent office

Grant

Patent officially issued

PatentBrief Score

Impact Score

Early stage

Citation count

0/40

No citations yet

Claim breadth

0/20

Narrow claimsclaimsThe numbered statements at the end of a patent that legally define what the inventor owns.Read more →

Recency

20/20

Granted within 5 years

Assignee scale

0/20

Independent or smaller assigneeassigneeThe entity that owns the patent — usually the inventor's employer or a company.Read more →

PatentBrief Impact Score — based on citation count, claim breadth, recency, and assignee scale. Not a legal assessment.

Heuristic Value Estimate

What this patent might be worth

Minimal

$17K – $54K

Midpoint $34K · 17.9 yr remaining · industry ×1.4

Adjust inputs →

Heuristic only — blends forward/backward citation counts, claim scope, time remaining, litigation history, and CPC-derived industry baseline. Real valuations need a professional appraisal.

Claim text not yet imported for this patent

Claim text not yet imported for this patent.

Concepts involved

ClaimPrior artNon-obviousnessNoveltySpecificationAssigneePatent term

Cite this patent

(2026). How to Secretly Collect Digital Evidence from Computers (U.S. Patent No. 12,739,263). U.S. Patent and Trademark Office. https://patentbrief.org/patent/us/12739263/remote-operations-forensics

Auto-generated from the patent record. Double-check author order and the issue date against the official USPTO document before submitting.

Embed

Add this patent to your site

Drop this plain-English patent card into any blog post or article — free, no signup. It always links back to the full breakdown here.

<div data-patentlens-widget data-patent-number="US12739263"></div>
<script src="https://patentbrief.org/embed.js" async></script>

Stay in the loop

Get a weekly digest of new patents.

One email per week. No spam. Unsubscribe anytime.

Keep exploring

Related patents you should know

US 4683195 · 1987

How to Make Billions of Copies of a DNA Segment

This patent describes the Polymerase Chain Reaction (PCR), a method to rapidly create many copies of a specific piece of DNA or RNA, enabling its detection and analysis.

Cetus Corp

US 8697359 · 2014

How to Edit Genes in Human Cells Using an Engineered CRISPR System

This patent describes an engineered CRISPR-Cas9 system for precisely cutting DNA in eukaryotic cells to change how genes work, opening the door for gene editing in complex organisms.

Massachusetts Institute of Technology

US 7657849 · 2010

How the iPhone's Slide-to-Unlock Gesture Works

Apple's 2010 patent describes unlocking a device by dragging a specific graphical image across the touchscreen along a predefined path, a gesture that became iconic with the original iPhone.

Apple Inc

US 4733665 · 1988

How Doctors Implant a Permanent Stent Using a Balloon

This patent describes the method for placing a permanent, expandable wire mesh tube inside a blood vessel or other body tube using a balloon-tipped catheter to widen it and keep it open.

Expandable Grafts Partnership

US 4965188 · 1990

How to Make Many Copies of a DNA Piece with Heat

This patent describes the Polymerase Chain Reaction (PCR) method, a technique to make millions of copies of a specific DNA segment using a heat-resistant enzyme and repeated temperature changes.

Cetus Corp

US 4235871 · 1980

How to Encapsulate Active Materials in Lipid Bubbles Efficiently

This patent describes a method for trapping biologically active substances inside tiny, multi-layered fat bubbles called liposomes, using a specific water-in-oil emulsion and gel-forming process to improve how much material gets captured.

Individual

Semantically similar

You might also find these interesting

SEARCH ALL

More to explore

More in Software & Internet

Browse all Software & Internet

New to patents?

What is a patent?How to read a patentAnatomy of a claimHow strong is this patent?What the citations meanWhat it doesn't coverSoftware PatentsPatent glossary
Explore the landscape:software patents →cybersecurity patents →cloud computing patents →

Common Questions

Frequently Asked Questions

What does How to Secretly Collect Digital Evidence from Computers cover?

This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.

When does this patent expire?

This patent is expected to expire on September 15, 2046, when the invention enters the public domain.

What problem does this patent solve?

This technology matters because it allows for more discreet and efficient cybersecurity investigations. By operating "in memory" and avoiding disk writes, the system makes it harder for sophisticated attackers to detect and tamper with the evidence collection process. The integrated agent and cloud-based analysis, including natural language queries, streamline the process of understanding complex security incidents, helping organizations respond faster to threats.

What does this patent NOT cover?

Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.

Patent monitoring

Get notified when new matching patents are published

Get notified when this company files a new patent. Weekly digest · Confirm via email · Unsubscribe anytime.

Last reviewed: October 5, 2026 · PatentBrief is not a law firm and this is not legal advice.