{
  "patent_number": "US 12739263",
  "country": "US",
  "title": "How to Secretly Collect Digital Evidence from Computers",
  "original_title": "Remote operations forensics",
  "summary": "This patent describes a system for secretly collecting digital evidence and monitoring activity from computers using a single software agent that runs only in memory and sends data to a cloud server for smart analysis.",
  "what_it_does": "The patent describes a system for monitoring computers and collecting digital evidence, called \"forensic artifacts.\" It uses a single software program, or \"agent,\" installed on the target computer, known as an \"endpoint.\" This agent is designed to run entirely \"in memory,\" meaning it avoids writing data to the computer's hard drive, making it harder to detect. The collected evidence is then broken into smaller pieces, or \"chunked,\" prior to being sent to a \"cloud server.\" This cloud server then organizes the data by \"category,\" processes it, and can even summarize it or highlight the most important parts. The cloud server also allows users to ask questions about the data using everyday language, like asking a search engine. For example, a company's security team could use this system to investigate a computer suspected of being hacked, collecting evidence without leaving traces on the disk that an attacker might find and remove.",
  "what_it_does_not_cover": [
    "Does not cover systems where separate software agents are used for monitoring and for collecting forensic evidence.",
    "Does not cover agents that primarily store collected forensic data on the local computer's hard drive before transfer.",
    "Does not cover transferring forensic artifacts to a cloud server without first breaking them into smaller chunks.",
    "Does not cover cloud analysis systems that only provide raw data without summaries or identification of relevant information.",
    "Does not cover systems that require complex, non-natural language commands to query monitoring data and forensic artifacts."
  ],
  "filed": "2024-08-28",
  "granted": "2026-09-15",
  "expires": null,
  "status": "active",
  "holder": null,
  "holder_url": null,
  "inventors": [],
  "times_cited": 0,
  "tags": [
    "software",
    "cybersecurity",
    "cloud_computing",
    "telecommunications"
  ],
  "abstract": "The present disclosure is related to endpoint monitoring and forensic artifact collection. In some embodiments, forensic artifacts and endpoint monitoring data are collected on an endpoint using the same agent. In some embodiments, forensic artifacts are chunked prior to being transferred to a cloud server for analysis. In some embodiments, forensic artifacts are categorized and processed according to the category. In some embodiments, the agent operates in memory and does not write to disk. In some embodiments, the agent does not write to disk during the transfer of forensic artifacts to a cloud server. In some embodiments, a cloud server can enable natural language queries of monitoring data and/or forensic artifacts. In some embodiments, the cloud server provides summaries. In some embodiments, the cloud server identifies the most relevant data in monitoring data and/or forensic artifacts.",
  "url": "https://patentbrief.org/patent/us/12739263/remote-operations-forensics",
  "markdown_url": "https://patentbrief.org/patent/us/12739263/remote-operations-forensics/md",
  "google_patents_url": "https://patents.google.com/patent/US12739263",
  "relatedPatents": [
    {
      "patentNumber": "12244567",
      "countryCode": "US",
      "title": "How to Monitor Secure Government Computer Networks Automatically",
      "url": "https://patentbrief.org/patent/us/12244567/spacex-philosophy"
    },
    {
      "patentNumber": "11876858",
      "countryCode": "US",
      "title": "Managing and Updating AI on Many Smart Devices from the Cloud",
      "url": "https://patentbrief.org/patent/us/11876858/cloud-based-fleet-and-asset-management-for-edge-computing-of-machine-learning-an"
    },
    {
      "patentNumber": "8112476",
      "countryCode": "US",
      "title": "How Software Automatically Collects and Organizes Data from Multiple Websites",
      "url": "https://patentbrief.org/patent/us/8112476/amazon-ec2-elastic-compute-cloud"
    },
    {
      "patentNumber": "9430664",
      "countryCode": "US",
      "title": "How Microsoft Protects Corporate Data on Employee Devices",
      "url": "https://patentbrief.org/patent/us/9430664/windows-defender-antivirus"
    },
    {
      "patentNumber": "12739267",
      "countryCode": "US",
      "title": "How a Single Command Deploys Cloud Infrastructure Automatically",
      "url": "https://patentbrief.org/patent/us/12739267/automated-cloud-infrastructure-deployment"
    }
  ]
}