DEVICE, SYSTEM, AND METHOD FOR UTILIZING A NETWORKED COMPUTER-ASSISTED THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY - Patent application

The integrated threat hunting platform addresses the inefficiencies of current SIEM tools by enabling real-time threat hunting and automated response across multiple networks, enhancing scalability and reducing costs for MSSPs.

JP7812491B2Active Publication Date: 2026-02-09BLUEVOYANT LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
JP2025501722
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-07-15
Filing Date
2023-07-14
Publication Date
2026-02-09
Estimated Expiration
2043-07-14

AI Technical Summary

Technical Problem

Current SIEM tools lack the ability to perform real-time threat hunting, are not scalable, and do not provide a unified threat hunting environment for MSSPs managing multiple tenant networks, leading to inefficiencies and increased costs due to the need for manual and multi-tool approaches.

Method used

A networked, computer-assisted integrated threat hunting platform that enables simultaneous querying of multiple tenant networks, automated response, and code development within a connected environment, supporting various programming languages and providing tools for threat detection and response.

Benefits of technology

Enables efficient, real-time threat hunting and response across multiple tenant networks, reducing operational costs and enhancing scalability by automating and standardizing threat detection and response processes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007812491000001
    Figure 0007812491000001
  • Figure 0007812491000002
    Figure 0007812491000002
  • Figure 0007812491000003
    Figure 0007812491000003
Patent Text Reader

Abstract

Disclosed herein are systems and methods for a threat hunting development environment. The systems and methods may include running a networked assisted threat hunting environment configured to: establish a data transfer pipeline between the threat hunting environment and at least one tenant network via a dedicated user interface, the data transfer pipeline maintaining a connection between the threat hunting environment and the at least one tenant network during an active session and enabling continuous data communication via at least one SIEM server; query the at least one tenant network with queries developed via an integrated code editor; receive query result data from the at least one tenant network; analyze the result data for detected threats in the at least one tenant network; and push subsequent queries to the at least one tenant network based on the analyzed result data to respond to the detected threats.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims the benefit of and priority to U.S. Provisional Patent Application No. 63 / 368,567, filed July 15, 2022, entitled "DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY," the disclosure of which is incorporated herein by reference in its entirety.

[0002] The present technology relates to systems and methods for a networked, connected, integrated security management environment. In particular, but not exclusively, the present technology provides a networked, computer-assisted, integrated threat hunting platform. Summary of the Invention [Means for solving the problem]

[0003] In some embodiments, the technology is directed to an assisted networked threat hunting detection and response system comprising: at least one SIEM server connected to at least one tenant network; and a SOAR management server connected to the SIEM server, the SOAR management server having at least one memory coupled to at least one processor, the memory loaded with instructions, the at least one processor running a threat hunting environment and coupled to the at least one memory configured to: establish a data transfer pipeline between the threat hunting environment and the at least one tenant network via a dedicated user interface, the data transfer pipeline maintaining a connection between the threat hunting environment and the at least one tenant network during an active session and enabling continuous data communication via the at least one SIEM server; receive query result data from the at least one tenant network to cause the at least one tenant network to query with queries developed via the integrated code editor; analyze the result data for detected threats in the at least one tenant network; and push subsequent queries to the at least one tenant network based on the analyzed result data to respond to the detected threats. In various embodiments, the threat hunting environment is further configured to save the query or subsequent queries for future use and reference. [Brief explanation of the drawings]

[0004] For purposes of explanation, but not limitation, specific details are set forth herein, such as particular embodiments, procedures, techniques, etc., to provide a thorough understanding of the present technology. However, it will be apparent to one skilled in the art that the present technology may be practiced in other embodiments that depart from these specific details.

[0005] The accompanying drawings, where like reference numbers refer to identical or functionally similar elements throughout the separate views, and together with the following detailed description, which are incorporated in and form a part of this specification, serve to further illustrate embodiments of the concepts comprising the claimed disclosure and to explain various principles and advantages of those embodiments.

[0006] The methods and systems disclosed herein are represented, where appropriate, by conventional symbols in the drawings, showing only those specific details relevant to an understanding of the embodiments of the present disclosure, so as not to obscure the disclosure with details that will be readily apparent to those skilled in the art having the benefit of the description herein.

[0007] [Figure 1] FIG. 1 illustrates a system configured to remotely manage another organization's security orchestration, automation, and response (SOAR) in accordance with at least one non-limiting aspect of the present disclosure. [Figure 2] FIG. 2 illustrates a functional architecture of the system of FIG. 1 in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 3] FIG. 3 illustrates a method for securing a tenant network via an integrated threat hunting environment in accordance with at least one non-limiting aspect of the present disclosure. [Figure 4A] FIG. 4A illustrates the relationships between various participants in an integrated threat hunting environment, in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 4B] FIG. 4B illustrates the relationships between various participants in an integrated threat hunting environment, in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 5] FIG. 5 illustrates a user interface (UI) configured for the inventors through the integrated threat hunting environment of FIG. 3 in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 6] FIG. 6 illustrates another UI of the integrated threat hunting environment of FIG. 3 in accordance with at least one non-limiting aspect of the present disclosure. [Figure 7]FIG. 7 illustrates a system diagram of a threat hunting environment and its various connecting networks and services, in accordance with at least one non-limiting embodiment of the present disclosure. [Figure 8A] FIG. 8A illustrates a method for dynamic exception handling (DEP) and how it may be incorporated by an integrated threat hunting environment, in accordance with at least one non-limiting aspect of the present disclosure. [Figure 8B] FIG. 8B illustrates a method for dynamic exception handling (DEP) and how it may be incorporated by an integrated threat hunting environment, according to at least one non-limiting aspect of the present disclosure. [Figure 9] FIG. 9 illustrates a system diagram of an integrated threat hunting environment in accordance with at least one non-limiting embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0008] The applicant of the present application owns the following US provisional patent applications, the disclosures of each of which are incorporated herein by reference in their entirety: - International Patent Application No. PCT / US2022 / 072739, filed June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS; - International Patent Application No. PCT / US2022 / 072743, filed June 3, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STANDARDIZING & STREAMLINING THE DEPLOYMENT OF SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS; - International Patent Application No. PCT / US2022 / 082167, filed December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR PROVISIONING AND UPDATING SECURITY INFORMATION & EVENT MANAGEMENT ARTIFACTS FOR MULTIPLE TENANTS; - International Patent Application No. PCT / US2022 / 082173, filed December 21, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR STREAMLINING AND STANDARDIZING THE INGEST OF SECURITY DATA ACROSS MULTIPLE TENANTS; - International Patent Application No. PCT / US2023 / 061069, filed January 23, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR REMOTELY MANAGING ANOTHER ORGANIZATION'S SECURITY ORCHESTRATION, AUTOMATION, AND RESPONSE; - International Patent Application No. PCT / US2023 / 062894, filed February 20, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTION BASED ON DOMAIN REDIRECTS. - International Patent Application No. PCT / US2023 / 021736, entitled DEVICES, SYSTEMS, AND METHODS FOR SUMMARIZING ANALYTIC OBSERVATIONS, filed May 10, 2023; - International Patent Application No. PCT / US2023 / 022858, filed May 19, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR INGESTING & ENRICHING SECURITY INFORMATION TO AUTONOMOUSLY SECURE A PLURALITY OF TENANT NETWORKS; - International Patent Application No. PCT / US2023 / 022535, filed May 17, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR IDENTIFYING CYBER ASSETS AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON A DEMOCRATIC MATCHING ALGORITHM; - International Patent Application No. PCT / US2023 / 024386, entitled DEVICES, METHODS, AND SYSTEMS FOR GENERATING A HIGHLY-SCALABLE, EFFICIENT COMPOSITE RECORD INDEX, filed June 4, 2023; - International Patent Application No. PCT / US2023 / 068590, filed June 16, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR CATEGORIZING, PRIORITIZING, AND MITIGATING CYBER SECURITY RISKS; - U.S. Provisional Patent Application No. 63 / 368,567, filed July 17, 2022, entitled DEVICES, SYSTEMS, AND METHODS FOR UTILIZING A NETWORKED, COMPUTER-ASSISTED, THREAT HUNTING PLATFORM TO ENHANCE NETWORK SECURITY; - U.S. Provisional Patent Application No. 63 / 369,582, filed July 27, 2022, entitled AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT; - U.S. Provisional Patent Application No. 63 / 377,304, entitled DEVICES, SYSTEMS, AND METHODS FOR CONTINUOUSLY ENHANCING THE IMPLEMENTATION OF CODE CHANGES VIA ENRICHED PIPELINES, filed September 27, 2022; - U.S. Provisional Patent Application No. 63 / 507,250, filed June 9, 2023, entitled DEVICES, SYSTEMS, AND METHODS FOR ATTRIBUTING NETWORK-IMPLEMENTED CYBER ASSETS TO OPERATING ENTITIES AND GENERATING CYBER RISK MITIGATION ACTIONS BASED ON THE ATTRIBUTION.

[0009] Numerous specific details are set forth in this disclosure to provide a thorough understanding of the overall structure, function, manufacture, and use of the embodiments described in the accompanying drawings. Well-known operations, components, and elements have not been described in detail so as not to obscure the embodiments described herein. The reader will understand that the embodiments described and illustrated herein are non-limiting embodiments. Accordingly, it will be understood that specific structural and functional details disclosed herein may be representative and exemplary. Changes and modifications can be made without departing from the scope of the claims. Furthermore, it should be understood that such terms as "front," "rear," "left," "right," "upper," "lower," and similar terms are terms of convenience and should not be construed as limiting terms.

[0010] In the following description, like reference numerals indicate like or corresponding parts throughout the several views of the drawings. Also, in the following description, it should be understood that such terms as "front," "rear," "left," "right," "upper," "lower," etc. are terms of convenience and should not be construed as terms of limitation.

[0011] Before describing in detail the various aspects of the systems and methods disclosed herein, it should be noted that the exemplary aspects are not limited in application or use to the details disclosed in the accompanying drawings and description. It should be understood that the exemplary aspects may be implemented or incorporated in other aspects, variations, and modifications, and may be practiced or carried out in various ways. Furthermore, unless otherwise indicated, the terms and phrases used herein have been chosen for the convenience of the reader to describe the exemplary aspects and are not intended to be limiting thereof. For example, it will be understood that any reference to a particular manufacturer, software suite, application, or development platform disclosed herein is intended merely to illustrate some of the many aspects of the present disclosure. This includes any trademark references. It should therefore be understood that the devices, systems, and methods disclosed herein can be implemented to enhance any software update according to any intended use and / or user preference.

[0012] As used herein, the term "server" may refer to or include one or more computing devices that operate through or facilitate communication and processing for multiple parties in a network environment, such as the Internet or any public or private network. As used herein, references to a "server" or "processor" may refer to previously enumerated servers and / or processors that are enumerated as performing the previous steps or functions, different servers and / or processors and / or combinations of servers and / or processors.

[0013] As used herein, the term "platform" is intended to include an ecosystem of software and / or physical resources necessary to enable the technical benefits provided by the software. For example, a platform may include either a standalone software product or a software product configured to integrate with other software or physical resources in the ecosystem necessary for the software to provide its technical benefits. According to some non-limiting aspects, the technical benefits provided by the software are provided to the physical resources of the ecosystem or to other software employed by the physical resources in the ecosystem (e.g., APIs, services, etc.). According to other non-limiting aspects, a platform may include a framework for several software applications intended and designed to function together.

[0014] As used herein, the term "network" refers to an entire enterprise information technology ("IT") system, and the term "tenant network" applies to a client of a managed security service provider (MSSP) for whom the MSSP provides security information and event management (SIEM) services. For example, a network may include a group of two or more nodes (e.g., devices) connected by any physical and / or wireless connection and configured to communicate and share information with one or more other nodes. However, the term network is not limited to any particular nodes or any particular means of connecting those nodes. A network may include any combination of devices (e.g., servers, databases, local or cloud storage, desktop computers, laptop computers, personal digital assistants, mobile phones, wearables, smart appliances, etc.) connected via Ethernet, intranet, and / or extranet and configured to communicate with each other via ad hoc connections (e.g., Bluetooth, near field communication (NFC), etc.), local area connections ("LANs"), wireless local area networks ("WLANs"), and / or virtual private networks ("VPNs"), regardless of the physical location of each device. The network may further include any tools, applications, and / or services deployed by the devices or otherwise utilized by the enterprise IT systems, such as firewalls, email clients, document management systems, office systems, etc. In some non-limiting aspects, the "network" may include third-party devices, applications, and / or services that are owned and controlled by a third party, but that the tenant is authorized to access the enterprise IT systems.

[0015] Security information and event management (SIEM) includes software configured to aggregate and analyze activity from many different resources across an information technology (IT) infrastructure. For example, a SIEM may be utilized by a SIEM service provider, also known as a managed security service provider (MSSP), to aggregate data (e.g., log data, event data, threat intelligence data, etc.) from multiple systems and analyze that data to detect anomalous behavior or potential cyberattacks. For example, a SIEM may collect security data from network devices, servers, domain controllers, etc. A SIEM may then store, normalize, aggregate, and apply analytics to that data to detect trends, detect threats, and enable an organization to investigate any alerts.

[0016] Commonly implemented SIEMs include Azure Sentinel and Splunk Cloud, Devo, LogRhythm, IBM's QRadar, Securonix, McAfee Enterprise Security Manager, LogPoint, Elastic Stack, ArcSight Enterprise Security Manager, and InsightIDR. Deploying Azure Sentinel as a cloud-based tool has gained widespread acceptance among managed security service providers (MSSPs), and as such, Azure Sentinel is described as a non-limiting example. However, other SIEMs are naturally contemplated by this disclosure. Like most SIEMs, deploying Azure Sentinel requires advanced skills, is time-consuming, and can be error-prone. Each organization needing a security solution has specific needs regarding ingest log sources, detection / alert rules, response automation, monitoring (e.g., reporting), and alerting. Microsoft (MSFT) is often used by MSSPs to manage multiple clients, but the complexity of initial configuration, deployment, and ongoing maintenance of artifacts (e.g., resource groups, log analysis workspaces, alert rules, workbooks, playbooks, etc.) increases significantly. This can result in high costs for both MSSPs, who must hire more expensive specialists, and their clients, who often bear at least part of the increased expenses. However, there is often overlap between some of the deployment needs of various clients. For example, many organizations may need similar firewall monitoring solutions. In these cases, asset reuse and redeployment (and updates) can lead to significant cost savings and operational simplification. Unfortunately, known SIEM tools are not technically capable of taking advantage of these synergies.As a result, MSSPs have limited opportunities for reuse to capture efficiencies across multiple clients, from initial provisioning, data collection, analysis, and classification, to threat detection, to automating incident response. This necessitates the issuance of improved devices, systems, and implementation methods, as well as SIEM client updates. These enhancements can improve the technical performance and cost efficiency of SIEMs, including the deployment of detection rules, visualizations, investigation workbooks, and ongoing maintenance.

[0017] The process of creating, testing, developing, protecting, processing, and executing security content designed to hunt malicious code is unique among other forms of code development. While the specific requirements of threat hunters are similar, they differ among developers. Therefore, while known SIEM tools and software offer excellent functionality, including event monitoring, data collection, and issuing security alerts across the network, current SIEM tools do not provide the ability to perform threat hunting in real time. MSSPs provide all the service capabilities necessary to protect tenant networks, including the proactive ability to respond to threats and changes in client databases in a timely and efficient manner. The more tenants an MSSP must protect, the more difficult its job becomes, and the less useful its current SIEM tools become. Furthermore, MSSPs must perform threat hunting services and provide security for multiple tenants, each of which may use different SIEM tools. For example, an MSSP may access one client database and run a SIEM tool associated with that client, such as Azure Sentinel or Splunk Cloud, which then receives the results of security queries. The MSSP then has to run the same query separately for different clients, only this time using one SIEM tool, such as Azure Sentinel, to receive the results and then run the query against another tenant network. While this process is manageable for a small number of clients, the number of queries, the different SIEMs or tools applicable to each client, and the differences in databases makes it neither scalable nor efficient across a large number of clients.

[0018] Additionally, there is no uniform feature set offered by current SIEM tools that are primarily designed and targeted for threat detection and response, and current tools also lack automation or continuous monitoring and response capabilities, nor the integration of services and microservices into a unified threat hunting environment that would provide these capabilities for MSSPs. Current SIEMs also lack other capabilities, including logging analysis, issuing simultaneous high-volume queries to numerous tenant networks and databases, and / or actively interfacing between different microservices directly via tool integration into a unified threat hunting environment, including the ability to simultaneously query various SIEM endpoints, add tickets, track workflows, and more.

[0019] Another issue is the requirement that the threat hunting environment be able to handle extreme amounts of data; at the same time, while traditional development environments run on the local machine and are based on text running on the local system, threat hunting environments execute queries, responses and other forms of programs and code on downstream tenant networks and databases, thus processing millions of lines of code generated from queries in real time and effectively processing that code to create solutions so that the threat hunter or security analyst can perform their job.

[0020] Additionally, security content developers and threat hunters have specific needs that are largely unmet by current solutions. IDE options, while numerous among today's software solutions, do not offer the specific tooling, extensions, or connectivity required to deter malicious behavior. The result is often a multi-tool approach that falls short of the scope threat hunters need, while also requiring significant cost, time, and management overhead to operate. Hunters are forced to keep track of multiple query languages, authentication protocols, tool instructions, functions, methods, variables, reports, visualization techniques, APIs, quotas, document sets, graph sets, indicators of compromise, and more. While these management tasks are relatively necessary across any single product, their execution tends to vary from product to product. Multi-product security environments allow organizations and individuals to use multiple products to achieve peak security, which means that in addition to the items mentioned above, hunters must also learn product-specific language, nicknames, threat vectors, updates, and features. All of this adds to the hunter's primary task: finding threats, each with its own unique list of threats requiring significant attention.

[0021] Therefore, there is a need for devices, systems, and methods that employ an automated "as a service" approach to generate and deploy a reusable, pre-packaged solution that can be executed in a single step while providing a complete end-to-end SIEM solution. Such devices, systems, and methods can deploy Sentinel or other SIEM implementations via a dedicated environment. Thus, such devices, systems, and methods can be used to consistently and repeatedly scale cloud-based SIEM implementations.

[0022] Finally, MSSP operations, including threat hunting, require a connected environment capable of forming a simultaneous network pipeline to various servers, services, and SIEMs, and / or directly or indirectly connecting to tenant networks, including client databases and servers. Accordingly, the present disclosure presents a threat hunting environment in which MSSP security analysts and engineers can develop code and responses in a networked, integrated development environment that delivers immediate results through live connections. While many of these responses and queries can be automated, continuous, and autonomous, others may allow for human intervention in real time. A unique set of tools within this environment is provided herein to enable technicians, analysts, and engineers to develop and source programs, code, and snippets as they respond to threats in real time. The integrated, assisted, and networked threat hunting environment presented herein provides an integrated solution that enables MSSPs and other security service providers to efficiently respond to detected threats in real time, leveraging connected services while deploying autonomous and automated responses and queries as needed. The solution disclosed herein is referred to as a "threat hunting environment" or "platform."

[0023] The current solution provides a system and method for a networked, computer-assisted, integrated threat hunting environment and toolkit created for developing and testing security content and threat hunting across computable databases, tenant networks, or other sources accessible via internal or external networks. The solution presented herein provides the functionality necessary for authentication, querying and detecting threats within tenant networks, prioritizing and filtering results, and automated or manual creation of code by security engineers and analysts and pushing instructions to the SIEM and tenant networks. The integrated environment provides tools that enable users to prioritize threats and tools, allowing them to develop SIEM content and code through an integrated, connected threat hunting environment by creating analysis rules that can be executed across multiple customers. These rules can execute and retrieve results, generate alerts for security analysts, run sample queries, and analyze results through the integrated threat hunting environment. The solution also allows users to keep notes and save historical data, snippets of code, and programs for later use.

[0024] The present disclosure also provides a connected threat hunting environment in which tenant networks can be connected to the environment and queried and interacted with directly or indirectly through a SIEM or other service. The present disclosure also enables a complete coding toolbox to be executed within the environment, with instructions immediately deployed as written and pushed out to one or more tenant networks via a SIEM or other service. Thus, the techniques presented herein can execute written instructions and code on downstream databases using a threat hunting environment running on a local machine or a SOAR management server, allowing engineers to deploy solutions and updates to downstream tenant networks at a wide scale. The present disclosure also provides the ability to write programs and code in a variety of languages, including traditional object-oriented languages ​​like Java, functional languages ​​like Python, and definition languages, as well as several other languages ​​including JavaScript, Ruby, Typescript, NodeJS, ElectronJS, RUST, WASM, C#, Dart, and Flutter, as well as supporting writing code in SQL and query languages ​​specifically designed for one or more SIEM programs, such as Splunk's query language and Cousto for Microsoft Sentinel. The threat hunting environment also enables syntax highlighting and suggestions, and auto-complete functionality when writing in these languages. The present disclosure also provides functionality to ensure efficient processing of large amounts of data retrieved from multiple tenant networks, and provides techniques to organize and paginate queries and results returned from queries to ensure the environment can manage large data loads while also being able to act on and respond to them.

[0025] While the present technology is susceptible to embodiment in many different forms, several specific embodiments are illustrated in the drawings and will be described in detail herein, with the understanding that the present disclosure is to be considered as an exemplification of the principles of the technology and is not intended to limit the technology to the illustrated embodiments.

[0026] Referring now to FIG. 1 , a block diagram of a system 1000 configured to remotely manage security orchestration, automation, and response (SOAR) for another organization is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to the non-limiting aspect of FIG. 1 , the system 1000 may include a SOAR management server 1002, as further discussed with reference to FIG. 2 , comprising a memory 1006 configured to store a SOAR application (see FIG. 2 ) and a processor 1004 configured to execute the stored SOAR application (see FIG. 2 ). For example, the SOAR management server 1002 may be a computing resource owned or leased by a managed security service provider (“MSSP”). The SOAR management server 1002 may be communicatively coupled to multiple tenants 1010 a, 1010 b, through 1010 n via a network 1008. Each of the multiple tenants 1010 1, 1010 2, ... 1010 n may represent a customer (e.g., an organization) contracted with the MSSP. 1, the network 1008 may include any of a variety of wired, long-range wireless, and / or short-range wireless networks. For example, the network 1008 may include an internal network, a local area network (LAN), Wi-Fi, a cellular network, a near-field communication (NFC), etc.

[0027] 1 , each of the multiple tenants 10101, 10102, ... 1010n can host one or more instances of one or more clients 1012, 1014, 1016. For example, a first tenant 10101 may include one or more machines running one or more client applications 10121, 10122, ... 1012n, a second tenant 10102 may include one or more machines running one or more client applications 10141, 10142, ... 1014n, and / or a third tenant 1010n may include one or more machines running one or more client applications 10161, 10162, ... 1016n. Each tenant 10101, 10102, and 1010n may include an intranet with each machine running a client application. For example, each tenant 10101, 10102, and 1010n may each represent a customer, such as an organization that has contracted with an MSSP for security services.

[0028] Thus, the SOAR management server 1002 can be configured to have oversight of each of multiple tenants 10101, 10102, and 1010n, and thus is responsible for monitoring and managing each client application 1012, 1014, 1016 against threats. As previously discussed, differences and complexities in tenant 10101, 10102, and 1010n architectures can make this complicated and inefficient for MSSPs. Thus, known SOAR tools can leave tenants 10101, 10102, and 1010n technically exposed and therefore vulnerable to attacks. According to non-limiting aspects of the present disclosure, the SOAR management server 1002 can execute a SOAR management application (see FIG. 2 ) that addresses these deficiencies technically and practically by enhancing the SOAR management server's 1002's management capabilities for multiple tenants, sending alerts, and updating client applications based on correlated and synergistic development needs. Additionally, architecture 2000 of FIG. 2 further illustrates different means of communication between various modules.

[0029] Referring now to FIG. 2, a block diagram of a functional architecture 2000 of the system 1000 of FIG. 1 is illustrated in accordance with at least one non-limiting aspect of the present disclosure. According to the non-limiting aspect of FIG. 2, the architecture 2000 may include a content library 2002, a variable store 2004, an automation scheme 2008, and a service operation engine 2012, collectively provided via applications stored in the memory 1006 (FIG. 1) of the SOAR management server 1002. According to some non-limiting aspects, the SOAR management server 1002 may be located remotely relative to the MSSP and / or tenant 1010n. For example, the SOAR management server 1002 may be cloud-based. When executed by the processor 1004 (FIG. 1), the application's content library 2002, variable store 2004, automation scheme 2008, and service operation engine 2012 can collectively facilitate the simultaneous configuration, management, and / or control of multiple SOAR platforms 2018 for multiple tenants 1010n, or client organizations, at scale. Additionally, when executed by the processor 1004 (FIG. 1), the application can support the client organization's SOAR platform 2018, either abstractly or dynamically, as described in further detail herein.

[0030] According to certain non-limiting aspects, the application deployed by the SOAR management server 1002 may be configured as an Azure Sentinel Automation Portal (ASAP), such as that disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed June 3, 2021, and entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," the disclosure of which is incorporated herein by reference in its entirety. For example, according to one non-limiting aspect, the ASAP portal runtime software code may include server middleware responsible for processing content from the content library 2002, connections to the SOAR platform 2018, and / or other services, and service requests for the SOAR management server 1002 to deploy, update, and / or read. In other words, the applications deployed by the SOAR management server 1002, including the content library 2002, variable store 2004, and automation scheme 2008, can provide a unified, simplified view of all tenant 10101-n (FIG. 1) deployments, along with the ability to work with one or more tenants 10101-n simultaneously.

[0031] The content library 2002 may be configured to store various artifacts (e.g., detections, automations, workbooks, alert rules, playbooks, etc.) that enable the SOAR management server 1002 to configure and manage the SOAR platform for one or more tenants 1010 n. According to some non-limiting aspects, the content library 2002 of FIG. 2 may be stored local to the application, meaning provided via the memory 1006 ( FIG. 1 ) of the SOAR management server 1002. However, according to other non-limiting aspects, the content library 2002 may be stored on a remote server communicatively coupled to the SOAR management server 1002. In yet another non-limiting aspect, the content library 2002 is provided by a third-party provider (e.g., GitHub, GitLab, etc.) similar to that disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed June 3, 2021, and entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," the disclosure of which is incorporated herein by reference in its entirety. In summary, the content library 2002, and more specifically, the artifacts stored within the content library 2002, control rules by which the SOAR management server 1002 can remotely interface with and / or manage the SOAR platform 2018 for a tenant 1010n, or client organization. For example, the content library 2002 may store one or more rules and / or templates configured to automate the deactivation of a user account if the SOAR management server 1002 and / or the SOAR platform 2018 determines that a determined risk score exceeds a predetermined threshold based on detected variables across the tenant architecture 1010n.

[0032] 2 , tenant 1010n requirements, such as variation points specific to a particular client organization and / or tenant 1010n architecture, can be provided in artifacts stored in content library 2002. Content library 2002 can accomplish this according to deployable artifact templates, such as those disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed June 3, 2021, and entitled “DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS,” the disclosure of which is incorporated herein by reference in its entirety. For example, content library 2002 can include “JSON” files for defining alert rules, workbooks, playbooks, etc. As new content is added to the content library 2002 or existing content is updated, the changes can be automatically pushed to the SOAR platform 2018 of tenant 1010 n via the SOAR management server 1002. In other words, once deployed, the SOAR management server 1002 can be configured for the unique SOAR needs of each tenant 10101-n ( FIG. 1 ), which vary based on each tenant's architecture.

[0033] The variable store 2004 can be configured to further customize the interface between the SOAR management server 1002 and the tenant 1010n, or client organization, architecture. For example, the variable store 2004 allows a user of the SOAR management server 1002, such as an MSSP, to define and / or link variables associated with the tenant 1010n architecture to various artifacts stored in the content library 2002 for detection by the SOAR management server 1002, thereby enhancing the SOAR management server 1002's ability to automate client-specific execution. According to some non-limiting aspects, variables can be stored using a primary key that uniquely indicates the destination environment. For example, when registering an environment to be managed, an MSSP or another user can indicate an administrator account associated with the environment so that content can be configured when it is deployed to the specific environment. Thus, deployed automations may need to be provided with which accounts are administrators to execute automations specific to those account roles.

[0034] The automation scheme 2008 can be configured to recognize commonalities among various tenant 10101-n (see FIG. 1 ) architectures and standardize the execution of the SOAR management server 1002. This represents a significant technological improvement over traditional SOAR management platforms that are configured to run for a single client organization or require significant manual labor to run across multiple tenants 10101-n or client organizations. For example, traditional SOAR platforms require assessment of a client's unique environment and needs, which necessitates the design and implementation of a custom solution. The automation scheme 2008 of FIG. 2, in conjunction with the content library 2002 and variable store 2004, enables the SOAR management server 1002 of FIGS. 1 and 2 to automatically generate customized SOAR solutions and scale such solutions across an unprecedented number of tenants 10101-n or client organizations simultaneously.

[0035] With further reference to FIG. 2 , an example of one such tenant 1010 n architecture is illustrated in accordance with at least one non-limiting aspect of the present disclosure. SOAR management server 1002 can be configured to detect variables associated with the tenant 1010 n architecture and to design and deploy tenant 1010 n -specific configurations, including one or more modules shown in FIG. 2 . For example, according to a non-limiting aspect of FIG. 2 , the tenant 1010 n architecture can include a remote SOAR platform 2018, a dashboard / reporting module 2022, and one or more security tool application program interfaces (“APIs”) 2020 a-d. Each security tool API 2020 a-d can be configured to prevent malicious attacks or misuse of the API by clients deployed in tenant 1010 n. Because APIs are key to programming web-based interactions, they are a target for hackers. Thus, the security tool APIs 2020a-d can monitor the client's APIs and send alerts 2030 back to the SOAR platform 2018 if a suspicious event is detected.

[0036] According to some non-limiting aspects, the dashboard / reports module 2022 may include a customizable visual representation of the cybersecurity of the tenant 1010n. For example, the dashboard / reports module 2022 may enable employees of the MSSP and / or client organization to view what is happening across the tenant 1010n network and, in response to detected threats, take corrective action to protect the network. This may enable the MSSP and / or client organization to identify, prevent, mitigate, and / or predict cybersecurity incidents in a significantly more efficient manner. Of course, the specific tenant 1010n architecture of FIG. 2 is presented solely for illustrative purposes. According to other non-limiting aspects, the tenant 1010n architecture designed and deployed by the SOAR management server 1002 may be alternatively configured to include alternative types and / or quantities of modules. The capabilities of the SOAR management server 1002, and more specifically the content library 2002, variable store 2004, and automation scheme 2008, enable customized SOAR-based solutions that can be remotely managed on behalf of tenants 1010n. Each solution differs depending on the variables discovered by the variable store 2004 as deployed by the SOAR management server 1002 and the artifacts selected from the content library 2002 based on the discovered variables.

[0037] 2 also illustrates different means of communication between various modules of the SOAR management server 1002 and one or more tenants 1010 n. For example, certain modules, such as the API broker 2006, may communicate with other modules, such as the service operation engine 2012, the graphical user interface 2010, the remote SOAR platform 2018, and the dashboard / reporting module 2022, via a service layer 2024. Other modules, such as the content library 2002, the variable store 2004, and the API broker 2006, may communicate with the remote SOAR platform 2018 of the tenant 1010 n via a management and content delivery layer 2026. The remote SOAR platform 2018 may communicate with one or more security tool APIs 2020 a-c of the tenant 1010 n via a SOAR communication protocol 2028. The one or more security tool APIs send alerts back to the remote SOAR platform 2018 via alert protocol 2030 according to rules defined by artifacts 2032 applied from content library 2002, as defined by variables from variable store 2004. The impact of artifacts selected from content library 2002 and variables detected from variable store 2004 on artifacts 2032 is indicated in FIG. 2 via corresponding cross-hatching. In other words, similar or identical protocols and / or methods may apply, but each communication vehicle may include different content. Thus, an end user can utilize architecture 2000 of FIG. 2 with or without a specific "Managed Detection and Response" (MDR) service. However, once delivered with a specific MDR service, the same APIs can be used by a specific MDR service user to interface with the APIs to manage architecture 2000 and take action on behalf of one or more tenants.

[0038] 2 , various modules of the SOAR management server 1002 architecture can be configured to communicate with, manage, and control the tenant 1010 n's remote SOAR platform 2018 according to specific artifacts 2032 from the content library 2002, which are autonomously selected variables associated with the tenant 1010 n, as determined by the variable store 2004 and / or previously stored. Thus, the content library 2002 and variable store 2004, in conjunction with the automation scheme 2008, can enable the SOAR management server 1002 to autonomously generate custom configurations for integrating with and remotely managing each tenant's 1010 n SOAR platform 2018. For example, the artifacts 2032 can define the means by which the API broker 2006 and service operation engine 2012 of the SOAR management server 1002 interface with the tenant 1010 n's remote SOAR platform 2018. Additionally, the artifact 2032 may further define content alerts 2030 and the conditions under which they are sent from one or more security tool APIs 2020a-d to the remote SOAR platform 2018.

[0039] The SOAR management server 1002, including the content library 2002, variable store 2004, and automation scheme 2008, can provide a powerful cloud-based tool that allows an MSSP to remotely manage a client organization's SOAR platform 2018. While the primary interface is the graphical user interface 2010, the API interface 2006 can further enable programmatic control of the SOAR platform 2018 management functions, allowing users to deploy content in the form of playbooks, automations, integrations, dashboards, and other SOAR forms that control code-based content to remote environments, such as tenants 1010n, through a central interface. Additionally, the content library 2002, variable store 2004, and automation scheme 2008 of the SOAR management server 1002 provide features that enable customization of that content, enabling bespoke deployments based on the specific needs of tenants 1010n. In other words, the SOAR management server 1002 can provide a modular and scalable way of referencing a stored library of code and content (e.g., content library 2002) so that options can be determined autonomously at deployment time.

[0040] For example, a user may deploy a set of artifacts stored in content library 2002, such as playbooks, code, integrations, and / or dashboards, that enable integration of next-generation antivirus (“NGAV”) products, email security products, and / or identity protection products and then automate the detection, investigation, and response stages based on controls received from the user via graphical user interface 2010. Additionally and / or alternatively, SOAR management server 1002 may enable a user to automate portions of a tenant's 1010n architecture or environment. Furthermore, graphical user interface 2010 may enable a user to “opt-in” and / or “opt-out” of automation features as presented by automation scheme 2008 via wizard-like tracing, walkthroughs, and application simplifications. A user may further customize report and / or dashboard functionality and preferences to be applied via dashboard / reports module 2022, which may be packaged for deployment along with automation content.

[0041] According to some non-limiting aspects, the application launched by the SOAR management server 1002 may be scalable, i.e., configured with the ability to expand or grow with respect to the number of tenants 1010n having the SOAR platform 2018 that can be remotely managed (e.g., scalability) and / or the number of SOAR management functions that it provides. In other words, the application, including the content library 2002, variable store 2004, and automation scheme 2008, may be designed to minimize the level of effort required to enable the SOAR management server 1002 to be extended for future use. For example, extensibility mechanisms provided by the application launched by the SOAR management server 1002, pluggable add-ons configured to enable additional service components and features of the SOAR management server 1002, may be introduced in the future.

[0042] According to some non-limiting aspects, the extension mechanism may be implemented in various ways to enable plugging in of additional SOAR service components. For example, authentication mechanisms such as DUO, Okta, among others, may be supported simultaneously. These authentication mechanisms may not be hard-coded, but configuration files may be discoverable (e.g., the main "config" file for each of the authentication mechanisms may be placed in a well-known repository location that is scanned for new or deleted files). If new configurations such as Azure AD are also supported, configuration files corresponding to Azure AD may be placed in the same repository location as the Duo and Okta configurations, discovered by the application management server, and presented to the user to select and configure from the client as needed. The configuration files may conform to a scheme defined and understood by this application management tool, and the user interface may be generated and auto-populated accordingly. Notably, the SOAR applications discussed herein are built in a way that is easily extended with additional configuration features that are not hard-coded in the source code but are dynamically plugged in through new configurations according to this method.

[0043] When a user deploys these add-ons via automation, they can trigger applications launched by the SOAR management server 1002 to enable additional subscription-based services on behalf of the MSSP and enhance security and health monitoring for the tenant 1010n. Additionally and / or alternatively, the applications deployed by the SOAR management server 1002 can be configured to work with existing "ungoverned" content, which may allow for discovery and light management of at least some of the prior SOAR assets already deployed by the tenant 1010n, instead of generating an entirely new, customized tenant 1010n architecture, as illustrated in FIG. 2.

[0044] As previously described, when executed by the processor 1004 (FIG. 1), the application may be configured to abstractly and / or dynamically manage a client organization's SOAR platform 2018. For example, in an abstract implementation, the SOAR management server 1002 may employ generically defined artifacts stored in a content library 2002, as disclosed in U.S. Provisional Patent Application No. 63 / 196,458, filed June 3, 2021, and entitled "DEVICES, SYSTEMS, AND METHODS FOR ENHANCING SECURITY INFORMATION & EVENT MANAGEMENT UPDATES FOR MULTIPLE TENANTS BASED ON CORRELATED, AND SYNERGISTIC DEPLOYMENT NEEDS," the disclosure of which is incorporated herein by reference in its entirety. The generically defined artifacts may include, for example, blocks of executable code. However, platform-specific implementations may subsequently be provided (e.g., Azure Defender, Crowdstrike, etc.). Summary automations / playbooks can be written in a general format and then translated into specific formats at deployment time. For example, an automation / playbook can be created that is specifically configured to disable a user's email account if their business email is compromised. However, upon actual implementation of that automation / playbook in a specific customer environment, the system 1000 (FIG. 1) and functional architecture 2000 (FIG. 2) disclosed herein can translate the generally written content into a version that is specifically implemented for the particular mail application used by the tenant. In this way, unlike conventional systems and architectures, content can be generated that can be programmatically adapted to multiple environments without rewriting it.Thus, the system 1000 (FIG. 1) and functional architecture 2000 (FIG. 2) disclosed herein provide a significant technical solution to the technical problems of traditional automation / playbooks: flexible formats and interfaces that allow users to extend services to multiple tenants and their authentication mechanisms.

[0045] Alternatively, in a dynamic implementation, the SOAR management server 1002, via the content library 2002, can dynamically generate new automation types, which can be automatically detected and displayed for selection by the graphical user interface 2010 for subsequent deployment. Similarly, a new automation, such as an endpoint monitoring solution (e.g., CarbonBlack), can be added to the content library 2002 for a given automation type, such as one that blocks the execution of harmful programs detected by the automation (e.g., block executable file automation), which in turn becomes automatically available in the GUI and can be deployed to appropriate client SOARs (which use these security tools).

[0046] Upon deployment via the SOAR management server 1002, tenant 1010n, or client, specific variation points can be detected by the variable store 2004 and correlated with artifacts stored in the content library 2002. For example, the SOAR management server 1002 has the ability to configure automated responses / corrective actions (e.g., playbooks) for a given configuration. These corrective actions may require optional steps, e.g., the tenant may first have to approve the action. Thus, configuring a remediation automation may involve similar configuration to the actual task (e.g., blocking an account), but the approval step may be done manually via phone, email, or workflow form (e.g., integration via a service ticket). In this way, the approval step may be variable (e.g., it may or may not be present, and if present, it may be accomplished in several ways) and require pulling the appropriate code and configuration from the automation repository to configure for this client and SOAR automation.

[0047] Thus, during deployment, variation points can be configured for tenant 1010n's specific SOAR needs based on tenant 1010n's network architecture. According to one non-limiting aspect, SOAR management server 1002 can automate SOAR platform 2018 to block user accounts upon detection of security events based on input received by security tool APIs 2020a-d. For example, the automation can include several steps or conditions, such as approval from tenant 1010n's administrative account. During deployment, for example, via a wizard presented via graphical user interface 2010, the automation can request the user to provide information associated with one or more administrative accounts for tenant 1010n (e.g., phone number, short message service (“SMS”) address, email address, etc.). Thus, specific steps and / or conditions, such as contact and / or prompting of action from administrative accounts, can be programmed into the automation via graphical user interface 2010.

[0048] According to one non-limiting aspect, when executing a custom automation, the SOAR management server 1002, and more specifically, the custom automation generated by the SOAR management server 1002, can manage the SOAR platform 2018 to detect a security event and determine that a user account needs to be blocked based on input / alerts received from one or more security tool APIs 2020a-d. The SOAR management server 1002 can manage the SOAR platform 2018 to notify the managed account, and the automation can wait for approval. Upon receiving approval, the automation can continue with subsequent steps, ultimately removing the suspicious account from the tenant 1010n network. As previously mentioned, this can be abstracted into automation types with specific implementations for each security tool API 2020a-d and / or notification method. Removing a suspicious account is just one example of an action the SOAR platform 2018 can take to enhance the security of the tenant 1010n network. For example, besides blocking accounts, the SOAR Platform 2018 can also delete suspicious files, email them to security administrators, among other measures.

[0049] Once deployed by the SOAR management server 1002, the artifacts 2032 (e.g., automation) may reside within the tenant 1010n architecture, and, depending on non-limiting aspects, the MSSP and / or client may modify the deployed configuration. For example, according to some non-limiting aspects, the client may desire to control the configuration deployed across the tenant 1010n network. However, according to other non-limiting aspects, the client may desire the MSSP to have exclusive control of the configuration. In either case, the applications deployed by the SOAR management server 1002 may be configured to automatically detect changes made by the MSSP and / or client and use them to manage future deployments and / or updates to already deployed artifacts 2032. According to some non-limiting aspects, these changes can be utilized by artificial intelligence stored in memory 1006 ( FIG. 1 ) of SOAR management server 1002 to adapt one or more artifacts 2032 (e.g., templates, workflows, etc.) in content library 2002 for expanded deployment for similar clients and / or architectures. Thus, content library 2020, along with graphical user interface 2010 and API broker 2006, can act as a contribution mechanism that, when deployed by applications on SOAR management server 1002, can abstractly and / or dynamically discover updates to both content library 2002 and client SOAR platforms 2018. These updates can be collectively managed via SOAR management server 1002, which serves as a central console for system 1000 ( FIG. 1 ), enabling unprecedented scalability to manage a large number of clients. In this manner, SOAR management server 1002 can reliably and consistently remotely manage different client SOAR platforms 2018.Its modular design allows users and third-party applications to contribute new artifacts 2032 and / or update existing artifacts 2032, making it "future-proof" as third-party vendor solutions evolve.

[0050] FIG. 3 illustrates a diagram of a method for securing tenant networks via an integrated threat hunting environment. This method 100 for conducting threat hunting activities via the disclosed threat hunting environment first executes 105 on a local server or local computing device, then uses the executed environment to query 110 one or more tenant networks with instructions developed by an optimized threat hunting code editor. The core of the threat hunting development platform is a code editor specifically optimized for targeting threats, connected to downstream information sources via the optional assistance of an API gateway using API Runtime Decoration, Data Discovery for Search Optimization (also referred to herein as “DDSO”), and Dynamic Exception Handling (also referred to herein as “DEP”). Queries are written by threat hunters, and the code editor searches and processes the information sources. The information sources are not limited to any provider and are therefore extensible to any service that provides interface capabilities. Examples of information providers include databases, SIEM systems, endpoint detection and response platforms, threat feeds, indicator lists, cloud platforms, static files, and user-defined libraries. Where consumable information exists, the platform strives to standardize, index, and expand its capabilities to meet the needs of hunters or developers. Hunters have the option to define specific target scopes or allow DDSO to dynamically select targets based on the query entered.

[0051] Because querying and processing multiple databases across a SIEM's network presents unique challenges, requests are pre-processed, aggregated, and fired across multiple network channels, including web APIs, local databases, and processed files. Errors are intelligently collected and displayed as received results,115 providing useful information to hunters and searched on the results layer. Multiple security products are searched in tandem, with de-duplication where applicable and preferred. Authentication is requested and delegated only when necessary, with stateless architectures and edge processing preferred where possible.

[0052] Results are designed to be moldable and exportable, meeting the needs of hunters. Post-processing techniques are developed to enhance and simplify where possible. Next steps, such as SOAR automation and ticket creation, are built into the environment, including search and threat data context at the time of submission. Storing and processing millions of table results per user requires special care to maintain a user-friendly experience. Aggregating authentication solutions requires additional attention to prioritize stateless design and security.

[0053] The received results generate a large amount of loggable data, which may occur naturally on the platform; logging of received or generated result data may also occur on individual APIs. The results may then be statistically analyzed 120. The automated analysis includes determining threat levels, analyzing threat indicators, and generating threat score levels and scores to prioritize the threats the analysis can detect and identify. One example of such analysis is disclosed in U.S. Provisional Patent Application No. 63 / 369,582, entitled AUTONOMOUS THREAT SCORING AND SECURITY ENHANCEMENT, Attorney Docket No. 220102P, filed July 27, 2023, the disclosure of which is incorporated herein by reference in its entirety. Because threat hunting is a cycle rather than a linear pipeline, there is no expectation of a required start-to-end user action; rather, the tools are designed to be usable and configurable at any point in the threat hunting process. Accordingly, subsequent instructions may be pushed 125 to tenant networks responding to detected threats.

[0054] FIG. 4 illustrates a diagram of the relationships between an MSSP-controlled computer system, which may be SOAR management server 450, corresponding to SOAR management server 1002, as disclosed in FIG. 1. All steps provided herein, as well as the systems described, are optional and may occur in any order. The order of steps is not limited to the embodiment presented in FIG. 4; steps may occur in any order or combination desired. Threat hunting system 400 illustrates the relationships between different parts of system 400 and the interactions between SOAR management server 450, SIEM / services 460, and tenant network 470. In the illustrated embodiment of environment 400, a threat hunting integration environment executes 401 on SOAR management server 450, which, in various embodiments, is or includes a local computing device. When users run the threat hunting environment, their credentials and access level must be authenticated in relation to both or one of SIEM / services 460 and / or tenant network 470. One or more of SIEM / service 460 and / or tenant network 470 receive authentication requests 403 and 405. In various embodiments, the authentication request is transmitted 404 via SIEM / service 460 to tenant network 470.

[0055] SIEM / service 460 and / or tenant network 470 may authenticate 406, 407 a user, a computing device running a threat hunting environment, or SOAR management server 450, which may receive authentication and form a connection or send a connection request to one or more tenant networks via SIEM / service 460, which may form one or more pipelines or connections to one or more tenant networks 470. In various embodiments, these connections are kept open by ensuring that HTTP requests remain running throughout the entire session, not just for a single request, call, or query. This ensures that connections to endpoints within tenant network 470 enable continuous communication between SOAR management server 450 and / or SIEM / service 460 and itself 470. This is because a standard request or HTTP call generally initiates a connection, performs a query or request, and then terminates the connection; therefore, a lot of overhead is used when several connections must be repeatedly created and terminated to enable the flow of data and communication between tenant network 470 and SOAR management server 450 and / or SIEM 460. This solution overcomes the unnecessary overhead of forming numerous PCP handshakes. Of course, the connections made herein may include multiple connections from SOAR management server 450 and the threat hunting environment it runs, as well as multiple connections to various SIEMs / services 460 and / or direct connections to tenant networks 470 as needed. A typical workflow may include SOAR management server 450 connecting with GitLab, Azure Sentinel, Windows Defender, and Jira. Client-facing SIEMs such as Sentinel and Windows Defender may then also maintain connections to multiple tenant networks 470, all of which are controllable by the disclosed threat hunting environment running on SOAR management server 450.

[0056] The threat hunting environment includes a code editor that allows queries to be written in any of the languages ​​of the SIEM software 460 and can automatically change the language in the user interface based on which SIEM the user is interacting with in the threat hunting environment of the SOAR management server 450. The code editor may also include syntax highlighting, auto-completion of functions, and allow users to load languages ​​and settings in a customized manner. For example, language packages for specific tenant networks 470 may be saved for later use, and multiple languages ​​applicable to each SIEM / service 460 may be selected or automatically applied as the user navigates through the user interface to different SIEMs / services 460 and tenant networks 470.

[0057] This threat hunting optimized code editor allows a user, threat hunter, or security analyst to write a query 412, which is then sent 413 to one or more tenant networks via one or more SIEMs / services 460. The user may select or define which SIEMS / services 460 or tenant networks 470 to target or include when executing the query. After the query is submitted, the dashboard may also allow the user to write or submit 414 new data, instructions, or code in real time and / or during runtime, either to further refine the instructions, adjust the query and / or its parameters based on preliminary results, or respond to detected threats or obtained results. In many embodiments, this may be performed autonomously without human involvement by the threat hunting environment.

[0058] In various embodiments, the threat hunting environment or platform running on the SOAR management server 450 enables live session sharing and recording, as well as code editing among members of the operator's security team. This allows security analysts and users of the threat hunting environment to respond to threats by editing each other's code and writing queries across different devices, the SIEM 460, and the tenant network 470. The code editor also includes linting, debugging, saving, and updating code functions. Linting is particularly important and is performed to optimize and fix code and, if necessary, reduce memory usage. Various SIEMs are limited in the number of code lines that can be deployed, making automated linting, code management, and optimization critical for the platform. The platform also relies on a performance-optimized code base that utilizes low-level programming to enable large-scale search query caching and indexing. Optimized code may include techniques such as metadata capture, where a list of tables is required, which could result in hundreds of thousands of product listings in a single JSON file for each client or tenant network, and where metadata is used to filter the captured and retrieved data, so that, for example, instead of retrieving the entire file, the platform retrieves only the table name, or specified column names of a table, which may be extracted from a data object that may include a JSON file or a dictionary.

[0059] Both the initial query and all subsequent queries and instructions may be pushed 416 to tenant networks 470. In some embodiments, SOAR management server 450 may autonomously add new data, filters, instructions, etc., in response to obtained results or during query execution time and for each result, processing and / or query execution. Queries may be executed on tenant networks 470, and results may be generated 418 and sent 419 to SOAR management server 450 or SIEM / service 460. In a preferred embodiment, SIEM / service 460 receives the results and then displays them on a threat hunting environment UI executing on SOAR management server 450. These results may be displayed 421 on one or more display panes on the threat hunting environment's user interface. The queries or instructions written in steps 413 and 414 may be subjected to a smart search function 422 by the threat hunting environment, and the query can automatically and autonomously determine which functions, queries, and tables apply to each tenant network. The smart search feature is comprised of threat hunting environment recognition features and lookup tables within a query, allowing the threat hunting environment to recognize and automatically remove tenant networks and SIEMS that are applicable to other SIEMs and tenant networks. Thus, instead of having hundreds or thousands of API calls each time a mass query is sent by the threat hunting environment to each client and then determining whether each tenant network or SIEM is relevant to the query, the smart search feature recognizes this in advance and, based on the features within the query and the tables the query depends on or calls, allows it to establish connections only to endpoints in tenant networks 470 or SIEMs / services 460 to which the query applies, and can also remove 423 any tenant networks 470 or SIEMS / services 460 from the query. This reduces system and network call overhead, computing costs, and memory usage.The smart search function may also display related clients or clients to which the query applies to the user on the SOAR management server end 450. The smart search function may also depend on the particular SIEM / service 460 and / or tenant network 470 involved in the query. For example, Azure Sentinel uses an API that has a list that is iterated by tenant networks, and the smart search function determines the intersections between different tenant networks 470 from these lists and which functions or tables are relevant to, should be connected to, or should not be connected to each tenant network.

[0060] Written or automated instructions, code, and queries may also be stored in a database or threat hunting environment by the user or by the SOAR management server 450. Code may be saved as snippets, i.e., small pieces of code that do not merit their own file but may be available to the user in a particular UI or UI pane. Code that returns results may also be flagged as such by the user or automatically by the system if the results produced are highly successful or efficient, and queries may be saved in the system.

[0061] Dynamic exception processing 425 may be applied to a specific tenant network 470 when a query is being executed based on the tenant network 470 being targeted. Dynamic exceptions are applied when there are unique needs or queries. For example, a command such as "return results excluding a list of whitelisted IP addresses." This request may be interpreted as relying on a global whitelist across all tenant networks, or alternatively, it may apply to a per-customer whitelist. Dynamic exception processing in a threat hunting environment can identify and translate requests at runtime by tailoring functionality to each client. Another example may be a request to "limit results to 10," which may mean displaying 10 results at a time, or 10 results per customer, or returning 10 results overall. DEP triggers may be based on previously saved rules for a specific tenant network 470, which may be stored in a database or file. The dynamic exception file or rules can be accessed at runtime to dynamically modify queries based on the rules for that specific tenant network 470. Specific client rules can be saved that are triggered or signal dynamic rule exception execution when a general query is executed. One way these can be applied is via predefined or configured IP addresses, which affects how a method or function is applied to one or more defined IP addresses.

[0062] Dynamic exceptions may also occur at a mass tenant network level, with numerous exceptions being executed as queries are initiated based on specific rules for each tenant network 470 that modify, adjust, or update the query according to the specific needs and requirements of the queried tenant network 470. This may be dynamic exceptions stored in any database or component of system 400. Dynamic exceptions may also be applied based on client or tenant network category, where special rules are triggered for tenant networks 470 that fall into a particular category, such as a security service contract, service, or agreement purchased by the client.

[0063] In various embodiments, API runtime decoration may be deployed 438. This occurs during query runtime or when pushing instructions to the tenant network, where, in real time, an API broker may be used to retrieve partial results, add metadata to the results, which may include data about what the search or query was, details about the threats and technologies the query or search targets, and then resume the query if it was paused or otherwise send the data added during runtime to a database in the tenant network. This may also be extended in various embodiments to adding new functionality, including adding metadata that adjusts the query based on partial results retrieved, where analysis is performed on the partial results and it becomes clear that changes or adjustments should be applied to the query to improve the results or target a specific threat. Runtime decoration may also be used to report information to a customer or add any type of instruction or metadata during query runtime. The runtime decoration may also include a pagination function, where a large JSON file is paginated in a browser or threat hunting environment / platform, automatically parsing the results and sending or only sending the data to a SOAR management server 450, SIEM 460, or tenant network 470 that is involved in or selected from the pagination process.

[0064] The threat hunting SIEM / service 460 receives any of the discussed queries from the SOAR management server 450, pushes 427 the queries to one or more tenant networks 470 that receive them 428, generates results, and can return partial results 430 or full results 431 based on the query results. The SIEM / service 460 receives the results 432, which can be displayed 43 on a UI on the SOAR management server 450. Responses to the received results can also be generated 434, which can be user-generated or automated by the threat hunting environment, and the responses are received by the SIEM / service 460 and pushed 436 onto one or more tenant networks to be executed 437 to respond to or neutralize detected threats.

[0065] 5 illustrates one embodiment of a user interface (UI) for an integrated threat hunting environment. The UI 500 includes a code editor section 501 where queries can be entered, edited, and executed, a results pane 502 that lists all results returned from the query, and may include information such as the client name, tenant ID, time generated, the threat display name, or execution of the query, and / or a list of results, detected threats, and / or threat classifications. The UI may also include a logging screen 503 that configures how alerts are generated or results are logged. Finally, the UI may include an error or threat alerts side pane 504 for viewing errors returned during or after execution time.

[0066] 6 shows another embodiment of a UI for an integrated threat hunting environment. The UI 600 includes a client view side pane 601 that lists all client / tenant networks and each of their workspaces or databases. The UI 600 also includes a code editing pane 602 and a results section 603 that displays the client name, tenant ID, time created, threat display name, or query execution and / or a list of results, detected threats, and / or threat classifications.

[0067] 7 shows a schematic diagram of the relationships 700 between a threat hunting environment 701 and the various networks and services to which it may connect. Because this is a connected and supported threat hunting development environment, it may be connected to various SIEMs 702, several tenant networks 703, and various services and microservices that support the threat hunting environment 701. The threat hunting environment 701 utilizes the functionality of the SIEMs 702 and services 704 to address threats and provide security services to the tenant networks 703. The platform 701 may be connected to any one or more of these 702, 703, and 704 simultaneously, as needed.

[0068] Figure 8 shows a diagram illustrating dynamic exception processing and how it is incorporated by the platform discussed herein. Queries are used on tenant networks via the SIEM to uncover malicious activity and threats. Once written and tested, each search query becomes a valuable asset and is used to recognize and diagnose attacks and malicious activity. Queries can be highly complex and must be tailored to new environments for precision. Dynamic exception processing modifies search query parameters at runtime. While traditional exception processing may require thousands of unique files, DEP only requires one. For example, a search query may attempt to identify a specific commuter virus with a specific name 801. To eliminate false positives, a folder, database, or location may be considered as part of the command and be an exception 802 to the rest of the search. Of course, this exception becomes problematic when managing security for hundreds of companies. This requirement forces security providers to create new queries for each client, effectively duplicating hundreds of attempts per rule to account for customer-specific data. As a solution to this obstacle, DEP stores a mutable list of exceptions 803 alongside the original query and creates a function that dynamically inserts the correct values ​​based on the tenant network or client being searched. The inserted values ​​can relate to relevant fields, whether it's a folder name, location, or ID number. When dynamic exception processing is performed, for example, as shown in Figure 4, the threat hunting environment takes a single file that stores the mutable list and isolates the query. When a query is performed against a target environment, the dynamic exception function is provided with data related to the target tenant network and performs its function based on this target / tenant network customization. This reduces network load, storage space, and management effort while improving the security and privacy of customer data.

[0069] FIG. 9 is a schematic diagram of an exemplary computing system 1 having a host machine 3000, within which a set of instructions may be executed to cause the machine to perform any one or more of the methodologies discussed herein. In various exemplary embodiments, the machine may operate as a standalone device or may be connected (e.g., networked) to other machines. In a network deployment, the host machine 3000 may operate in the capacity of a server or client machine in a server-client network environment, or as a peer machine in a peer-to-peer (or distributed) network environment. The host machine 3000 may be a personal computer (PC), tablet PC, set-top box (STB), personal digital assistant (PDA), mobile phone, portable music player (e.g., a portable hard drive audio device such as a Move Picture Experts Group Audio Layer 3 (MP3) player), web appliance, network router, switch, or bridge, or any machine capable of executing a set of instructions (sequential or otherwise) that specify actions to be taken by that machine. Furthermore, although only a single machine is illustrated, the term "machine" is also intended to include any collection of machines that individually or jointly execute a set (or sets) of instructions to implement any one or more of the methodologies discussed herein.

[0070] Exemplary computer system 1 includes a host machine 3000, which may be a computing device that executes a host operating system (OS) 3001 on a processor or multiple processors / processor cores 3003 (e.g., a central processing unit (CPU), a graphics processing unit (GPU), or both), and various memory nodes 3005. The host OS 3001 may include a hypervisor 3004 that can control the function of and / or communicate with virtual machines (VMs) 3010 running on machine-readable media. The VMs 3010 may also include virtual CPUs or vCPUs 3009. The memory nodes 3005 and 3007 may be linked or pinned to virtual memory nodes or vNodes 3006, respectively. When memory nodes 3005 are linked or pinned to corresponding virtual nodes 3006, data may be mapped directly from the memory nodes 3005 to their corresponding vNodes 3006.

[0071] All the different components shown in host machine 3000 may be connected to each other or may communicate with each other via a bus (not shown) or other coupling mechanism. Host machine 3000 may further include video display, audio devices, or other peripheral devices 3020 (e.g., a liquid crystal display (LCD), e.g., a keyboard, a cursor control device, e.g., a mouse, a voice recognition or biometric verification unit, an external drive, a signal generator, e.g., a speaker), an alphanumeric input device including persistent storage device 3002 (also called a disk drive unit), and a network interface device 3025. Host machine 3000 may further include a data encryption module (not shown) for encrypting data.

[0072] The components provided in host machine 3000 are components typically found in computer systems that may be suitable for use with embodiments of the present disclosure and are intended to represent broad categories of such computer components known in the art. Accordingly, computer system 1 may be a server, a minicomputer, a mainframe computer, or any other computer system. Computers may also include different bus configurations, network platforms, multiprocessor platforms, etc. A variety of operating systems may be used, including UNIX, LINUX, WINDOWS, QNX ANDROID, IOS, CHROME, TIZEN, and other suitable operating systems.

[0073] The disk drive unit 3002 may also be a solid state drive (SSD), hard disk drive (HDD), or otherwise, and includes a computer or machine-readable medium on which is stored one or more sets of instructions and data structures (e.g., data or instructions 3015) that embody or utilize any one or more of the methodologies or functions described herein. The instructions 3015 may also reside, completely or at least partially, within the main memory node 3005 and / or within the processor 3003 during its execution by the host machine 3000. The processor 3003, and the memory node 3005 may also include machine-readable media.

[0074] The instructions 3015 may further be transmitted or received over the network 3030 via the network interface device 3025 using any one of several well-known transfer protocols (e.g., Hypertext Transfer Protocol (HTTP)). The terms "computer-readable medium" or "machine-readable medium" should be taken to include a single medium or multiple media (e.g., centralized or distributed databases and / or associated caches and servers) that store one or more sets of instructions. The term "computer-readable medium" also refers to a medium that can store, encode, or carry a set of instructions for execution by a machine and cause the machine to perform any one or more of the methodologies of the present application. The term "computer-readable medium" should be taken to encompass any medium capable of storing, encoding, or carrying the data structures utilized by or associated with such a set of instructions. Accordingly, the term "computer-readable medium" includes, but is not limited to, solid-state memory, optical and magnetic media, and carrier wave signals. Such media may also include, but are not limited to, hard disks, floppy disks, flash memory cards, digital video disks, random access memory (RAM), read-only memory (ROM), etc. The exemplary embodiments described herein may be implemented in an operating environment including software, hardware, or a combination of software and hardware installed on a computer.

[0075] Those skilled in the art will recognize that an Internet service may be configured to provide Internet access to one or more computing devices coupled to the Internet service, and that the computing devices may include one or more processors, buses, memory devices, display devices, input / output devices, etc. Additionally, those skilled in the art will recognize that an Internet service may be coupled to one or more databases, repositories, servers, etc., which may be utilized to implement any of the embodiments of the present disclosure described herein.

[0076] The computer program instructions may also be loaded onto a computer, server, other programmable data processing device, or other device to cause the computer, other programmable device, or other device to perform a series of operational steps to generate a computer-implemented process, such that the software instructions executing on the computer or other programmable device provide a process for implementing the functions / acts specified in the flowchart and / or block diagram blocks.

[0077] Suitable networks may include or interface with, for example, one or more of a local intranet, a PAN (Personal Area Network), a LAN (Local Area Network), a WAN (Wide Area Network), a MAN (Metropolitan Area Network), a Virtual Private Network (VPN), a Storage Area Network (SAN), a Frame Relay connection, an Advanced Intelligent Network (AIN) connection, a Synchronous Optical Network (SONET) connection, a digital T1, T3, E1 or E3 line, a Digital Data Service (DDS) connection, a DSL (Digital Subscriber Line) connection, an Ethernet connection, an ISDN (Integrated Services Digital Network) line, a dial-up port such as V.90, a V.34 or V.34bis analog modem connection, a cable modem, an ATM (Asynchronous Transfer Mode) connection, or an FDDI (Fiber Distributed Data Interface) or CDDI (Copper Distributed Data Interface) connection. Additionally, communications may also include links to any of a variety of wireless networks, such as WAP (Wireless Application Protocol), GPRS (General Packet Radio Service), GSM (Global System for Mobile Communications), CDMA (Code Division Multiple Access) or TDMA (Time Division Multiple Access), cellular networks, GPS (Global Positioning System), CDPD (Cellular Digital Packet Data), RIM (Research in Motion, Limited) two-way paging networks, Bluetooth radio, or IEEE 802.11-based radio frequency networks. Network 3030 may further include or interface with any one or more of an RS-232 serial connection, an IEEE-1394 (Firewire) connection, a Fibre Channel connection, an IrDA (Infrared) port, a SCSI (Small Computer System Interface) connection, a USB (Universal Serial Bus) connection, or other wired or wireless, digital or analog interface or connection, mesh or Digi® networking.

[0078] In general, cloud-based computing environments are resources that typically combine the computing power of a large group of processors (such as in web servers) and / or the storage capacity of a large grouping of computer memory or storage devices. Systems that provide cloud-based resources may be used exclusively by their owners, or such systems may be accessible to external users to deploy applications within the computing infrastructure and take advantage of the large computing or storage resources.

[0079] A cloud is formed by a network of web servers, including multiple computing devices, such as, for example, host machines 3000, where each server 3035 (or at least a plurality of them) provides processor and / or storage resources. These servers manage the load provided by multiple users (e.g., customers or other users of the cloud resources). Typically, each user imposes workload demands on the cloud that change in real time, sometimes dramatically. The nature and extent of these fluctuations typically depend on the type of business associated with the user.

[0080] It is worth noting that any hardware platform suitable for carrying out the processes described herein is suitable for use with the technology. As used herein, the terms "computer-readable storage medium" and "computer-readable storage media" refer to any medium or media that participate in providing instructions to a CPU for execution. Such media can take many forms, including, but not limited to, non-volatile media, volatile media, and transmission media. Non-volatile media include, for example, optical or magnetic disks, such as fixed disks. Volatile media include dynamic memory, such as system RAM. Transmission media include coaxial cables, copper wire, and fiber optics, including the wires that comprise an embodiment of a bus, among others. Transmission media can also take the form of acoustic or light waves, such as those generated during radio frequency (RF) and infrared (IR) data communications. Common forms of computer-readable media include, for example, flexible disks, hard disks, magnetic tape, any other magnetic media, CD-ROM disks, digital video disks (DVDs), any other optical media, any other physical media with a pattern of marks or holes, RAM, PROM, EPROM, EEPROM, FLASHEPROM, any other memory chip or data exchange adapter, carrier wave, or any other medium from which a computer can read.

[0081] Various forms of computer-readable media may be involved in carrying one or more sequences of one or more instructions to the CPU for execution. A bus carries data to system RAM, from which the CPU retrieves and executes the instructions. The instructions received by the system RAM may optionally be stored on a fixed disk either before or after execution by the CPU.

[0082] Computer program code for carrying out operations of aspects of the present technology may be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, Smalltalk, C++, and conventional procedural programming languages ​​such as the "C" programming language, Go, Python, or other programming languages ​​including assembly language. The program code may run partially on the user's computer, partially on the user's computer as a standalone software package, partially on the user's computer, partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be to an external computer (e.g., via the Internet using an Internet Service Provider).

[0083] (Example clause) Various aspects of the subject matter described herein are set forth in the following numbered sections.

[0084] Clause 1: An assisted, networked threat hunting detection and response system, the system comprising: at least one SIEM server connected to at least one tenant network; and a SOAR management server connected to the SIEM server, the SOAR management server having at least one memory coupled to at least one processor, the memory loaded with instructions, the at least one processor coupled to the at least one memory executing a threat hunting environment via a dedicated user interface, the threat hunting environment being configured to: establish a data transfer pipeline between the threat hunting environment and the at least one tenant network, the data transfer pipeline maintaining a connection and enabling continuous data communication between the threat hunting environment and the at least one tenant network during an active session via the at least one SIEM server; query the at least one tenant network with queries developed via an integrated code editor; receive result data of the queries from the at least one tenant network; analyze the result data for detected threats in the at least one tenant network; and push subsequent queries to the at least one tenant network based on the analyzed result data to respond to the detected threats.

[0085] Clause 2: The system of clause 1, wherein the threat hunting environment is further configured to store the query or the subsequent query for future use and reference.

[0086] Clause 3: The system of clause 1, wherein the threat hunting environment is further configured to dynamically recognize functions and tables referenced by the query or the subsequent query to autonomously determine associated tenant networks or portions of tenant networks from the at least one tenant network, and to remove connection requests to endpoints that are not within the associated tenant network or portions of the tenant network from the query or the subsequent query.

[0087] Clause 4: The system described in Clause 1, wherein the threat hunting environment is further configured to apply dynamic exception handling to the query or the subsequent query, the dynamic exception handling including autonomously adjusting the query or the subsequent query for the at least one tenant network.

[0088] Clause 5: The system described in clause 4, wherein the dynamic exception handling is configured to autonomously create a function that dynamically inserts correct values ​​associated with the at least one tenant network from a stored mutable list.

[0089] Clause 6: The system of clause 5, wherein the dynamic exception handling further includes isolating the query or the subsequent query and performing the function on data associated with the at least one tenant network.

[0090] Clause 7: The system of clause 1, wherein the user interface enables the user to navigate between interfaces that display execution of the query or the subsequent queries running on the at least one SIEM server, the at least one tenant network, and the SOAR management server, or any combination thereof.

[0091] Clause 8: The system of clause 1, wherein the threat hunting environment is further configured to add enhanced data to the query or the subsequent query during execution time of the query or the subsequent query, wherein the data may modify functionality of the provided query or the subsequent query.

[0092] Clause 9: The system of clause 1, wherein adding the extension data includes pausing execution of the query or the subsequent query, autonomously adding data to the query or the subsequent query, and resuming the execution of the query or the subsequent query.

[0093] Clause 10: The system of clause 8, wherein the added data includes pagination instructions for returning only a specific subset of the results to the at least one SOAR management server.

[0094] Clause 11: The system of clause 1, wherein the user interface of the threat hunting environment includes a display of a history of results, and the history of results is interactive.

[0095] Clause 12: The system of clause 1, wherein the integrated code editor is networked, accessible, and usable by multiple connected users.

[0096] Clause 13: The system of clause 1, further comprising a networked microservice connected to the SOAR management server and accessible by the threat hunting environment.

[0097] Clause 14: A method for networked threat hunting, the method comprising: establishing a data forwarding pipeline between a threat hunting environment and at least one tenant network, wherein the data forwarding pipeline maintains a connection and enables continuous data communication between the threat hunting environment and the at least one tenant network during an active session via at least one SIEM server; querying the at least one tenant network with a query developed via an integrated code editor; receiving result data of the query from the at least one tenant network; analyzing the result data for detected threats in the at least one tenant network; and pushing a subsequent query to the at least one tenant network based on the analyzed result data to respond to the detected threats.

[0098] Clause 15: The method of clause 14, further comprising storing the query or the subsequent query for future use and reference.

[0099] Clause 16: The method of clause 14, further comprising: dynamically recognizing functions and tables referenced by the query or the subsequent query to autonomously determine an associated tenant network or portion of a tenant network from the at least one tenant network; and removing connection requests to endpoints that are not within the associated tenant network or portion of a tenant network from the query or the subsequent query.

[0100] Clause 17: The method of clause 14, further comprising applying dynamic exception handling to the query or the subsequent query, wherein the dynamic exception handling comprises autonomously adjusting the query or the subsequent query to the at least one tenant network.

[0101] Clause 18: The method of clause 17, wherein the dynamic exception handling includes autonomously creating a function that dynamically inserts correct values ​​associated with the at least one tenant network from a stored mutable list.

[0102] Clause 19: The method of clause 18, wherein the dynamic exception handling further includes isolating the query or the subsequent query and performing the function on data associated with the at least one tenant network.

[0103] Clause 20: A non-transitory computer-readable storage medium having a program embodied thereon, the program being executable by a processor to execute a method for providing a networked threat hunting environment to: establish a data transfer pipeline between the networked threat hunting environment and at least one tenant network, the data transfer pipeline maintaining a connection and enabling continuous data communication between the threat hunting environment and the at least one tenant network during an active session via at least one SIEM server; querying the at least one tenant network with queries developed via an integrated code editor; receiving result data of the queries from the at least one tenant network; analyzing the result data for detected threats in the at least one tenant network; and displaying the result data of the queries in a user interface of the threat hunting environment, the display of the result data including a history of similar results, and the history of similar results being interactive.

[0104] The foregoing detailed description includes references to the accompanying drawings, which form a part of the detailed description. The drawings illustrate diagrams of exemplary embodiments. These exemplary embodiments, also referred to herein as "examples," are described in sufficient detail to enable those skilled in the art to practice the present subject matter.

[0105] The various embodiments described above are presented by way of example only and not by way of limitation. The description is not intended to limit the scope of the present technology to the form described herein. On the contrary, the description is intended to cover alternatives, modifications, and equivalents as may be understood by those skilled in the art and included within the spirit and scope of the present technology. Thus, the breadth and scope of the preferred embodiment should not be limited by any of the above-described exemplary embodiments.

[0106] Although specific embodiments and examples of the system are described above for illustrative purposes, various equivalent modifications are possible within the scope of the system, as those skilled in the relevant art will recognize. For example, while processes or steps are presented in a given order, alternative embodiments may perform routines having steps in a different order, and some processes or steps may be deleted, moved, added, sub-divided, combined, and / or modified to provide alternative or sub-combinations. Each of these processes or steps may be implemented in a variety of different ways. Also, while processes or steps are sometimes shown as being performed in series, these processes or steps may instead be performed in parallel or at different times.

[0107] Embodiments may be combined, other embodiments may be utilized, and structural, logical, and electrical changes may be made without departing from the scope of the claims. It will be further understood by those skilled in the art that disjunctive words and / or phrases, whether in the description, claims, or drawings, typically presenting two or more alternative terms, should be understood to contemplate the possibility of including one of the terms, either one of the terms, or both terms, unless the context dictates otherwise. Therefore, the detailed description is not to be construed in a limiting sense, and the scope is defined by the appended claims and their equivalents. In this document, as is common in patent documents, the terms "a" or "an" are used to include one or more. In this document, the term "or" is used to refer to a non-exclusive "or," such that "A or B" includes "A but not B," "B but not A," and "A and B."

[0108] All patents, patent applications, publications, or other disclosure materials mentioned herein are incorporated herein by reference in their entirety, as if each individual reference were expressly incorporated by reference. All references and any material, or portions thereof, said to be incorporated herein by reference are incorporated herein only to the extent that the incorporated material does not contradict existing definitions, descriptions, or other disclosed material set forth in this disclosure. Therefore, and to the extent necessary, the present disclosure as set forth herein supersedes any conflicting material incorporated herein by reference, and this disclosure is expressly set forth within the control of this application.

[0109] Those skilled in the art will recognize that the terms used herein generally, and in the appended claims in particular (e.g., the body of the appended claims), are generally intended as "open-ended" terms (e.g., the term "including" should be interpreted as "including, but not limited to," the term "having" should be interpreted as "having at least," the term "includes" should be interpreted as "including, but not limited to," etc.). It will be further understood by those skilled in the art that where recitation of a specific number of introduced claims is intended, such intention will be expressly recited in the claim, and that in the absence of such recitation, no such intention exists. For example, as an aid to understanding, the following appended claims may include the use of the introductory phrases "at least one" and "one or more" to introduce the recitation of claims. However, the use of such phrases should not be construed as implying that the introduction of a claim recitation by the indefinite article "a" or "an" limits any particular claim that includes such an introduced claim recitation to claims containing only one such recitation, even when the same claim also includes the introductory phrase "one or more" or "at least one" and an indefinite article such as "a" or "an" (e.g., "a" and / or "an" should ordinarily be construed to mean "at least one" or "one or more").

[0110] Furthermore, even if a particular number of enumerations in an introduced claim are explicitly recited, those skilled in the art will recognize that such enumerations should typically be interpreted to mean at least the recited number (e.g., the mere enumeration of "two enumerations," without other modifiers, typically means at least two enumerations or more than two enumerations). Furthermore, in those instances where a convention similar to "at least one of A, B, and C, etc." is used, such construction is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, and C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.). In instances where a convention similar to "at least one of A, B, or C, etc." is used, such a structure is generally intended in the sense that one of ordinary skill in the art would understand the convention (e.g., "a system having at least one of A, B, or C" includes, but is not limited to, A alone, B alone, C alone, a system having A and B together, a system having A and C together, a system having B and C together, and / or a system having A, B, and C together, etc.).

[0111] With respect to the appended claims, those skilled in the art will understand that the actions recited therein may generally occur in any order. Also, while the claim recitations are presented sequentially, it should be understood that various actions may occur in other orders than those described, or may occur simultaneously. Examples of such alternative orders include overlapping, interleaved, interrupted, reordered, incremental, preparatory, supplemental, simultaneous, reverse, or other variant orders, unless the context dictates otherwise. Furthermore, unless the context dictates otherwise, terms such as "responsive," "related," or other past tense adjectives are generally not intended to exclude such variants.

[0112] It should be noted that any reference to "one aspect," "an embodiment," "one embodiment," "aspect," "example," "one example," and the like means that a particular feature, structure, or characteristic described in connection with an aspect is included in at least one aspect. Thus, the appearances of the phrases "in one aspect," "in an aspect," "in one example," and "in one example" in various places throughout this specification do not necessarily all refer to the same aspect. Furthermore, particular features, structures, or characteristics may be combined in any suitable manner in one or more aspects.

[0113] As used herein, the singular forms "a," "an," and "the" include plural references unless the context clearly dictates otherwise.

[0114] Directional terms used herein, such as, but not limited to, up, down, left, right, below, over, front, back, and variations thereof, relate to the orientation of the elements as shown in the accompanying drawings and are not intended to be limiting with respect to the claims, unless expressly stated otherwise.

[0115] As used in this disclosure, the term "about" or "approximately," unless otherwise specified, refers to an acceptable error for a particular value as determined by one of ordinary skill in the art, which depends in part on how the value is measured or determined. In certain embodiments, the term "about" or "approximately" means within 1, 2, 3, or 4 standard deviations. In certain embodiments, the term "about" or "approximately" means within 50%, 200%, 105%, 100%, 9%, 8%, 7%, 6%, 5%, 4%, 3%, 2%, 1%, 0.5%, or 0.05% of a given value or range.

[0116] As used herein, unless otherwise indicated, all numerical parameters are understood to be predicated and, in all instances, modified by the term "about" given the inherent variability characteristic of the underlying measurement technique used to determine the numerical value of that parameter. At the very least, and not as an attempt to limit the application of the doctrine of equivalents to the scope of the claims, each numerical parameter set forth herein should at least be construed in light of the number of reported significant digits and by applying ordinary rounding techniques.

[0117] Any numerical range recited herein includes all subranges subsumed within the recited range. For example, a range of "1 to 100" includes all subranges between (and including) the recited minimum value of 1 and the recited maximum value of 100, i.e., having a minimum value of 1 or greater and a maximum value of 100 or less. Also, all ranges recited herein include the recited endpoints. For example, a range of 1 to 100 includes the endpoints 1 and 100. Any maximum numerical limitation recited herein is intended to include all lower numerical limitations subsumed therein, and any minimum numerical limitation recited herein is intended to include all higher numerical limitations subsumed therein. Accordingly, applicants reserve the right to amend this specification, including the claims, to explicitly recite subranges subsumed within the explicitly recited ranges. All such ranges are inherently set forth herein.

[0118] The terms "comprise" (and any form of comprise, such as "comprises" or "comprising"), "have" (and any form of have, such as "has" and "having"), "include" (and any form of include, such as "includes" and "including"), and "contain" (and any form of contain, such as "contains" and "containing") are open-ended linking verbs. Consequently, a system that "comprises," "has," "includes," or "contains" one or more elements possesses those one or more elements, but is not limited to possessing only those one or more elements. Similarly, an element of a system, device, or apparatus that "comprises," "has," "includes," or "contains" one or more features possesses those one or more features, but is not limited to possessing only those one or more features.

[0119] The corresponding structure, material, acts, and equivalents of all means or step-plus-function elements in the following claims are intended to include any structure, material, or acts for performing a function in combination with other claimed elements as specifically claimed. The description of the present technology has been presented for purposes of illustration and description, but is not intended to be exhaustive or to limit the invention to the form disclosed. Many modifications and variations will be apparent to those skilled in the art without departing from the scope and spirit of the invention. The exemplary embodiments were chosen and described to best explain the principles of the technology and its practical application, and to enable those skilled in the art to understand the invention in various embodiments with various modifications suited to the particular uses contemplated.

Claims

1. 1. An assisted networked threat hunting detection and response system, comprising: at least one SIEM server connected to at least one tenant network; a SOAR management server connected to the SIEM server; the SOAR management server having at least one memory coupled to at least one processor; the memory is loaded with instructions; the at least one processor coupled to the at least one memory executes a threat hunting environment via a dedicated user interface; the threat hunting environment: establishing a data transfer pipeline between the threat hunting environment and the at least one tenant network, the data transfer pipeline maintaining a connection and enabling continuous data communication between the threat hunting environment and the at least one tenant network during an active session via the at least one SIEM server; Querying the at least one tenant network with a query developed via an integrated code editor; receiving result data of the query from the at least one tenant network; analyzing the resulting data for detected threats within the at least one tenant network; Pushing a subsequent query to the at least one tenant network based on the analyzed result data to respond to the detected threat; and applying dynamic exception handling to the query or the subsequent query, the dynamic exception handling comprising autonomously adjusting the query or the subsequent query to the at least one tenant network; A system that is configured to:

2. the threat hunting environment: The system of claim 1 , further configured to save the query or the subsequent query for future use and reference.

3. the threat hunting environment: dynamically recognizing functions and tables referenced by the query or the subsequent query to autonomously determine relevant tenant networks or portions of tenant networks from the at least one tenant network; filtering out connection requests to endpoints that are not within the associated tenant network or part of the tenant network from the query or subsequent queries; The system of claim 1 , further configured to:

4. The dynamic exception handling The system of claim 1 , configured to autonomously create a function that dynamically inserts correct values ​​associated with the at least one tenant network from a stored mutable list.

5. The dynamic exception handling separating the query or the subsequent query; The system of claim 4 , further comprising performing the function on data associated with the at least one tenant network.

6. 2. The system of claim 1, wherein the user interface allows a user to navigate between interfaces that display execution of the query or the subsequent queries running on the at least one SIEM server, the at least one tenant network, and the SOAR management server, or any combination thereof.

7. the threat hunting environment: adding extension data to the query or the subsequent query during runtime of the query or the subsequent query, the extension data being capable of modifying functionality of the provided query or the subsequent query; The system of claim 1 , further configured to:

8. adding the extension data pausing execution of said query or said subsequent query; autonomously adding data to the query or the subsequent query; resuming said execution of said query or a subsequent query; The system of claim 7 , further comprising:

9. 8. The system of claim 7, wherein the added extension data includes pagination instructions for returning only a particular subset of query results to the at least one SOAR management server.

10. The system of claim 1 , wherein the user interface of the threat hunting environment includes a display of a history of results, and the history of results is interactive.

11. The system of claim 1 , wherein the integrated code editor is networked, accessible, and usable by multiple connected users.

12. 10. The system of claim 1, further comprising a networked microservice connected to the SOAR management server and accessible by the threat hunting environment.

13. 1. A method for networked threat hunting, comprising: establishing a data transfer pipeline between the threat hunting environment and at least one tenant network, the data transfer pipeline maintaining a connection and enabling continuous data communication between the threat hunting environment and the at least one tenant network during an active session via at least one SIEM server; Querying the at least one tenant network with a query developed via an integrated code editor; receiving result data of the query from the at least one tenant network; analyzing the resulting data for detected threats within the at least one tenant network; Pushing a subsequent query to the at least one tenant network based on the analyzed result data to respond to the detected threat; and applying dynamic exception handling to the query or the subsequent query, the dynamic exception handling including autonomously adjusting the query or the subsequent query to the at least one tenant network; and A method comprising:

14. The dynamic exception handling 14. The method of claim 13, comprising autonomously creating a function that dynamically inserts correct values ​​associated with the at least one tenant network from a stored mutable list.

15. The dynamic exception handling separating the query or the subsequent query; performing the function on data associated with the at least one tenant network; 15. The method of claim 14, further comprising:

Citation Information

Patent Citations

  • System and method for network data characterization

    JP2018506808A

  • Providing secure data-replication between a master node and tenant nodes of a multi-tenancy architecture

    US20200259847A1

  • Attack analysis system, coordination device, attack analysis coordination method, and program

    WO2014112185A1