Endpoint Forensic Agent Memory-Only Artifact Collection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in efficiently investigating and responding to security incidents due to difficulties in collecting and analyzing data, particularly in preserving forensic artifacts and correlating endpoint monitoring data with forensic artifacts.

Innovation Solution

A computer-implemented method that involves an agent installed on an endpoint collecting endpoint monitoring data, transmitting it to a cloud server, and upon detecting a security incident, identifying and transmitting forensic artifacts to a destination server without writing to non-volatile storage, thereby preserving data integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Duration of action of stationary object

If forensic artifacts are collected and stored on non-volatile storage medium, then data persistence is improved, but data integrity is worsened due to risk of modification or loss

Engineering Contradiction:
Improvedata persistenceVSAvoiddata integrity
Core Design Contradiction:
Duration of action of stationary objectVSReliability

Solution Approach 1:

The patent extracts the forensic artifact data from the non-volatile storage medium and loads it into random access memory (RAM) for analysis. This separation allows the original forensic artifacts to remain preserved on storage while working copies are analyzed in memory, preventing modification of the original evidence during the investigation process.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system creates copies of forensic artifacts from non-volatile storage and loads them into random access memory for analysis. Multiple copies can be created and manipulated in memory without affecting the original forensic artifacts stored on the non-volatile medium, enabling thorough analysis while preserving evidence integrity.

Inventive Principle:
Principle #26Copying

2Loss of information

If comprehensive forensic artifact collection is performed, then investigation completeness is improved, but system performance is worsened due to memory constraints

Engineering Contradiction:
Improveinvestigation completenessVSAvoidsystem performance
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent segments the forensic artifact collection process by organizing artifacts into different categories and loading them into random access memory in manageable portions. This segmentation allows the system to handle comprehensive artifact collections without overwhelming memory resources, enabling complete investigation while maintaining system performance.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system loads forensic artifacts into random access memory as needed for specific analysis tasks rather than loading all artifacts simultaneously. This partial action approach allows comprehensive investigation capabilities while managing memory consumption efficiently by loading only the necessary artifacts for each analytical step.

Inventive Principle:
Principle #16Partial or excessive action

3Speed

If forensic analysis is performed on the endpoint device, then analysis speed is improved, but forensic artifact preservation is worsened due to potential contamination

Engineering Contradiction:
Improveanalysis speedVSAvoidforensic artifact preservation
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent uses random access memory as an intermediary between the non-volatile storage medium and the analysis processes. Forensic artifacts are loaded into RAM for analysis, allowing fast processing on the endpoint device while the original artifacts remain preserved on storage. The RAM acts as a temporary workspace that prevents direct contamination of the original evidence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20250080551A1Remote operations forensics
Publication Date: 2025.03.06 SENTINELONE INC
  • US20250080551A1 patent drawing
  • US20250080551A1 patent drawing
  • US20250080551A1 patent drawing

AI summary

The present disclosure is related to endpoint monitoring and forensic artifact collection. In some embodiments, forensic artifacts and endpoint monitoring data are collected on an endpoint using the same agent. In some embodiments, forensic artifacts are chunked prior to being transferred to a cloud server for analysis. In some embodiments, forensic artifacts are categorized and processed according to the category. In some embodiments, the agent operates in memory and does not write to disk. In some embodiments, the agent does not write to disk during the transfer of forensic artifacts to a cloud server. In some embodiments, a cloud server can enable natural language queries of monitoring data and/or forensic artifacts. In some embodiments, the cloud server provides summaries. In some embodiments, the cloud server identifies the most relevant data in monitoring data and/or forensic artifacts.