Patents Assigned to BeyondTrust Corporation
  • Patent number: 12688279
    Abstract: Systems and methods are disclosed for event-based application control. A system extension is configured to leverage an endpoint security Application Programing Interface (API) for monitoring event activity within operating system kernel processes. The system extension registers with the endpoint security API particular event types for which the system extension would like to receive notifications. In response to receiving notifications regarding detected events corresponding to the registered event types, the system extension determines if the event, and its corresponding process, are safe and allowable to execute. In various embodiments, the system leverages whitelists, blacklists, and rules policies for making a safeness determination regarding the event notification. The system extension transmits this determination to the operating system via the endpoint security API.
    Type: Grant
    Filed: April 12, 2024
    Date of Patent: July 21, 2026
    Assignee: BeyondTrust Corporation
    Inventors: Omar Jawayd Ikram, Simon Fradkin
  • Patent number: 12603785
    Abstract: Systems and methods for root-level application selective configuration for managing performance of actions on files in a file system including an agent executed on a computing device. The agent can determine a plurality of files stored in a particular folder. The agent can receive a selection of a particular file of the plurality of files. The agent can determine whether to include an action for the particular file in a context menu based on a first policy determination. The agent can render the context menu comprising a plurality of menu entries. The plurality of menu entries can include an additional menu entry that corresponds to the action. The agent can determine whether to perform the action based on a second policy determination. The agent can cause the at least one action to be performed.
    Type: Grant
    Filed: February 26, 2024
    Date of Patent: April 14, 2026
    Assignee: BeyondTrust Corporation
    Inventors: Simon Fradkin, Steven Joruk
  • Patent number: 12500894
    Abstract: A privilege access management (PAM) appliance can receive an access request from an accessor device to access an endpoint device. The PAM appliance can establish a session via a secure connection between the accessor device and the endpoint device. The PAM appliance can transmit a request for credential information available for the accessor device to access the endpoint device from a credential management device. The credential management device can receive the request for credential information available for the accessor device to access the endpoint device. The credential management device can extract a set of credentials that are available for the accessor device from a plurality of credentials. The credential management device can provide at least one of the set of credentials to the endpoint device for the accessor device for the session.
    Type: Grant
    Filed: September 11, 2023
    Date of Patent: December 16, 2025
    Assignee: BeyondTrust Corporation
    Inventors: John Burns Smith, III, Nicholas Shawn Twerdochlib
  • Patent number: 12483592
    Abstract: The disclosed system includes privileged access management (PAM) appliance that facilitates establishing a session between an accessor device and an endpoint device. Generally, an access application can be pushed to the endpoint device. Once received, the endpoint device can automatically execute the access application. When executed, the access application can connect to the PAM appliance. The PAM appliance can establish the session between the accessor device and the endpoint device.
    Type: Grant
    Filed: July 8, 2019
    Date of Patent: November 25, 2025
    Assignee: BeyondTrust Corporation
    Inventors: Donald Warren Hasson, David William Durham, Dustin L. Majure
  • Patent number: 11863558
    Abstract: An approach is described for securely and automatically handling credentials when used for accessing endpoints, and/or applications and resources on the endpoints. The approach involves selecting and injecting credentials at an endpoint by an accessor to log into the endpoint, running applications or gaining access to resources on the endpoint, without full credential information traversing the accessor's machine.
    Type: Grant
    Filed: August 22, 2019
    Date of Patent: January 2, 2024
    Assignee: BeyondTrust Corporation
    Inventors: John Burns Smith, III, Nicholas Sawn Twerdochlib
  • Patent number: 10956559
    Abstract: An approach is described for securely and automatically handling credentials when used for accessing endpoints, and/or applications and resources on the endpoints, and more particularly accessing web endpoints and/or web applications and resources on the web endpoints. The approach involves selecting and injecting credentials at an endpoint by an accessor and/or protocol agent to log into the endpoint, running applications, or gaining access to resources on the endpoint, without full credential information traversing the accessor's machine.
    Type: Grant
    Filed: March 5, 2019
    Date of Patent: March 23, 2021
    Assignee: BEYONDTRUST CORPORATION
    Inventors: Rajesh Cherukuri, John Burns Smith, III, Nicholas Shawn Twerdochlib, Ricardo Fabiano De Andrade
  • Publication number: 20140020052
    Abstract: To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a process's token. The rule includes an application-criterion set and changes to be made to the groups and/or privileges of a token. The rule is set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers. When a GPO containing a rule is applied to a computer, a driver installed on the computer accesses the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.
    Type: Application
    Filed: September 11, 2013
    Publication date: January 16, 2014
    Applicant: BeyondTrust Corporation
    Inventor: Marco Peretti
  • Patent number: 8566586
    Abstract: To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a process's token. The rule includes an application-criterion set and changes to be made to the groups and/or privileges of a token. The rule is set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers. When a GPO containing a rule is applied to a computer, a driver installed on the computer accesses the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.
    Type: Grant
    Filed: August 10, 2011
    Date of Patent: October 22, 2013
    Assignee: BeyondTrust Corporation
    Inventor: Marco Peretti
  • Patent number: 8006088
    Abstract: To control privileges and access to resources on a per-process basis, an administrator creates a rule that may be applied to modify a process's token. The rule includes an application-criterion set and changes to be made to the groups and/or privileges of a token. The rule is set as a policy within a group policy object (GPO), where a GPO is associated with one or more groups of computers. When a GPO containing a rule is applied to a computer, a driver installed on the computer accesses the rule(s) anytime a logged-on user executes a process. If the executed process satisfies the criterion set of a rule the changes contained within the rule are made to the process token, and the user has expanded and/or contracted access and/or privileges for only that process.
    Type: Grant
    Filed: August 18, 2005
    Date of Patent: August 23, 2011
    Assignee: BeyondTrust Corporation
    Inventor: Marco Peretti