Patents Assigned to BlueVoyant LLC
-
Patent number: 12659346Abstract: A method for identifying cyber assets and implementing cyber risk mitigation actions based on domain redirects is disclosed. The method comprising selecting an entity for evaluation; identifying one or more seed domains of the entity; identifying candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetching the candidate domains to determine routing information for each of the candidate domains; classifying, based on the routing information, each candidate domain that redirects to the one or more seed domains as an associated domain, wherein each associated domain is considered to be an asset of entity; generating an entity asset database based on the one or more seed domains and the associated domains; and generating a cyber risk mitigation action based on the entity asset database.Type: GrantFiled: February 20, 2023Date of Patent: June 16, 2026Assignee: BlueVoyant LLCInventor: Peter Gleitz
-
Publication number: 20260122100Abstract: A cyber risk management server configured to attribute a network-implemented cyber asset to an operating entity and enhance cyber security of a tenant entity is disclosed herein. The cyber risk management server can include a processor communicably coupled to a source and a memory configured to store algorithmic instructions that, when executed by the processor, cause the cyber risk management server to receive geographic information from the source, receive a plurality of Internet Protocol events associated with a plurality of cyber assets, correlate a Internet Protocol event of the plurality with the received geographic information, attribute the Internet Protocol event to the operating entity based on the correlation, and generate a cyber risk mitigation action configured to enhance the cyber security of the tenant entity based on the attribution of the first Internet Protocol event to the operating entity.Type: ApplicationFiled: June 5, 2024Publication date: April 30, 2026Applicant: BlueVoyant LLCInventors: Wayne Chung, Peter M. Gleitz, Ben Schofield
-
Patent number: 12519823Abstract: A Security Information, and Event Management (“SIEM”) provider server is disclosed herein. The SIEM provider server is configured to enhance network security on behalf of a tenant network by autonomously generating and providing an SIEM configuration to the tenant network. The SIEM provider server includes a processor and a memory configured to store a managed security service provider (“MSSP”) management system that, when executed by the processor, causes the processor to autonomously retrieve an SIEM artifact associated with the tenant network from a content repository; generate a tenant-specific SIEM configuration for the tenant network including the SIEM artifact; and deploy the tenant-specific SIEM configuration to a tenant-specific repository.Type: GrantFiled: December 21, 2022Date of Patent: January 6, 2026Assignee: BlueVoyant LLCInventors: Dorian Birsan, Chee Wai Ooi
-
Publication number: 20250384127Abstract: Systems and methods for a threat-hunting development environment are disclosed herein. The systems and methods can include: executing a networked, assisted, threat-hunting environment that, via a dedicated user interface, is configured to establish data transfer pipelines between the threat-hunting environment and the at least one tenant network, the data transfer pipelines maintaining a connection between the threat-hunting environment and the at least one tenant network during an active session, via the at least one SIEM server, to allow continuous data communication; query the at least one tenant network with a query developed via an integrated code editor; receive the query result data from the at least one tenant network: analyze, the result data for a detected threat in the at least one tenant network; and based on the analyzed result data, push a subsequent query to the at least one tenant network to respond to detected threat.Type: ApplicationFiled: July 14, 2023Publication date: December 18, 2025Applicant: BlueVoyant LLCInventors: Lucas HOOTEN, Stoney DeVille, Ryan Moon, Michael Scutt, Ben Nelson
-
Publication number: 20250363209Abstract: The present disclosure describes a method and system for processing and indexing cyber event data from a continuously updated distributed database. The method and system employ an indexing strategy mapping a unique rowKey for each cyber event to the serialized contents of the event. This indexing strategy enables constant-time queries to events provided query parameters consisting of one or more assets and optionally one or more timestamps.Type: ApplicationFiled: June 23, 2023Publication date: November 27, 2025Applicant: BlueVoyant LLCInventors: Alfredo GIMENEZ, Adam NAJMAN, Tucker LEAVITT, Tyler FLACH
-
Publication number: 20250363219Abstract: A method for managing cyber security risk for a client entity communicating with a plurality of target entities is disclosed. In one aspect, the method includes identifying a plurality of cyber asset footprints, wherein each cyber asset footprint comprises cyber assets associated with a different one of the target entities. In another aspect, the method includes monitoring a plurality of data sources comprising cyber security risk information to generate source data, wherein the source data is organized based on a plurality of risk factors, and wherein the risk factors are classified according to a cyber security risk taxonomy. In yet another aspect, the method includes identifying relevant observations in the source data, wherein each relevant observation comprises information related to one the risk factors, and wherein each relevant observation is identified based on a correlation between the information related to the risk factor and one of the cyber asset footprints.Type: ApplicationFiled: June 16, 2023Publication date: November 27, 2025Applicant: BlueVoyant LLCInventors: Brian Keller, Ryan C. Agee, Michael Spencer, John Reel, Brandon Beaty
-
Patent number: 12464010Abstract: Systems and methods are disclosed for autonomous security enhancement of a tenant network via a managed security service provider (MSSP) server comprising a processor and a memory, with information from a plurality of data sources, the method comprising querying a database or server, upon an encounter with an indicator of compromise (IoC), by a security system, to identify data sources of a plurality of data sources, wherein the data sources include information on the IoC; generating, via the processor, an IoC threat score for the IoC; generating, at least one actionable security enhancement notification based on the IoC threat score; and deploying an automated security response that can comprise displaying the IoC threat score and an actionable security enhancement notification to a user, allowing triggering or disabling of at least one action based on the single IoC threat score.Type: GrantFiled: July 26, 2023Date of Patent: November 4, 2025Assignee: BlueVoyant LLCInventors: Ayal Reich, Leo Sojref, Tal Blaustein
-
Publication number: 20250284799Abstract: A method for identifying cyber assets and implementing cyber risk mitigation actions based on a democratic matching algorithm is disclosed. In one aspect, the method includes executing a plurality of cyber asset identification algorithms to identify a plurality of candidate match pairs, wherein each candidate match pair comprises two cyber assets identified as potential assets of the same entity by at least one of the cyber asset identification algorithms. The method can further include determining a true match probability for each candidate match pair, wherein the true match probability is the probability that the two cyber assets in the candidate match pair are assets of the same entity, and wherein the true match probability is based on which of the cyber asset identification algorithms identified the candidate match pair.Type: ApplicationFiled: May 17, 2023Publication date: September 11, 2025Applicant: BlueVoyant LLCInventors: Abdul KHAN, Brian KELLER, Peter Meriwether GLEITZ
-
Publication number: 20250278483Abstract: A Security Information and Event Management (“SIEM”) provider server configured to enhance network security on behalf of a tenant network by autonomously ingesting and enriching security information associated with the tenant network is disclosed herein. The SIEM provider server can be configured to periodically monitor the tenant network for configuration changes, detect a configuration change in the tenant network, update a fetch job parameter stored in a job database based on the detected configuration change in the tenant network, generate a fetch job for the tenant network based on the updated job parameter stored in the job database and store the generated fetch job in a queue, execute the generated fetch job such that the job manager retrieves security information from a data source associated with the tenant network, enrich the retrieved security information, and generate an output configured to enhance the security of the tenant network.Type: ApplicationFiled: May 19, 2023Publication date: September 4, 2025Applicant: BlueVoyant LLCInventor: Neel Arora
-
Publication number: 20250260715Abstract: Systems and methods are disclosed for autonomous security enhancement of a tenant network via a managed security service provider (MSSP) server comprising a processor and a memory, with information from a plurality of data sources, the method comprising querying a database or server, upon an encounter with an indicator of compromise (IoC), by a security system, to identify data sources of a plurality of data sources, wherein the data sources include information on the IoC; generating, via the processor, an IoC threat score for the IoC; generating, at least one actionable security enhancement notification based on the IoC threat score; and deploying an automated security response that can comprise displaying the IoC threat score and an actionable security enhancement notification to a user, allowing triggering or disabling of at least one action based on the single IoC threat score.Type: ApplicationFiled: July 26, 2023Publication date: August 14, 2025Applicant: BlueVoyant LLCInventors: Ayal Reich, Leo Sojref, Tal Blaustein
-
Patent number: 12332870Abstract: The present disclosure describes a method and system for processing and indexing data from a continuously updated distributed database. The method and system employ a portioned database architecture to return results in a constant-time query and reduce the storage size of indexed records. The database partitions include a plurality of data records correspond to an index group in a single row of a rowKey table. The index group comprises data records that are indexed in a predetermined indexing interval. The portioned database architecture allows record fields to be queried from the index group.Type: GrantFiled: June 4, 2023Date of Patent: June 17, 2025Assignee: BlueVoyant LLCInventors: Tucker Leavitt, Adam Najman, Alfredo Gimenez, Tyler Flach, Abdul Khan, Jonathan Greenblatt
-
Patent number: 12335370Abstract: A method for generating representative Key:Value pairs of cyber event or cyber asset behavior and de-duplicating multiple alerts associated with a cyber event or cyber asset behavior. The Key:Value pairs comprise a hash value representative of the cyber event or cyber asset behavior and an asset identifier. The Key:Value pairs provides a security operations center a queryable identifier to easily track the behavior of an asset and determine the number of cyber event observations in a predetermined time period.Type: GrantFiled: May 10, 2023Date of Patent: June 17, 2025Assignee: BlueVoyant LLCInventors: Reagan Short, Steven Bremner, Christopher Wildes
-
Publication number: 20250184350Abstract: A method for identifying cyber assets and implementing cyber risk mitigation actions based on domain redirects is disclosed. The method comprising selecting an entity for evaluation; identifying one or more seed domains of the entity; identifying candidate domains based on at least one of a public data source, a proprietary data source, or a combination thereof; fetching the candidate domains to determine routing information for each of the candidate domains; classifying, based on the routing information, each candidate domain that redirects to the one or more seed domains as an associated domain, wherein each associated domain is considered to be an asset of entity; generating an entity asset database based on the one or more seed domains and the associated domains; and generating a cyber risk mitigation action based on the entity asset database.Type: ApplicationFiled: February 20, 2023Publication date: June 5, 2025Applicant: BlueVoyant LLCInventor: Peter Gleitz
-
Publication number: 20250150467Abstract: A security automation platform is disclosed herein. The security automation platform can be communicably coupled to a tenant configured to deploy a tenant security platform and comprises a processor and a memory configured to store a security automation platform that, when executed by the processor, causes the processor to detect, via a variable store, a variable associated with the tenant, correlate, via a content library, the detected variable to an artifact stored within the content library; generate, via an automation schema, an automation for the tenant based on the artifact, wherein the automation comprises a security tool configured to continuously monitor an API deployed by the tenant, and transmit, via an API broker of the security automation platform, the generated automation to the security automation platform deployed by the tenant.Type: ApplicationFiled: January 23, 2023Publication date: May 8, 2025Applicant: BlueVoyant LLCInventors: Dorian Birsan, Christopher Teekema, Neel Arora
-
Publication number: 20250110939Abstract: The present disclosure describes a method and system for processing and indexing data from a continuously updated distributed database. The method and system employ a portioned database architecture to return results in a constant-time query and reduce the storage size of indexed records. The database partitions include a plurality of data records correspond to an index group in a single row of a rowKey table. The index group comprises data records that are indexed in a predetermined indexing interval. The portioned database architecture allows record fields to be queried from the index group.Type: ApplicationFiled: June 4, 2023Publication date: April 3, 2025Applicant: BlueVoyant LLCInventors: Tucker LEAVITT, Adam NAJMAN, Alfredo GIMENEZ, Tyler FLACH, Abdul KHAN, Jonathan GREENBLATT
-
Publication number: 20250112762Abstract: A method for generating representative Key:Value pairs of cyber event or cyber asset behavior and de-duplicating multiple alerts associated with a cyber event or cyber asset behavior. The Key:Value pairs comprise a hash value representative of the cyber event or cyber asset behavior and an asset identifier. The Key:Value pairs provides a security operations center a queryable identifier to easily track the behavior of an asset and determine the number of cyber event observations in a predetermined time period.Type: ApplicationFiled: May 10, 2023Publication date: April 3, 2025Applicant: BlueVoyant LLCInventors: Reagan Short, Steven Bremner, Christopher Wildes
-
Publication number: 20250097244Abstract: A method for streamlining and standardizing the ingest of security data across a plurality of tenant networks is disclosed. Each of the plurality of tenant networks comprises at least one log source, the method comprising receiving, by each of a plurality of data gateway modules, raw log data from the log source associated therewith; generating, by each of the plurality of data gateway modules, formatted log data based on the raw log data; ingesting, by an edge module, formatted log data from the plurality of data gateway modules; automatically updating, by a central control plane module, a configuration of at least one of the plurality of data gateway modules based on a change to the log source(s) associated therewith; and implementing, by a security monitoring system, a security action related to at least one of the plurality of tenant networks based on the ingested formatted data.Type: ApplicationFiled: December 21, 2022Publication date: March 20, 2025Applicant: BlueVoyant LLCInventors: Chris White, Jake Vance, Allen Duet, Ed Schernau, Neel Arora, Chris Surel
-
Publication number: 20240419788Abstract: A method of enhancing network security across a plurality of tenants is disclosed herein. The method can include: providing a Security Information, and Event Management (SIEM) management application configured to be hosted by a SIEM provider server communicably coupled to a tenant server; coupling, via a data connector, the SIEM management application to a log source hosted by the tenant server, wherein the data connector is configured the control a flow of data to and from the log source; generating, via the SIEM management application, a JavaScript Object Notation (JSON) based solution bundle for the log source; visually displaying, via a user interface of the SIEM management application, a proposed SIEM protocol for the tenant server based, at least in part, on the JSON-based solution bundle; and deploying, via the SIEM management application, the proposed SIEM protocol from the SIEM provider server to the tenant server.Type: ApplicationFiled: August 29, 2024Publication date: December 19, 2024Applicant: BlueVoyant LLCInventors: Dorian Birsan, Marius Mocanu, Igor Bologan
-
Patent number: 12105797Abstract: A method of enhancing network security across a plurality of tenants is disclosed herein. The method can include: providing a Security Information, and Event Management (SIEM) management application configured to be hosted by a SIEM provider server communicably coupled to a tenant server; coupling, via a data connector, the SIEM management application to a log source hosted by the tenant server, wherein the data connector is configured the control a flow of data to and from the log source; generating, via the SIEM management application, a JavaScript Object Notation (JSON) based solution bundle for the log source; visually displaying, via a user interface of the SIEM management application, a proposed SIEM protocol for the tenant server based, at least in part, on the JSON-based solution bundle; and deploying, via the SIEM management application, the proposed SIEM protocol from the SIEM provider server to the tenant server.Type: GrantFiled: June 3, 2022Date of Patent: October 1, 2024Assignee: BlueVoyant LLCInventors: Dorian Birsan, Marius Mocanu, Igor Bologan
-
Publication number: 20240273188Abstract: A method for enhancing network security across a plurality of tenants configured to host a plurality of client applications is disclosed herein. The method includes: providing a SIEM management application hosted by a SIEM provider server communicably coupled to the plurality of tenants; receiving a SIEM status from the plurality of tenants; visualizing the SIEM status; filtering the SIEM status based on a user input received via the graphical user interface; visualizing the filtered SIEM status; selecting, via the graphical user interface, at least one client application of the plurality of clients applications hosted by at least one tenant of the plurality of tenants to update based on the filtered SIEM status; generating a client application update, and an update alert based on the selection; transmitting the update alert to the at least one tenant; and updating the at least one client application based on the update alert.Type: ApplicationFiled: June 3, 2022Publication date: August 15, 2024Applicant: BlueVoyant LLCInventors: Dorian Birsan, Marius Mocanu, Adrian Grigorof, Igor Bologan, Catalin Duta