Patents Assigned to Wiz, Inc.
  • Patent number: 12689636
    Abstract: A system and method for detecting an attack path in a computing environment is presented. The method includes: detecting a forensic artifact in a computing environment, the forensic artifact including an identifier of a resource deployed in the computing environment; inspecting the resource for a cybersecurity object, the cybersecurity object indicating a cybersecurity issue; generating a representation of: the detected forensic artifact, the resource, and the cybersecurity object, in a security database, wherein the security database includes a representation of the computing environment; generating a potential lateral movement path between the resource and another resource; and generating a visualization based on the potential lateral movement, the forensic artifact, and the cybersecurity object.
    Type: Grant
    Filed: November 11, 2024
    Date of Patent: July 21, 2026
    Assignee: Wiz, Inc.
    Inventors: Alma Raziel, George Pisha, Michael Aminov, Avi Tal Lichtenstein, Tal Gilady, Amitai Cohen
  • Patent number: 12688277
    Abstract: A system and method for inspecting a running container for a cybersecurity object in a cloud computing environment is disclosed. The method includes: generating a clone of a disk, wherein the disk is deployed in a cloud computing environment; detecting a software container on the generated clone of the disk; and inspecting the software container for a cybersecurity object, in response to determining that the container is a running container.
    Type: Grant
    Filed: April 29, 2024
    Date of Patent: July 21, 2026
    Assignee: Wiz, Inc.
    Inventors: Daniel Hershko Shemesh, Yarin Miran, Roy Reznik, Ami Luttwak, Yinon Costica, Niv Roit Ben David, Yaniv Shaked, Raaz Herzberg, Amir Lande Blau
  • Publication number: 20260205461
    Abstract: A system and method for detecting a permission escalation event includes querying a security graph to detect a second principal node, representing a second principal, the second principal having a permission to assume a first principal, represented by a first principal node, wherein the security graph stores a representation of a cloud computing environment in which the first principal and second principal are deployed; determining that the first principal node has access to a permission which is not accessible by the second principal node; and generating a permission escalation event.
    Type: Application
    Filed: March 9, 2026
    Publication date: July 16, 2026
    Applicant: Wiz, Inc.
    Inventors: Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT
  • Patent number: 12683989
    Abstract: A method for scalable vulnerability detection is provided. The method includes selecting at least a workload of a plurality of workloads deployed in a first cloud environment for inspection, wherein the workload includes a first volume; generating in a remote cluster an inspection node, the inspection node including at least a first disk, wherein the remote cluster provisions inspection nodes in response to demand for inspection nodes; generating a persistent volume (PV) on which the at least a first disk is mounted, wherein the at least a first disk is generated from a snapshot of the first volume; and generating a persistent volume claim (PVC) of the PV for an inspector workload, wherein the inspector workload is configured to inspect the PV for an object, and wherein inspector workloads are provisioned in response to demand for inspector workloads.
    Type: Grant
    Filed: May 23, 2024
    Date of Patent: July 14, 2026
    Assignee: Wiz, Inc.
    Inventors: Yarin Miran, Ami Luttwak, Roy Reznik, Avihai Berkovitz, Moran Cohen, Yaniv Shaked, Yaniv Joseph Oliver
  • Patent number: 12682038
    Abstract: A system and method detect weak passwords in a workload deployed in a cloud computing environment. The method includes extracting a digest value from a password record, the password record further including a cryptographic function identifier of a cryptographic function; generating a digest value by processing the cryptographic function with a value selected from a dictionary list as an input; comparing the generated digest value to the extracted digest value; determining that a password associated with the password record is weak in response to the generated digest value matching the extracted digest value.
    Type: Grant
    Filed: June 20, 2022
    Date of Patent: July 14, 2026
    Assignee: Wiz, Inc.
    Inventors: Yaniv Shaked, Gal Kozoshnik
  • Patent number: 12676890
    Abstract: A system and method for applying a cybersecurity contextual policy in a computing environment are disclosed. In an embodiment, the method includes: detecting a cybersecurity object on a virtualization, the virtualization deployed in a computing environment; detecting a policy of the computing environment, the policy including a conditional rule; generating a contextual policy based on: the conditional rule, and an exception to the conditional rule based on the cybersecurity object; and configuring an admission controller of a software container cluster deployed in the computing environment to apply the contextual policy.
    Type: Grant
    Filed: June 12, 2023
    Date of Patent: July 7, 2026
    Assignee: Wiz, Inc.
    Inventors: Amir Lande Blau, Roy Reznik, Bar Magnezi
  • Publication number: 20260189464
    Abstract: The system and method for performing cybersecurity threat detection on a resource in a cloud computing environment are presented. The method includes providing a sensor to the resource; configuring the sensor to detect an event in the resource from a data link layer communication; matching the event to a rule, the rule specifying a mitigation action if a condition is met; initiating the mitigation action in accordance with the rule; and including data of the event in a software bill of materials (SBOM).
    Type: Application
    Filed: February 23, 2026
    Publication date: July 2, 2026
    Applicant: Wiz, Inc.
    Inventors: Amir LANDE BLAU, Michael AMINOV, Arik NEMTSOV, Udi REITBLAT, Shahar YAKOV, Jonathan DORON, Eliad PELLER, Gal DE LEON
  • Publication number: 20260189596
    Abstract: The system and method for agentless detection of sensitive data in a cloud computing environment are presented. The method includes extracting a data schema of a data file from the data file; deploying the data file in a cloud computing environment; storing the data schema in a security database, the security database including a representation of the cloud computing environment; generating a data file node in the security database, the data file node corresponding to the data file; classifying a type of sensitive data in the data file; updating a value in metadata of the data file node, the value indicating the classified type of sensitive data; and performing a mitigation action based on the classified type of sensitive data and a location of the data file.
    Type: Application
    Filed: February 23, 2026
    Publication date: July 2, 2026
    Applicant: Wiz, Inc.
    Inventors: Raaz HERZBERG, Avi Tal LICHTENSTEIN, Roy REZNIK, Ami LUTTWAK, Moran COHEN, Yaniv SHAKED, Yinon COSTICA, George PISHA
  • Publication number: 20260178742
    Abstract: A system and method for risk and constraint-based cybersecurity inspection of a computing environment is presented. The method includes querying an application programming interface (API) of a computing environment to detect a plurality of workloads deployed therein; determining a constraint for inspection of the computing environment; provisioning resources of the computing environment to an inspection account based on the determined constraint; and initiating inspection of the plurality of workloads utilizing the provisioned resources.
    Type: Application
    Filed: July 8, 2025
    Publication date: June 25, 2026
    Applicant: Wiz, Inc.
    Inventors: Ami LUTTWAK, Yaniv SHAKED, Shahar RAND, Eric ABRAMOV, Elad GABAY, Yinon COSTICA
  • Publication number: 20260180998
    Abstract: A system and method fordetection of cybersecurity threats based on cloud entity groups is presented. The method includes detecting a cloud entity in a cloud computing environment, the cloud entity associated with a plurality of cloud components; grouping, based on the cloud entity, a plurality of detected events for the cloud components; detecting a cybersecurity threat in a first event of the plurality of detected events; determining a state of a cloud component of the plurality of cloud components; detecting a cybersecurity risk based on the cybersecurity threat and the determined state of the cloud entity; and executing at least a mitigation action in the cloud computing environment based on the cybersecurity risk.
    Type: Application
    Filed: October 1, 2025
    Publication date: June 25, 2026
    Applicant: Wiz, Inc.
    Inventor: Itay HAREL
  • Publication number: 20260181000
    Abstract: A system and method for detecting a cybersecurity threat in a cloud computing environment is presented. The method includes detecting an event based on accessing log data from a cloud log; receiving runtime data from a runtime sensor, wherein the runtime sensor is configured to detect runtime data on a resource deployed in the cloud computing environment; determining a state for each entity of a plurality of entities deployed in a cloud computing environment, wherein the state of each entity is a status of an entity at a specific point in time; detecting an event of a first type, wherein the first type indicates a potential cybersecurity attack; determining that the event of the first type is a benign event based on the determined state; and initiating a mitigation action, in response to determining that the event of the first type is a non-benign event.
    Type: Application
    Filed: December 19, 2024
    Publication date: June 25, 2026
    Applicant: Wiz, Inc.
    Inventor: Itay HAREL
  • Patent number: 12664072
    Abstract: A method and system for generating an Application Programming Interface (API) path utilizing code detection is presented. The method includes detecting a resource, wherein the resource is deployed in a cloud computing environment; detecting at least a code object of a plurality of code objects stored in a code repository, from which the resource is deployed; inspecting only the at least a code object from which the resource is deployed for a hint of an API path; generating a potential API path based on the hint of the API path; executing a network access instruction in the cloud computing environment based on the generated API path; and determining that the potential API path is a validated API path based on a response of executing the network access instruction.
    Type: Grant
    Filed: May 29, 2025
    Date of Patent: June 23, 2026
    Assignee: Wiz, Inc.
    Inventors: Ido Yariv, Cfir Cohen, Amit Rapaport, Or Tzabary, Gilad Hoze, Bar Vaserman, Assaf Segal
  • Publication number: 20260172430
    Abstract: A system and method for cybersecurity root cause analysis. A method includes identifying a first resource name including a first string within cybersecurity data of a cybersecurity event. The first string is parsed into a set of first structured units based on structured unit formats. Each structured unit format is defined with respect to substrings of certain data types. The first structured units are compared to a set of second structured units of a second string for a second resource name. The first string is correlated to the second string based on results of comparing the first structured units to the second structured units. The second resource name is identified as matching the first resource name based on the correlation. A root cause of the cybersecurity event is determined based on the matching. Mitigation actions are performed in order to mitigate the cybersecurity event based on the determined root cause.
    Type: Application
    Filed: July 15, 2025
    Publication date: June 18, 2026
    Applicant: Wiz, Inc.
    Inventors: Barak BERCOVITZ, Bernie PINKENZON-HOWARD
  • Publication number: 20260163911
    Abstract: A system and method for executing mitigation actions in a cloud computing environment based on a severity of a detected cybersecurity risk is presented. The method includes detecting a cybersecurity risk based on an enriched event record from a cloud log, the enriched event record including runtime data from a resource deployed in a cloud computing environment and a state of an entity detected in the runtime data; determining a severity score for the detected cybersecurity risk of the enriched event record; prioritizing a plurality of mitigation actions based on the severity score; and executing at least a mitigation action in the cloud computing environment based on the prioritization.
    Type: Application
    Filed: January 6, 2026
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventor: Itay Harel
  • Publication number: 20260161781
    Abstract: A system and method for detecting cybersecurity threats in a cloud computing environment utilizing runtime data is presented. The method includes: receiving runtime data from a runtime sensor deployed on a resource in a cloud computing environment, wherein the runtime sensor is configured to detect runtime events on the resource; generating an event log in an inspection environment based on the received runtime data, each event in the event log generated by extracting data from the runtime data; detecting in the event log a software application identifier of a software application; querying a security database based on the software application identifier; determining, based on a result of querying, that the software application was not previously detected on the resource; and initiating inspection of the resource in response to determining that the software application corresponding to the software application identifier was not previously detected on the resource.
    Type: Application
    Filed: January 14, 2026
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Amir LANDE BLAU, Michael AMINOV, Arik NEMTSOV, Udi REITBLAT, Shahar YAKOV, Jonathan DORON, Eliad PELLER, Gal DE LEON
  • Publication number: 20260163904
    Abstract: A system and method for detecting endpoint exposures in a cloud computing environment is presented. The method includes detecting a plurality of endpoints in a cloud computing environment, inspecting each of a plurality of resources deployed in the cloud computing environment to detect an endpoint; associating the endpoint to another object, wherein the another object is an entity of the cloud computing environment; generating a representation of the endpoint in a security database, wherein the security database includes a representation of the cloud computing environment; detecting a network path between the another object and an external network; determining that the endpoint is an exposed endpoint in response to detecting the network path; and initiating a remediation action based on the exposed endpoint.
    Type: Application
    Filed: December 6, 2024
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Or TZABARY, Ido YARIV, Ron David BEN ARZI, Cfir COHEN
  • Publication number: 20260161772
    Abstract: A system and method for cybersecurity threat investigation using sensor-based runtime execution data is presented. The method includes receiving aggregated runtime data from a sensor deployed on a resource in a cloud computing environment; generating an event log based on the aggregated runtime data, each event in the event log generated by extracting data from the aggregated runtime data; detecting in the event log a new software application identifier based on an event in the event log; and initiating inspection of the resource to detect a cybersecurity object, the cybersecurity object indicating the new software application.
    Type: Application
    Filed: December 9, 2024
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Amir LANDE BLAU, Michael AMINOV, Arik NEMTSOV, Udi REITBLAT, Shahar YAKOV, Jonathan DORON, Eliad PELLER, Gal DE LEON
  • Publication number: 20260161800
    Abstract: A system and method for inspecting private code repositories for cybersecurity issues is presented. The method includes accessing a private code repository, the private code repository including a plurality of code objects; generating a pull request including code for an inspector, the inspector configured to detect a cybersecurity object in a code object of the plurality of code objects; initiating the pull request in the private code repository; and receiving a result from the inspector, wherein the result includes an identifier of the code object and an identifier of a detected cybersecurity object, wherein the cybersecurity object indicates a cybersecurity issue.
    Type: Application
    Filed: June 5, 2025
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Arnon TRABELSI, Daniel Hershko SHEMESH
  • Publication number: 20260161384
    Abstract: A system and method for initiating a remediation action based on an End-Of-Life (EOL) date of a software component deployed in a cloud computing environment is presented. The method includes inspecting resources of a cloud computing environment for a plurality of software components, each software component deployed on at least a resource; detecting software components from the inspection of resources deployed in the cloud computing environment; generating a software bill of materials (SBOM) for the cloud computing environment based at least on a detected software component, wherein the SBOM includes an identifier of the software component; determining for the detected software component an end of life (EOL) date, wherein the EOL date is determined based on vendor data; applying a policy including a conditional rule to the EOL date; and initiating a remediation action for the detected software in response to determining that the conditional rule is satisfied.
    Type: Application
    Filed: January 8, 2026
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Shay ZADIK, Mattan SHALEV, Gal KOZOSHNIK, Omri KORNBLAU, Yaniv SHAKED, Alon WEISS, Addi Grinbaum, Idan Shoval, Mika Maymon, Maayan LAAV
  • Publication number: 20260161775
    Abstract: A system and method for self-injecting inspection workloads for cybersecurity inspection is presented. The method includes receiving access to a managed code repository including a plurality of code objects, each code object utilized to deploy a resource in a cloud computing environment; generating code for an inspector workload for deploying in a computing environment of the managed code repository; injecting the generated code in the managed code repository; initiating deployment of the inspector workload; and initiating a remediation action in the managed code repository based on a result received from the inspector workload.
    Type: Application
    Filed: December 9, 2024
    Publication date: June 11, 2026
    Applicant: Wiz, Inc.
    Inventors: Arnon TRABELSI, Daniel Hershko SHEMESH