Patents by Inventor Or HELLER
Or HELLER has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).
-
Patent number: 12579251Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment utilizes code objects of infrastructure as code. The method also includes accessing a configuration code, the configuration code including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal in the cloud computing environment; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining that the first code object includes a permission which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.Type: GrantFiled: December 29, 2022Date of Patent: March 17, 2026Assignee: Wiz, Inc.Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
-
Publication number: 20260039685Abstract: A system and method for detecting lateral movement in a computing environment based on configuration code is presented. The method includes accessing a configuration code, the configuration code including a plurality of code objects, wherein a code object of the plurality of code objects corresponds to an entity deployed in the computing environment; selecting an identifier of an exposed entity, the exposed entity associated with a secret; querying a security database based on the identifier to detect a representation of the exposed entity, wherein the representation of the exposed entity is connected to a representation of the secret; traversing the security database to detect a second representation connected to the representation of the secret, the second representation representing a second entity deployed based on the code object of the plurality of code objects; and initiating a mitigation action associated with the second entity.Type: ApplicationFiled: October 13, 2025Publication date: February 5, 2026Applicant: Wiz, Inc.Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK
-
Publication number: 20250370786Abstract: A system and method for signatureless validation of virtual instances in a computing environment is presented. The method includes detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein, each validated fingerprint corresponding to a software artifact; deploying the instance in response to detecting the first fingerprint in the fingerprint database; and blocking deployment of the instance in response to determining that the first fingerprint is not stored in the fingerprint database.Type: ApplicationFiled: August 19, 2025Publication date: December 4, 2025Applicant: Wiz, Inc.Inventors: Lir LOCKER, Bar MAGNEZI, Amir LANDE BLAU, Yaniv Joseph OLIVER, Or HELLER
-
Patent number: 12489781Abstract: A system and method for detecting lateral movement in a cloud computing environment is based on configuration code. The method includes: accessing a configuration code, the configuration code including a plurality of code objects, wherein a code object of the plurality of code objects corresponds to a cloud entity deployed in the cloud computing environment; selecting an identifier of an exposed cloud entity, the cloud entity associated with a secret; querying a security graph based on the identifier to detect a node representing the secret, wherein the node representing the secret is connected to a node representing the exposed cloud entity; traversing the security graph to detect a second node connected to the node representing the secret, the second node representing a second cloud entity deployed based on the code object of the plurality of code objects; and generating a mitigation action based on the second cloud entity.Type: GrantFiled: December 29, 2022Date of Patent: December 2, 2025Assignee: Wiz, Inc.Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
-
Publication number: 20250363205Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment is presented. The method includes accessing a plurality of code objects, wherein a code object of the plurality of code objects corresponds to a principal of the cloud computing environment; detecting in a log a plurality of access events associated with a first principal of the cloud computing environment, the first principal corresponding to a first code object of the plurality of code objects; detecting in the first code object a permission associated with the first principal which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.Type: ApplicationFiled: August 12, 2025Publication date: November 27, 2025Applicant: Wiz, Inc.Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK
-
Publication number: 20250350610Abstract: A system and method for detecting a cybersecurity toxic combination prior to a virtual instance deployment is presented. The method includes: inspecting an entity in a cloud computing environment for a cybersecurity object, the cybersecurity object; detecting the cybersecurity object on the inspected entity; inspecting a code object utilized to deploy a virtual instance in the cloud computing environment prior to deployment of the virtual instance; detecting a toxic combination cybersecurity issue based on the cybersecurity object and the code object; and initiating a mitigation action on the code object.Type: ApplicationFiled: May 9, 2024Publication date: November 13, 2025Applicant: Wiz, Inc.Inventors: Arnon TRABELSI, Or HELLER, Amir LANDE BLAU, Alon WEISS, Daniel Hershko SHEMESH, Tom FEIGIN, Gahl SARAF, Roy IARCHY, Or BIN, Raz HILLEL, Assaf AVITAL, Benny HOLTZER
-
Patent number: 12418527Abstract: A system and method for signatureless validation of objects in a computing environment, including artifacts, objects, files, virtual images, and the like. The method includes: detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact in response to detecting the request to deploy the instance; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein; deploying the instance in response to validating the first fingerprint; and blocking deployment of the instance in response to determining the first fingerprint is not of the plurality of validated fingerprints.Type: GrantFiled: December 12, 2023Date of Patent: September 16, 2025Assignee: Wiz, Inc.Inventors: Lir Locker, Bar Magnezi, Amir Lande Blau, Yaniv Joseph Oliver, Or Heller
-
Patent number: 12411937Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment utilizes code objects of infrastructure as code. The method also includes accessing a configuration code, the configuration code including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal in the cloud computing environment; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining that the first code object includes a permission which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.Type: GrantFiled: December 29, 2022Date of Patent: September 9, 2025Assignee: Wiz, Inc.Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
-
Publication number: 20250193178Abstract: A system and method for signatureless validation of objects in a computing environment, including artifacts, objects, files, virtual images, and the like. The method includes: detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact in response to detecting the request to deploy the instance; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein; deploying the instance in response to validating the first fingerprint; and blocking deployment of the instance in response to determining the first fingerprint is not of the plurality of validated fingerprints.Type: ApplicationFiled: December 12, 2023Publication date: June 12, 2025Applicant: Wiz, Inc.Inventors: Lir LOCKER, Bar MAGNEZI, Amir LANDE BLAU, Yaniv Joseph OLIVER, Or HELLER
-
Publication number: 20250141913Abstract: A system and method for inspecting a resource deployed in a cloud computing environment for a cybersecurity threat is presented. The method includes detecting a virtual instance deployed in a cloud computing environment, the virtual instance associated with an original disk; generating a cloned disk directly based on the original disk, wherein the original disk is provisioned storage from a cloud storage system; generating a cloned disk descriptor associated with the cloned disk, the cloned disk descriptor pointing to the provisioned storage; inspecting the cloned disk for a cybersecurity object, the cybersecurity object indicating a cybersecurity risk; and releasing the cloned disk in response to completing inspection of the cloned disk.Type: ApplicationFiled: December 30, 2024Publication date: May 1, 2025Applicant: Wiz, Inc.Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
-
Patent number: 12244634Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.Type: GrantFiled: April 26, 2024Date of Patent: March 4, 2025Assignee: Wiz, Inc.Inventors: Daniel Hershko Shemesh, Yarin Miran, Roy Reznik, Ami Luttwak, Yinon Costica, Avihai Berkovitz, George Pisha, Yaniv Joseph Oliver, Udi Reitblat, Or Heller, Raaz Herzberg, Osher Hazan, Niv Roit Ben David
-
Publication number: 20240275812Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.Type: ApplicationFiled: April 26, 2024Publication date: August 15, 2024Applicant: Wiz, Inc.Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
-
Publication number: 20240137382Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.Type: ApplicationFiled: December 29, 2023Publication date: April 25, 2024Applicant: Wiz, Inc.Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
-
Publication number: 20230221983Abstract: A system and method detects a vulnerable code object in configuration code for deploying instances in a cloud computing environment. The method includes: accessing a configuration code, including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining a first set of permissions associated with the first code object. The method also includes determining a second set of permissions based on the plurality of access events. The method also includes detecting a difference between the second set of permissions and the first set of permissions; and generating an updated code object based on the first code object and the detected difference.Type: ApplicationFiled: December 29, 2022Publication date: July 13, 2023Applicant: Wiz, Inc.Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK