Patents by Inventor Or HELLER

Or HELLER has filed for patents to protect the following inventions. This listing includes patent applications that are pending as well as patents that have already been granted by the United States Patent and Trademark Office (USPTO).

  • Patent number: 12579251
    Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment utilizes code objects of infrastructure as code. The method also includes accessing a configuration code, the configuration code including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal in the cloud computing environment; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining that the first code object includes a permission which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: March 17, 2026
    Assignee: Wiz, Inc.
    Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
  • Publication number: 20260039685
    Abstract: A system and method for detecting lateral movement in a computing environment based on configuration code is presented. The method includes accessing a configuration code, the configuration code including a plurality of code objects, wherein a code object of the plurality of code objects corresponds to an entity deployed in the computing environment; selecting an identifier of an exposed entity, the exposed entity associated with a secret; querying a security database based on the identifier to detect a representation of the exposed entity, wherein the representation of the exposed entity is connected to a representation of the secret; traversing the security database to detect a second representation connected to the representation of the secret, the second representation representing a second entity deployed based on the code object of the plurality of code objects; and initiating a mitigation action associated with the second entity.
    Type: Application
    Filed: October 13, 2025
    Publication date: February 5, 2026
    Applicant: Wiz, Inc.
    Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK
  • Publication number: 20250370786
    Abstract: A system and method for signatureless validation of virtual instances in a computing environment is presented. The method includes detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein, each validated fingerprint corresponding to a software artifact; deploying the instance in response to detecting the first fingerprint in the fingerprint database; and blocking deployment of the instance in response to determining that the first fingerprint is not stored in the fingerprint database.
    Type: Application
    Filed: August 19, 2025
    Publication date: December 4, 2025
    Applicant: Wiz, Inc.
    Inventors: Lir LOCKER, Bar MAGNEZI, Amir LANDE BLAU, Yaniv Joseph OLIVER, Or HELLER
  • Patent number: 12489781
    Abstract: A system and method for detecting lateral movement in a cloud computing environment is based on configuration code. The method includes: accessing a configuration code, the configuration code including a plurality of code objects, wherein a code object of the plurality of code objects corresponds to a cloud entity deployed in the cloud computing environment; selecting an identifier of an exposed cloud entity, the cloud entity associated with a secret; querying a security graph based on the identifier to detect a node representing the secret, wherein the node representing the secret is connected to a node representing the exposed cloud entity; traversing the security graph to detect a second node connected to the node representing the secret, the second node representing a second cloud entity deployed based on the code object of the plurality of code objects; and generating a mitigation action based on the second cloud entity.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: December 2, 2025
    Assignee: Wiz, Inc.
    Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
  • Publication number: 20250363205
    Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment is presented. The method includes accessing a plurality of code objects, wherein a code object of the plurality of code objects corresponds to a principal of the cloud computing environment; detecting in a log a plurality of access events associated with a first principal of the cloud computing environment, the first principal corresponding to a first code object of the plurality of code objects; detecting in the first code object a permission associated with the first principal which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.
    Type: Application
    Filed: August 12, 2025
    Publication date: November 27, 2025
    Applicant: Wiz, Inc.
    Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK
  • Publication number: 20250350610
    Abstract: A system and method for detecting a cybersecurity toxic combination prior to a virtual instance deployment is presented. The method includes: inspecting an entity in a cloud computing environment for a cybersecurity object, the cybersecurity object; detecting the cybersecurity object on the inspected entity; inspecting a code object utilized to deploy a virtual instance in the cloud computing environment prior to deployment of the virtual instance; detecting a toxic combination cybersecurity issue based on the cybersecurity object and the code object; and initiating a mitigation action on the code object.
    Type: Application
    Filed: May 9, 2024
    Publication date: November 13, 2025
    Applicant: Wiz, Inc.
    Inventors: Arnon TRABELSI, Or HELLER, Amir LANDE BLAU, Alon WEISS, Daniel Hershko SHEMESH, Tom FEIGIN, Gahl SARAF, Roy IARCHY, Or BIN, Raz HILLEL, Assaf AVITAL, Benny HOLTZER
  • Patent number: 12418527
    Abstract: A system and method for signatureless validation of objects in a computing environment, including artifacts, objects, files, virtual images, and the like. The method includes: detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact in response to detecting the request to deploy the instance; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein; deploying the instance in response to validating the first fingerprint; and blocking deployment of the instance in response to determining the first fingerprint is not of the plurality of validated fingerprints.
    Type: Grant
    Filed: December 12, 2023
    Date of Patent: September 16, 2025
    Assignee: Wiz, Inc.
    Inventors: Lir Locker, Bar Magnezi, Amir Lande Blau, Yaniv Joseph Oliver, Or Heller
  • Patent number: 12411937
    Abstract: A system and method for detecting excessive permissions of a principal in a cloud computing environment utilizes code objects of infrastructure as code. The method also includes accessing a configuration code, the configuration code including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal in the cloud computing environment; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining that the first code object includes a permission which is not utilized in any of the plurality of access events; and initiating a mitigation action for the first principal based on the permission.
    Type: Grant
    Filed: December 29, 2022
    Date of Patent: September 9, 2025
    Assignee: Wiz, Inc.
    Inventors: Or Heller, Raaz Herzberg, Yaniv Joseph Oliver, Osher Hazan, Niv Roit Ben David, Ami Luttwak, Roy Reznik
  • Publication number: 20250193178
    Abstract: A system and method for signatureless validation of objects in a computing environment, including artifacts, objects, files, virtual images, and the like. The method includes: detecting a request to deploy an instance based on a software artifact in the computing environment; generating a first fingerprint based on the software artifact in response to detecting the request to deploy the instance; querying a fingerprint database, including a plurality of validated fingerprints, to determine if the first fingerprint is stored therein; deploying the instance in response to validating the first fingerprint; and blocking deployment of the instance in response to determining the first fingerprint is not of the plurality of validated fingerprints.
    Type: Application
    Filed: December 12, 2023
    Publication date: June 12, 2025
    Applicant: Wiz, Inc.
    Inventors: Lir LOCKER, Bar MAGNEZI, Amir LANDE BLAU, Yaniv Joseph OLIVER, Or HELLER
  • Publication number: 20250141913
    Abstract: A system and method for inspecting a resource deployed in a cloud computing environment for a cybersecurity threat is presented. The method includes detecting a virtual instance deployed in a cloud computing environment, the virtual instance associated with an original disk; generating a cloned disk directly based on the original disk, wherein the original disk is provisioned storage from a cloud storage system; generating a cloned disk descriptor associated with the cloned disk, the cloned disk descriptor pointing to the provisioned storage; inspecting the cloned disk for a cybersecurity object, the cybersecurity object indicating a cybersecurity risk; and releasing the cloned disk in response to completing inspection of the cloned disk.
    Type: Application
    Filed: December 30, 2024
    Publication date: May 1, 2025
    Applicant: Wiz, Inc.
    Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
  • Patent number: 12244634
    Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.
    Type: Grant
    Filed: April 26, 2024
    Date of Patent: March 4, 2025
    Assignee: Wiz, Inc.
    Inventors: Daniel Hershko Shemesh, Yarin Miran, Roy Reznik, Ami Luttwak, Yinon Costica, Avihai Berkovitz, George Pisha, Yaniv Joseph Oliver, Udi Reitblat, Or Heller, Raaz Herzberg, Osher Hazan, Niv Roit Ben David
  • Publication number: 20240275812
    Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.
    Type: Application
    Filed: April 26, 2024
    Publication date: August 15, 2024
    Applicant: Wiz, Inc.
    Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
  • Publication number: 20240137382
    Abstract: A system and method for detecting a permission escalation event in a computing environment is disclosed. The method includes: generating a cloned disk based on an original disk of a resource deployed in a computing environment; detecting an identifier of a first principal on the cloned disk; detecting a second principal in the computing environment, the first principal authorized to assume the first principal; storing a representation of the computing environment in a security database, including: a first principal node representing the first principal, and a second principal node representing the second principal, further associated with a permission; querying the representation to determine a permission of the first principal; determining that the second principal includes a permission which the first principal does not include based on a result of querying the representation; and generating a permission escalation event.
    Type: Application
    Filed: December 29, 2023
    Publication date: April 25, 2024
    Applicant: Wiz, Inc.
    Inventors: Daniel Hershko SHEMESH, Yarin MIRAN, Roy REZNIK, Ami LUTTWAK, Yinon COSTICA, Avihai BERKOVITZ, George PISHA, Yaniv Joseph OLIVER, Udi REITBLAT, Or HELLER, Raaz HERZBERG, Osher HAZAN, Niv Roit BEN DAVID
  • Publication number: 20230221983
    Abstract: A system and method detects a vulnerable code object in configuration code for deploying instances in a cloud computing environment. The method includes: accessing a configuration code, including a plurality of code objects, where a code object of the plurality of code objects corresponds to a deployed principal; detecting in a log a plurality of access events, each access event associated with a first principal deployed in the cloud computing environment based on a first code object of the plurality of code objects; determining a first set of permissions associated with the first code object. The method also includes determining a second set of permissions based on the plurality of access events. The method also includes detecting a difference between the second set of permissions and the first set of permissions; and generating an updated code object based on the first code object and the detected difference.
    Type: Application
    Filed: December 29, 2022
    Publication date: July 13, 2023
    Applicant: Wiz, Inc.
    Inventors: Or HELLER, Raaz HERZBERG, Yaniv Joseph OLIVER, Osher HAZAN, Niv Roit BEN DAVID, Ami LUTTWAK, Roy REZNIK