SecureWorks Corp.
System and method for detecting and monitoring network communication
Last updated:
Abstract:
A system for collection and analysis of forensic and event data comprising a server and an endpoint agent operating on a remote system. The server is configured to receive event data including process creation data, persistent process data, thread injection data, network connection data, memory pattern data, or any combination thereof, and analyze the event data to detect compromises of a remote system. The endpoint agent is configured to acquire event data, and communicate the event data to the server.
Status:
Grant
Type:
Utility
Filling date:
17 Feb 2017
Issue date:
14 Jul 2020