Splunk Inc.
Threat identification-based collection of forensic data from endpoint devices
Last updated:
Abstract:
Techniques and mechanisms are disclosed enabling efficient collection of forensic data from client devices, also referred to herein as endpoint devices, of a networked computer system. Embodiments described herein further enable correlating forensic data with other types of non-forensic data from other data sources. A network security application described herein further enables generating various dashboards, visualizations, and other interfaces for managing forensic data collection, and displaying information related to collected forensic data and information related to identified correlations between items of forensic data and other items of non-forensic data.
Status:
Grant
Type:
Utility
Filling date:
23 Jul 2019
Issue date:
17 Aug 2021