The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.
The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.
Patent No.:
Date of Patent:
Apr. 08, 2025
Filed:
Apr. 29, 2022
Microsoft Technology Licensing, Llc, Redmond, WA (US);
Gueorgui Bonov Chkodrov, Redmond, WA (US);
Ryan John Littlefield, Cheltenham, GB;
Jeffrey Scott Shaw, Cheltenham, GB;
Zane Alexander Coppedge, Sedona, AZ (US);
Ying Qian, Bellevue, WA (US);
Dan Alexandru Nicolescu, Bellevue, WA (US);
Anitta M Miller, Bellevue, WA (US);
Khoi Hong, Seattle, WA (US);
Justin Matthew Powell, Seattle, WA (US);
Microsoft Technology Licensing, LLC, Redmond, WA (US);
Abstract
Methods, systems, and computer storage media for providing observation stream data of security incidents using an observation stream engine in a security management system. An observation stream framework supports continuously generating and presenting observation stream data that facilitates developing a working hypothesis of an active security incident. The observation stream framework can also include observation stream query-types that can be selected for running queries against a plurality of security data sources. In operation, an observation stream query is accessed. The observation stream query is a user-generated observation stream query associated with an observation stream query-type. The observation stream query-type comprises parameters for querying a plurality of security data sources and dynamic tracking of a security incident. The observation stream query is executed and observation stream data is generated. The observation stream data is caused to be displayed on an observation stream interface comprising data visualizations of the observation stream data.