The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Dec. 02, 2025

Filed:

Dec. 29, 2022
Applicant:

Wiz, Inc., New York, NY (US);

Inventors:

Or Heller, Tel Aviv, IL;

Raaz Herzberg, Tel Aviv, IL;

Yaniv Joseph Oliver, Tel Aviv, IL;

Osher Hazan, Mazkeret Batia, IL;

Niv Roit Ben David, Tel Aviv, IL;

Ami Luttwak, Binyamina, IL;

Roy Reznik, Tel Aviv, IL;

Assignee:

Wiz, Inc., New York, NY (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06F 16/901 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1441 (2013.01); G06F 16/9024 (2019.01); H04L 63/1416 (2013.01); H04L 63/1425 (2013.01);
Abstract

A system and method for detecting lateral movement in a cloud computing environment is based on configuration code. The method includes: accessing a configuration code, the configuration code including a plurality of code objects, wherein a code object of the plurality of code objects corresponds to a cloud entity deployed in the cloud computing environment; selecting an identifier of an exposed cloud entity, the cloud entity associated with a secret; querying a security graph based on the identifier to detect a node representing the secret, wherein the node representing the secret is connected to a node representing the exposed cloud entity; traversing the security graph to detect a second node connected to the node representing the secret, the second node representing a second cloud entity deployed based on the code object of the plurality of code objects; and generating a mitigation action based on the second cloud entity.


Find Patent Forward Citations

Loading…