MUMBAI, India, June 30 -- Intellectual Property India has published a patent application (202641054640 A) filed by Mr. Karthiban R; Ms. Monika P; Mr. Naveen Kumar P; Ms. Sandhiya C; and Ms. Sandhiya S on April 29, 2026, for Unified Blueteam Threat Detection And Alert System.
Inventors include Mr. Karthiban R; Ms. Monika P; Mr. Naveen Kumar P; Ms. Sandhiya C; and Ms. Sandhiya S.
The application for the patent was published on June 26, 2026, under issue no. 26/2026.
Abstract: ABSTRACT OF THE INVENTION 29-Apr-2026/63898/202641054640/Form 2(Title Page) A system and method for unified real-time cyber threat detection, alert generation, and automated response in endpoint computing environment is disclosed. The invention continuously ingests raw security telemetry from Windows-based endpoint log sources — including process creation, network connection, registry modification, and authentication event records — and normalizes said telemetry into a canonical event schema through a deduplication layer that assigns unique identifiers to each event. A multi-rule correlated detection engine evaluates the normalized event stream against eight independently operable detection rules, each mapped to a technique identifier within the MITRE ATT&CK adversary behavior framework, to identify patterns indicative of credential-based attacks, unauthorized privilege assignment, malicious process execution, persistence mechanism installation, lateral network movement, command-and-control communication, and credential extraction. Upon detection, each generated alert is enriched with a technique identifier, a dynamically computed risk score between zero and one hundred derived from technique-specific base weights and event context, a remediation recommendation, and an automated response descriptor. A composite risk scoring engine aggregates per-host alert weights to produce a normalized host-level threat score, enabling prioritized analyst triage. A policy-driven active response engine — configurable between a safe simulation mode and a live operational mode — automatically executes one or more defensive actions selected from the group comprising source address blocking, malicious process termination, compromised user account disabling, network-isolated host containment, and suspicious file quarantine, based on a severity-to-policy mapping. All detection events, enriched alerts, risk scores, and response actions are persisted to an auditable log store and propagated in sub-five-second latency to a real-time dashboard interface via a persistent bidirectional event channel. Keywords: threat detection, MITRE ATT&CK, automated response, risk scoring, endpoint security, SOC, Sysmon, intrusion detection
Disclaimer: Curated by HT Syndication.