Invalidity dossier
US 11740926
Techniques for securing virtual machines by analyzing data for cyber threats
Current assignee: Wiz, Inc.
Added 9/29/2026, 10:12:12 AM
Active provider: DeepSeek · deepseek-v4-flash
Auto-generating section 1 of 2: Extensions…
Each section takes ~30-60s with web-search grounding. Keep this tab open — sections will fill in below as they complete.
Patent summary
Title, assignee, inventors, filing/issue dates, abstract, and a plain-language overview of the claims.
I'll verify this patent against live sources before summarizing.
Let me check litigation/PTAB/CAFC status specifically.
Let me check for the January 2026 IPR final decision on this patent and any Federal Circuit appeal.
US Patent 11,740,926 B2 — Summary
Sourcing note: I could not query USPTO PatentCenter/PAIR directly through the tools available; this summary is grounded in the authoritative full patent text supplied in the prompt (Google Patents mirror of US11740926B2, fetched 2026-09-29) plus live web results from PTAB/USPTO filings, Docket Alarm, Unified Patents, and CourtListener. Where sources conflict or I could not confirm something, I say so below.
Bibliographic data
| Field | Value |
|---|---|
| Patent number | US 11,740,926 B2 |
| Title | "Techniques for securing virtual machines by analyzing data for cyber threats" |
| Assignee | Orca Security Ltd. (Tel Aviv, Israel) — original and current assignee; assignment recorded 2023-05-03 |
| Inventor | Avi Shua (Tel Aviv, Israel) — sole named inventor |
| Application no. | 18/055,220 |
| Filing date | 2022-11-14 (Google Patents); Unified Patents portal shows 2022-11-13 — a ±1 day timezone/record discrepancy, not a different case |
| Issue date | 2023-08-29 (Google Patents/justia); Unified Patents shows 2023-08-28 |
| Earliest priority | 2019-01-28 (US provisional 62/797,718); Unified Patents lists 2019-01-27 |
| Continuation chain | Cont. of 17/330,998 (now US 11,516,231) → cont. of 16/585,967 (now US 11,431,735) → prov. 62/797,718 |
| Publication (pre-grant) | US 2023/0092220 A1 (2023-03-23) |
| Examiners | Hassan Saadoun; Joseph P. Hirl |
| Expiration (adjusted) | 2039-09-27 (Google Patents) / 2039-09-26 (Unified Patents) |
| Claims | 15 total — independent claims 1 (method), 14 (non-transitory CRM), 15 (system) |
Abstract (as issued)
"A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority."
Note the abstract is the generic family abstract (identical wording appears in sibling members such as US 12,204,930), while the issued claims are considerably narrower than the abstract.
Independent claims in plain language
Claim 1 (method). Steps:
- Receive a request to scan a protected virtual cloud asset in a cloud computing environment.
- Locate, using an API or service provided by the cloud environment, a snapshot of at least one virtual disk of that asset.
- Access, also using a cloud-provided API or service, that snapshot.
- Analyze the snapshot to determine the existence of a plurality of potential cyber threats, where each threat is based on data stored on the virtual disk, and the data must include at least one of a specific recited list: unencrypted sensitive data; unencrypted system credentials; weak passwords; weak encryption schemes; disabled Address Space Layout Randomization (ASLR); boot record manipulation; suspicious definitions; services to be run on startup; PII; application-log data indicating the asset accessed PII; application-log data indicating the asset accessed a computer containing PII; or at least one change in at least one area of the virtual disk relative to an earlier point in time.
- Determine a risk associated with each determined threat.
- Prioritize the threats based on those per-threat risks.
- Report at least some of the threats as alerts prioritized according to their associated risks.
Conceptually: agentless cloud scanning in which the sensor is an out-of-band copy of the VM's disk snapshot obtained through the cloud provider's own APIs, not through an in-guest agent or network interception.
Claim 14 (CRM). A non-transitory computer-readable medium with instructions that cause at least one processor to perform the same seven-step operation set as claim 1 (mirror claim).
Claim 15 (system). A system with at least one processor configured to perform the same operation set as claim 1 (mirror claim). Note the claim uses inconsistent verb forms ("receive... locating... access... analyze"), a drafting defect on the face of the patent; I have not seen it construed.
Dependent claims worth noting: cl. 5 (take or request the snapshot if none exists); cl. 6–7 (filter threats by risk level, including on external exploit-likelihood intelligence); cl. 8–9 (parse and scan the snapshot; check config files, file access times, system logs); cl. 10–11 (mitigate — block untrusted traffic, halt, quarantine); cl. 12–13 (determine the allocated virtual disk; query the cloud management console for the snapshot and disk locations).
Litigation / PTAB posture (as of the search results, Jan–Mar 2026)
- Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del., filed 2023-07-12). The '926 patent was one of six Orca patents asserted (along with 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,775,326 — all same family). Case stayed 2025-01-16 pending the Wiz IPRs.
- IPR2024-01190 (Wiz, Inc. v. Orca Security Ltd., U.S. Patent 11,740,926) — filed 2024-07-31, instituted as to all claims on 2025-01-22. Oral argument held 2025-10-14 (consolidated with IPR2024-01109 and IPR2024-01191).
- This patent did not receive an adverse merits final written decision. Docket Alarm shows a "Termination Decision Post DI Settlement" in IPR2024-01190 entered 2026-01-13, followed by an expungement order on 2026-03-05. So the '926 claims were not held unpatentable in the IPR.
- By contrast, PTAB FWDs on 2025-12-08 held all claims of the sibling patents 11,663,031; 11,663,032; and 11,693,685 unpatentable (IPR2024-00863/00864/00865).
- The district court action was dismissed with prejudice by stipulated dismissal, SO ORDERED 2026-01-13 (D.I. 238), each side bearing its own fees.
Uncertainty / open items
- No CAFC 2026 docket entry for 11,740,926 could be confirmed. Because IPR2024-01190 terminated by settlement rather than by an adverse FWD, there was no PTAB merits decision on the '926 patent for Orca to appeal, and the parties dismissed the district court case with prejudice. The Feb 9, 2026 Federal Circuit appeal deadline applied to the patents that did receive adverse FWDs on 2025-12-08 ('031/'032/'685). I did not reach an authoritative confirmation of whether any such appeal was actually filed — treat that as unverified. If an appeal exists for this patent family, it is docketed under the sibling patents, not under 11,740,926.
- Google Patents flags family litigation (Darts-IP family 71731840) and lists the Delaware case and "PTAB case IPR2024-01190 filed (Settlement)," consistent with the above.
- I found no IPR2024-01190 institution-to-FWD merits outcome and no indication the '926 patent has been invalidated. One search snippet referenced "IPR2024-00220" on the '735 parent's page; I have not verified what that proceeding covers and am not asserting it relates to '926.
- Minor textual oddity: the '926 specification's Fig. 3 passage says the instructions cause the processing circuitry "to determine over-privileged roles vulnerabilities in serverless functions," which is inconsistent with the rest of the disclosure (apparent residual text from another application). I note it as an observed inconsistency, not as a legal conclusion.
Priority-date ID check
I did not auto-correct any identifiers. Note two near-miss numbers that appear in the family and should not be conflated with 11,740,926: US 11,740,926 (this patent) and US 11,740,926's sibling US 11,775,326; also the unrelated "11,740,926"/"11740926" string occurrences in the CourtListener ESI search-term exhibit are search terms in the Orca v. Wiz discovery record, not separate patents.
Generated 9/29/2026, 10:22:01 AM
Cases on file (2)
Group view →Specific litigation cases in our database that name US patent 11740926. The free-form analysis below may also discuss cases beyond this list.
- Wiz, Inc. v. Orca Security Ltd.filed Jul 31, 2024IPR2024-01190USPTO Patent Trial and Appeal Board (PTAB)terminated Jan 13, 2026terminated by settlement
Defendants: Orca Security Ltd.
- Orca Security Ltd. v. Wiz, Inc.filed Jul 12, 20231:23-cv-00758U.S. District Court for the District of Delaware (Wilmington Division)terminated Jan 13, 2026dismissed with prejudice
Defendants: Wiz, Inc.
Other patents asserted: 11663031, 11663032, 11693685, 11726809, 11775326
Litigation summary
Past and pending lawsuits — plaintiffs, defendants, jurisdictions, outcomes, and notable rulings.
I'll research litigation involving US patent 11,740,926. Let me search multiple sources.
Let me verify the PTAB proceeding status and check for any appellate or additional cases.
I have strong results. Let me do one final check for any additional/parallel cases or appellate activity.
Litigation Involving U.S. Patent No. 11,740,926
I searched litigation dockets (Docket Alarm, Unified Patents, PACER/CourtListener), the PTAB docket, and news coverage. There is one district court action and one PTAB proceeding that specifically involve U.S. Patent No. 11,740,926 ("the '926 patent"). Detail below.
Note on scope: Several results mention an unrelated "'926 patent" (e.g., the Finjan v. Symantec matter involving Finjan patents). Those involve a different patent number and are not included here. I have limited this list to matters expressly identifying U.S. 11,740,926.
1. Orca Security Ltd. v. Wiz, Inc. — District of Delaware
| Field | Detail |
|---|---|
| Plaintiff | Orca Security Ltd. (patent owner; also counterclaim-defendant) |
| Defendant | Wiz, Inc. (also counterclaim-plaintiff) |
| Jurisdiction | [U.S. District Court for the District of Delaware (Wilmington Division)](/courts/district-of-delaware-wilmington) |
| Case No. | 1:23-cv-00758 — captioned C.A. No. 23-758 (JLH) (SRF) |
| Judges | Hon. Jennifer L. Hall (presiding); Hon. Sherry R. Fallon (Magistrate) |
| Filed | July 12, 2023 |
| Cause | 35 U.S.C. § 271 — Patent Infringement |
| Status | Dismissed with prejudice (Jan. 13, 2026) |
Role of the '926 patent: Orca's operative Second Amended Complaint (filed Oct. 10, 2023, D.I. 15) asserted six patents against Wiz, including the '926 patent. The full asserted set was:
- 11,663,031; 11,663,032; 11,693,685; 11,726,809; 11,740,926; and 11,775,326.
Wiz denied infringement, challenged validity/enforceability, and filed counterclaims asserting five Wiz patents against Orca (11,722,554; 11,929,896; 11,936,693; 12,001,549; 12,003,529).
Procedural history (progression):
- Mar. 4, 2024 — Scheduling Order entered (D.I. 33).
- May–Aug. 2024 — Wiz petitioned for IPR on all six Orca patents (the '926 petition was filed July 31, 2024, D.I. 126 notice).
- Jan. 16, 2025 — The Court stayed the case pending the inter partes reviews (D.I. 232/233).
- Dec. 8, 2025 — PTAB issued Final Written Decisions in the IPRs on the '031, '032, and '685 patents, holding all claims unpatentable (joint notice filed Dec. 15, 2025).
- Jan. 13, 2026 — The parties filed a Stipulation of Dismissal; the Court entered it "SO ORDERED," dismissing all claims and defenses of both parties with prejudice, each side bearing its own costs and fees (D.I. 237/238).
Outcome: Terminated by dismissal with prejudice on January 13, 2026. No injunction, damages award, or infringement/validity judgment issued on the '926 patent — the case settled out after the adverse (for Orca) PTAB decisions on related patents.
2. Wiz, Inc. v. Orca Security Ltd. — PTAB Inter Partes Review
| Field | Detail |
|---|---|
| Petitioner | Wiz, Inc. |
| Patent Owner | Orca Security Ltd. |
| Forum | USPTO Patent Trial and Appeal Board (PTAB) |
| Proceeding | IPR2024-01190 |
| Patent challenged | U.S. 11,740,926 (all claims 1–15) |
| Petition filed / accorded filing date | July 31, 2024 |
| Institution | Instituted as to all claims on January 22, 2025 |
| Outcome | Terminated post-institution by settlement — "Termination Decision Post DI Settlement," P.T.A.B., Jan. 13, 2026 |
| Follow-on | Order granting Patent Owner's motions to expunge confidential documents, P.T.A.B., Mar. 5, 2026 |
Notes: This is the proceeding referenced in the Google Patents family data as "PTAB case IPR2024-01190 filed (Settlement)." Although the Board instituted review on all claims, the proceeding did not reach a Final Written Decision on the '926 patent — it was terminated because the parties settled, consistent with the simultaneous district-court dismissal (Jan. 13, 2026).
Related PTAB proceedings (same dispute, different patents — context only)
These do not involve the '926 patent, but arose from the same Orca/Wiz campaign and bear on how the '926 matter resolved:
- IPR2024-00863 / -00864 / -00865 (Orca's '031, '032, '685 patents) — instituted Dec. 9, 2024; Final Written Decisions Dec. 8, 2025: all claims unpatentable.
- IPR2024-01109 (Orca '809 patent) — instituted Jan. 16, 2025.
- IPR2024-01191 (Orca '326 patent) — instituted Jan. 22, 2025.
- IPR2025-01083 to -01087 — Orca's IPRs against Wiz's asserted patents ('554, '896, '693, '549, '529).
Summary
- District court: One case — Orca Security Ltd. v. Wiz, Inc., No. 1:23-cv-00758 (D. Del.), filed July 12, 2023; the '926 patent was one of six asserted; the case was stayed Jan. 16, 2025 and dismissed with prejudice Jan. 13, 2026.
- PTAB: One proceeding — IPR2024-01190, Wiz v. Orca, challenging the '926 patent; instituted Jan. 22, 2025, then terminated by settlement Jan. 13, 2026.
- Federal Circuit: No appeal involving the '926 patent was identified. (Appeal deadlines noted in the December 2025 joint filing pertained to the other Orca patents — the '031, '032, and '685 — not the '926.)
If you need the actual PTAB filings (Petition, Patent Owner Response, institution and termination decisions) or the Delaware docket entries, they are accessible via the USPTO PTAB portal (IPR2024-01190) and PACER/CourtListener for D. Del. 1:23-cv-00758.
Confidence: High on the two matters and the case/proceeding numbers, parties, forum, and dates as reported by Docket Alarm/Unified Patents and the parties' own court filings. I did not independently verify a PACER docket sheet for the docket no. beyond what the aggregated sources and filed PDFs show.
Generated 9/29/2026, 10:22:04 AM
Proceedings on file (0)
All PTAB activity →AIA trial proceedings (IPR / PGR / CBM) filed at the USPTO Patent Trial and Appeal Board against this patent. Sourced from the USPTO Open Data Portal and refreshed every six hours; each proceeding number deep-links to the PTAB E2E docket.
Current assignee: Wiz, Inc.
No PTAB proceedings on file. This patent has not been challenged via IPR, PGR, or CBM. The absence is itself a signal — well-asserted patents eventually attract IPRs. The LLM analysis below may surface filings the ODP feed hasn’t indexed yet.
PTAB challenges
AIA trial proceedings at the USPTO Patent Trial and Appeal Board — IPR, PGR, and CBM. Petitioners, judge panels, claim-level invalidation outcomes from Final Written Decisions, and Federal Circuit appeals. The single most important defensive datapoint after litigation history.
I'll verify the structured data against web sources before writing anything up.
The structured block says no PTAB activity, but search results surface a live proceeding on this exact patent. Digging deeper.
Now let me pin down the institution decision, grounds, and any appeals.
⚠️ Threshold discrepancy — the structured data is incomplete
The "PTAB proceedings on file" block states the USPTO ODP API returns no AIA trial proceedings for US11740926. That is incorrect as of today. Web sources document a fully-litigated IPR on this exact patent (Wiz, Inc. v. Orca Security Ltd., IPR2024-01190) that ran for ~18 months, went to oral hearing, and was terminated by settlement in January 2026. Google Patents' own machine-readable record for this patent also carries a "PTAB case IPR2024-01190 filed (Settlement)" entry. Treat the ODP "no proceedings" result as a stale/missed index, not as evidence of no PTAB activity. (Note also: Google Patents attributes that entry to its "Unified Patents PTAB Data" feed — Unified Patents is not a petitioner here.)
Proceedings overview
Total: 1 AIA trial proceeding on US11740926 — IPR2024-01190 — status: settled post-institution, pre-Final Written Decision (0 invalidated / 0 sustained / 1 settled / 0 institution denials). All 15 claims were challenged, the Board instituted, and the case settled after oral hearing but before any merits decision. This means the patent leaves the PTAB with all 15 claims intact and no estoppel attached to anyone — the defensive posture is "the patent has not been tested to judgment," not "the patent is hardened." For a defendant, the most valuable takeaway is negative space: the Federal Circuit never reviewed it, no FWD ever construed the claims, and the District of Delaware case that spawned the IPR was dismissed with prejudice on 2026-01-13. But the sibling patents in this family were invalidated over the same Veselov art in December 2025 — read on.
IPR2024-01190 — Wiz, Inc. v. Orca Security Ltd.
- Type: Inter Partes Review (35 U.S.C. §§ 311–319)
- Filed: 2024-07-31 (PTAB notice of filing date issued 2024-08-15)
- Status: Terminated — settlement after institution, before Final Written Decision ("Termination Decision Post DI Settlement," Paper 88, 2026-01-13; joint motion filed 2026-01-07)
- Judge panel: Michael R. Zecher, Daniel J. Galligani, and Garth D. Baer, APJs (per the consolidated oral hearing transcript, hearing held 2025-10-14). A Panel Change Order (Paper 82) issued 2025-11-19, after the hearing — the identity of the substituted panel is not disclosed in the sources I retrieved.
- Petition grounds: Challenged all claims of the '926 patent (claims 1–15) — method claim 1, CRM claim 14, system claim 15. Orca's own request for additional discovery confirms that "every Ground in these Proceedings is based on obviousness" (i.e., 35 U.S.C. § 103, no § 102 or § 112 theories). The primary reference was Veselov — U.S. Patent No. 11,216,563 (filed 2017-05-19, Amazon-assigned), the same "agentless scanning via snapshot" reference Wiz used across all six Orca asserted patents. For the '926 proceeding, the Petitioner's reply declaration is organized around a "Veselov–Mohanty Combination" mapping elements 1.5–1.6 / 14.5–14.6 / 15.5–15.6 — i.e., Veselov as to the independent claims with Mohanty as secondary. I could not retrieve the complete ground-by-ground lineup for this specific petition from public sources; do not treat the above as exhaustive.
- Institution decision: Instituted. Confirmed directly by Petitioner's expert ("I understand that this IPR was instituted"). The Board was expected to decide by 2025-01-31 (per Orca's 2024-08-23 notice to the district court). I was unable to retrieve the institution paper itself, so the exact date and the panel's stated reasoning at institution are not confirmed here — pull Paper 11/12 from PTAB E2E to verify.
- Final Written Decision: None issued. This is the single most important fact about this proceeding. There is no claim-level verdict — no claim of the '926 patent was canceled, and none was held patentable. Trial was terminated ~2 weeks after briefing concluded and ~2 months after oral argument, in the pre-FWD window.
- Settlement / termination: The parties filed a Joint Motion to Terminate Inter Partes Review on 2026-01-07, citing 35 U.S.C. § 317(a) and 37 C.F.R. §§ 42.72, 42.74, and stating they "have reached a settlement" resolving "all disputes between the Parties regarding the Patent-in-Suit." A copy of the confidential settlement agreement was filed as Ex. 2429, with a concurrent Joint Request to Keep Separate under § 42.74(c) — so the terms are confidential and not on the public record. The Board granted termination on 2026-01-13. The motion expressly invoked the line of authority (Comcast v. Rovi; Cox v. AT&T) allowing termination post-hearing where no FWD has entered.
- Parallel litigation: Orca Security Ltd. v. Wiz, Inc., C.A. No. 1:23-cv-00758-JLH-SRF (D. Del.), filed 2023-07-12, asserting six patents ('031, '032, '685, '809, '926, '326). The case was stayed pending the IPRs, then dismissed with prejudice by joint stipulation filed 2026-01-06 and so-ordered 2026-01-13 by Judge Jennifer L. Hall, each side bearing its own fees and costs. Docket: https://www.courtlistener.com/docket/67600951/orca-security-ltd-v-wiz-inc/
- Appeal: None. No FWD means no appealable final agency action; I found no Federal Circuit docket (no CAFC appeal of this IPR, no cross-appeal). The settlement and the with-prejudice dismissal closed off that path.
- Defensive value: This proceeding gives a defendant facing assertion of US11740926 almost nothing to cite at the PTAB — there is no FWD, so there is no claim-cancellation, no claim construction, and no estoppel. What it does give you is a roadmap: Wiz's Veselov-based § 103 theory was good enough to clear institution on all 15 claims, and the same art killed three sibling patents at the Board in December 2025 (below). An IPR-based defense is not foreclosed — it is, if anything, un-priced.
Strategic summary
Claim status — 15 of 15 claims are UNTESTED by the PTAB. No claim of US11740926 was canceled, narrowed, or confirmed in any AIA trial. Claims 1–15 (including independent claims 1, 14, and 15) stand as issued. Any FWD-based "claim 1 is dead" argument is unavailable here; conversely, a defendant cannot point to any Board holding that a claim survived scrutiny either. The patent is neither hardened nor wounded on the AIA record.
Estoppel landscape — the field is clear for everyone. Section 315(e)(2) estoppel attaches only where an IPR "results in a final written decision under section 318(a)." Because IPR2024-01190 was terminated by settlement before any FWD, no § 315(e)(1) or (e)(2) estoppel binds Wiz, or anyone in privity with Wiz, as to the '926 patent. Practically: the Veselov/Mohanty obviousness ground that Wiz pressed to oral hearing is not spent. A new petitioner (or Wiz itself, if Orca re-asserts the patent on new facts) can file a fresh petition raising Veselov-based § 103 grounds, subject only to the usual § 315(b) one-year bar running from service of a new complaint, and to whatever the Director does with § 325(d) / discretionary-denial analysis. Note the current policy environment: institution decisions are now made by the Director (per the October 2025 Squires memo), which practitioners expect to tighten institution rates — budget for that risk.
Pattern signals — this is a coordinated multi-patent campaign, not a lone IPR. Wiz filed IPRs against all six Orca asserted patents between May 2024 and August 2024: IPR2024-00220 ('735); IPR2024-00863, -00864, -00865 (filed 2024-05-24, against the '031, '032, '685); IPR2024-01109 (filed 2024-07-01, against the '809); IPR2024-01190 (2024-07-31, this patent, the '926); and IPR2024-01191 (2024-08-07, the '326). The latter three — -01109, -01190, -01191 — were consolidated for a single oral hearing on 2025-10-14 before the same three-APJ panel. No defensive aggregator is in the chain — Unified Patents appears only as the third-party data feed behind Google Patents' litigation metadata, not as a petitioner. Orca, for its part, has sued as a patent owner here and appears in at least one proceeding as a petitioner on a third party's patent (U.S. 11,929,896, "unified graph models for network entities") — it is a two-sided actor, not a passive NPE.
The December 2025 signal you should not miss. Press reporting (CTech/Calcalist, January 2026) states that in December 2025 the PTAB ruled all claims of three of the six asserted Orca patents unpatentable, including the two patents that formed the original backbone of the 2023 complaint. Those FWDs most plausibly correspond to the '031 / '032 / '685 patents (IPR2024-00863/-00864/-00865, instituted December 2024, FWDs due ~December 2025). I could not retrieve those FWDs directly, and they are not decisions on US11740926 — do not represent them as such. But they matter: the same Veselov reference drove Wiz's challenge across the family, and Orca's POPR-level attempts to distinguish Veselov ("an instantiated VM is not a 'snapshot'"; "analysis of a VM instantiated from a snapshot is not an analysis of a snapshot") were hauled into the Delaware claim-construction fight as alleged prosecutorial inconsistency. If the Board invalidated the sibling claims over Veselov, the '926 claims — drawn to the same snapshot-analysis concept — face a materially worse validity outlook than their "clean" PTAB record suggests.
Second-order caution. All six patents claim priority to the same provisional (62/797,718), but there are two base applications in the family: the '031 patent descends from abandoned App. No. 16/750,556 and has additional specification content; the rest (including the '926) descend from App. No. 16/585,967 and share a common specification. That shared-specification fact cuts both ways for claim construction and for written-description/§ 112 challenges.
Recommended next steps
- Verify the proceeding record from primary sources before relying on anything above. PTAB E2E / PTACTS: case IPR2024-01190 — retrieve the Institution Decision, the Joint Motion to Terminate (Paper 85, filed 2026-01-07), the Termination Decision (Paper 88, 2026-01-13), and the Panel Change Order (Paper 82, 2025-11-19). Docket mirror: https://www.docketalarm.com/cases/PTAB/IPR2024-01190/Wiz_Inc._v._Orca_Security_Ltd/ — Joint Motion: https://www.docketalarm.com/cases/PTAB/IPR2024-01190/Wiz_Inc._v._Orca_Security_Ltd/docs/01-07-2026-Patent_Owner/Motion__Motion_to_terminate_due_to_settlement_post_DI-85-Joint_Motion_to_Terminate_Inter_Partes_Review.pdf — Oral Hearing Transcript (2025-10-14): https://www.docketalarm.com/cases/PTAB/IPR2024-01190/Wiz_Inc._v._Orca_Security_Ltd/docs/11-26-2025-Petitioner/Other__other-83-Redacted_Oral_Hearing_Transcript.pdf
- There is no FWD to link or quote, and I will not manufacture one. The disposition is a settlement termination, not a merits decision. If a counterparty (or an ODP-derived chart) tells you the '926 claims were "invalidated," that is wrong — the invalidations reported in December 2025 were on sibling patents.
- If you are a defendant and Orca demands on US11740926: your best PTAB play is a fresh IPR built on Veselov (U.S. 11,216,563), which is not estopped as to this patent and which is publicly documented as sufficient to institute on all 15 claims. Pair it with a § 112 indefiniteness / written-description attack on "snapshot" and "analyzing the snapshot," leveraging Orca's own POPR statements (Ex. 27/28 in the Delaware record) that its claims exclude analysis of a VM instantiated from a snapshot — positions in tension with its district-court infringement theory. Watch Fintiv/§ 325(d) and the new Director-level institution regime.
- No active proceedings to track. Nothing is pending on US11740926; the statutory 1-year § 316(a)(11) trial clock is not running on any case. The only deadlines that existed (institution by 2025-01-31; FWD due ~January/February 2026) are moot.
- Confirm the litigation endpoint's scope. The 2026-01-13 with-prejudice dismissal resolves Orca↔Wiz only. It does not invalidate the patent or estop Orca against other accused parties. Check whether any new complaint asserting the '926 patent has been served since 2026-01-13 — the 1-year § 315(b) clock for any new defendant starts from that service date.
Generated 9/29/2026, 10:22:40 AM
Ownership chain (1)
Asserters network →Structured records extracted from the assignment-history narrative below. Each entity links to its full ownership-network profile.
? · recorded 2023-05-03 · Assignment
internal founder/employee assignment
Assignment history
Inventors, original assignee, and the chain of ownership recorded with the USPTO — including the correspondent attorney who recorded each assignment, since shell-LLC chains often share one repeat-player attorney even when the entity names look unrelated. Surfaces NPE / patent-troll patterns: shell-entity transfers, known asserters in the chain, repeat correspondent fingerprints, pre-litigation assignments, and bankruptcy fire-sales.
I'll verify the assignment record for US 11,740,926 against live sources before reconstructing the chain.
Let me dig into the specific assignment record and the correspondent/attorney details.
Let me pin down the specific reel/frame and check for any security agreements or additional assignments in the Orca chain.
I've gathered enough on the ownership record. Note the constraint I ran into: I could not directly query USPTO Assignment Center (no direct API/tool access), so the below is reconstructed from Google Patents legal events, USPTO file histories surfaced in PTAB submissions, Docket Alarm, and the litigation record. I flag every point where the reel/frame or correspondent could not be confirmed rather than inventing one.
Inventors
| Inventor | Residence | Employer at filing (determinable) |
|---|---|---|
| Avi Shua (sole named inventor) | Tel Aviv, Israel | Orca Security Ltd. — co-founder; ADS signature block lists his title as CEO at the time |
Evidence and notes:
- Every patent in the asserted family names Avi Shua as the sole inventor (confirmed in Orca's own IPR filing: "All six patents name Avi Shua, Orca's co-founder and current Chief Innovation Officer, as the sole named inventor").
- The inventor's mailing address on the file-history power of attorney is "c/o Orca Security LTD., 65 Yigal Alon St., Tel Aviv 6744316 ISRAEL," and the same document was signed 2019-09-26 — i.e., the inventor was operating out of Orca's address before the first non-provisional was even filed.
- Orca co-founder Gil Geron is named in press coverage as a co-founder of the company but is not an inventor on this patent — a normal single-inventor pattern for this portfolio, not a red flag.
- Unusual-pattern check: No evidence of inventors departing upstream of a fire-sale. The sole inventor remained affiliated with the assignee (CEO → Chief Innovation Officer) throughout the relevant period. Not present.
Original assignee
- Orca Security Ltd. (Tel Aviv, Israel) — original and current assignee (Google Patents legal events; current-assignee field; no subsequent transfer recorded).
- Primary line of business: Cloud-native security / CNAPP vendor. Its core product, SideScanning™, is the direct commercial embodiment of the claims — agentless, API-and-snapshot-based cloud workload inspection. Orca's own materials market the platform as "built on Orca's patented SideScanning technology."
- Shipped a product embodying the claims: yes. This is well documented. Orca represented to the PTAB that SideScanning™ practices claims 1, 16, and 19 of the sibling patent (Declaration of Avi Shua, IPR2024-01109, Ex. 2074), that it raised $6.5M in 2019, $75M in 2020, and $550M by 2021 at a $1.2–1.8B valuation on the strength of the technology, and that it earned significant revenue from the SideScanning-powered platform.
- Current status (as of the sources fetched): Privately held, venture-backed operating company. I could not confirm in the fetched material any acquisition, dissolution, or bankruptcy of Orca Security through 2026 — treat "still independent/operating" as the last confirmed data point (the Jan 2026 litigation dismissal and settlement), not a verified 2026 status.
Assignment timeline
Bottom line: there is a single recorded assignment, and it stays inside the operating company. USPTO Assignment Center does show a record (via Google Patents legal events), so I do not stop after this section.
- Execution date: not confirmed / recorded 2023-05-03 — Reel/Frame not retrievable from the sources fetched
- Conveyance: Assignment of Assignors' Interest (Google Patents legal-event text: "ASSIGNMENT OF ASSIGNORS' INTEREST (SEE DOCUMENT FOR DETAILS)")
- Assignor: Avi Shua
- Assignee: Orca Security Ltd.
- Correspondent: Not confirmed for the recorded assignment itself. I could not retrieve the recording correspondent's name from the available sources. What is documented on the family: Finnegan, Henderson, Farabow, Garrett & Dunner, L.L.P. is the attorney/agent of record for prosecution (it appears as the "(74) Attorney, Agent, or Firm" on the sibling US 11,726,809, submitted the corrected ADS in the family, and one of its attorneys signed a terminal disclaimer). A power-of-attorney document in the family's file histories also names M&B IP Analysts, LLC (Michael Ben-Shimon, 45 S. Park Place #262, Morristown, NJ). I am flagging both firms as prosecution-side actors only — neither is evidence of a repeat NPE correspondent, and I will not attribute the assignment recording to either without the reel/frame.
- Context: Internal founder/employee assignment — the inventor's standard conveyance of rights to his employer/operating company. Recorded roughly two months before Orca filed suit against Wiz, but it is the original corporate assignment (the right vesting chain), not a pre-litigation transfer to an asserting entity.
Cross-reference / contradiction flag:
- Google Patents shows exactly one legal event for this application number ("Assigned to Orca Security LTD., 2023-05-03"). I found no security agreement, merger, change of name, license, release, or correction recorded against US 11,740,926. If such records exist on Assignment Center, my sources did not surface them.
- Timing discrepancy to note (consistent with the prior section): the recorded date 2023-05-03 is a USPTO recording date for the continuation; the invention was assigned far earlier in substance (the inventor's POA/assignment documents date to 2019-09-26/27, around the parent filing). Do not read the 2023 date as the date Orca acquired the rights.
- Manual verification link: https://assignment.uspto.gov/patent/index.html (search patent number 11740926) and https://assignmentcenter.uspto.gov/. I was unable to open the underlying reel/frame page through the tools available.
Timeline diagram
timeline
title Ownership of US 11740926
2019 : Orca co-founded by Avi Shua
: Shua assigns rights to Orca
: Provisional filed
2021 : Orca raises 550M USD
2022 : Continuation filed
2023 : Assignment recorded with USPTO
: Patent issued
: Orca sues Wiz
2024 : Wiz files IPR petition
2025 : IPR instituted
2026 : IPR settled and suit dismissed
NPE / troll-pattern signals
Shell-entity transfer — Not present. No assignee carries an "IP / Patents / Licensing / Holdings / Ventures" suffix. The assignee is and remains Orca Security Ltd., a venture-backed operating company with a marketed product (SideScanning™) and revenue. The only recorded conveyance is inventor → operating company.
Known asserter in the chain — Not present. Orca Security does not appear on the enumerated NPE lists or in RPX/Unified high-frequency-plaintiff directories as an NPE. It appears in the litigation record as the plaintiff operating company asserting against a direct competitor — the opposite posture.
Repeat correspondent across the chain — Not applicable / unclear. There is only one link in the chain, so recurrence cannot be assessed. The documented family correspondent is a large general-practice prosecution firm (Finnegan) that does both operating-company and other patent work — a single appearance is not a finding, and no recurrence exists to flag.
Cascading transfers — Not present. One recorded assignment; no chained LLC hops within 24 months or at any time.
Pre-litigation transfer — Not present (as an NPE tell). The 2023-05-03 record lands ~2 months before the 2023-07-12 suit, but it is the inventor's original corporate assignment vesting title in the operating company, not an arranged transfer into an asserting vehicle to fix standing or venue. The rights originated with Shua and never left Orca.
Bankruptcy fire-sale — Not present. No Chapter 7/11, no assignment out of an estate, no sold-patent docket.
Privateering — Not present. Orca asserts its own patents; there is no evidence of an operating company transferring to an NPE to assert on its behalf. The litigation is a first-party competitor suit (Orca Security Ltd. v. Wiz, Inc., D. Del. 1:23-cv-00758).
Defensive aggregator — Not present. The chain does not terminate at RPX, AST, LOT, Unified, or OIN. (Note the inverted case: Unified Patents is on the attacking side here, not the owner — Google Patents flags IPR2024-01190, filed against this patent by Wiz and terminated by settlement.)
Verdict
Operating-company assertion.
Justification: The sole recorded conveyance is the inventor Avi Shua → Orca Security Ltd. (recorded 2023-05-03), and the patent has never left the operating company — there is no shell-entity transfer, no cascading LLC chain, and no defensive-aggregator endpoint. Orca Security is a venture-backed operating vendor whose SideScanning™ product embodies the claims, and it asserted the '926 patent in Orca Security Ltd. v. Wiz, Inc. (D. Del. 1:23-cv-00758, filed 2023-07-12) against a direct competitor. That is a classic operating-company-versus-competitor posture, not NPE monetization; the assignment-recording reel/frame and its correspondent could not be verified through the available tools and should be confirmed directly at https://assignment.uspto.gov/patent/index.html before reliance.
Generated 9/29/2026, 10:22:37 AM
Prior art
Earlier patents, publications, and products that may anticipate or render the claims unpatentable.
I'll pull the USPTO citation record for US 11,740,926 and verify each cited reference. Let me search.
The searches returned unrelated results. Let me target the patent's own pages and front-page citation record directly.
Let me get the patent's front-page citation list and the IPR2024-01190 grounds (which identify the examiner/petitioner's key art).
I hit the tool-step limit before I could retrieve the full front-page citation list and a few ID confirmations, so I'll answer with what is verified and flag what is not.
Prior art analysis — U.S. Patent No. 11,740,926
Target patent (literal ID, not auto-corrected): US 11,740,926 B2, "Techniques for securing virtual machines by analyzing data for cyber threats," app. 18/055,220, filed 2022-11-14, granted 2023-08-29, assignee Orca Security Ltd., sole inventor Avi Shua, earliest priority 2019-01-28 (prov. 62/797,718). 15 claims: independent claim 1 (method), claim 14 (non-transitory CRM), claim 15 (system). Because the patent has a 2019 effective filing date, AIA 35 U.S.C. § 102 governs (not pre-AIA § 102).
Sourcing note / limitation on this answer
- I could not query USPTO PatentCenter or PAIR directly — the tools available are web search only, and a search framed as "USPTO database for 11740926" returned unrelated documents (e.g., US 1,717,769 for bituminous pavement). I grounded the citation list in the authoritative full patent text supplied in the prompt (Google Patents mirror of US11740926B2, fetched 2026-09-29), which is the USPTO-issued front page.
- The "Citations (50)" block on that front page is truncated in the supplied text after the 36th entry (US 2019/0065754 A1). I recovered 36 of the 50 cited references. The remaining ~14 are unverified by me; I will not guess at them.
- The two documents in the "Cited By (2)" list (US 2022/0261804 A1, AmEx; US 2024/0126882 A1, HP) are later publications citing the '926 patent — they are not prior art and are excluded.
- No reference was ever adjudicated to anticipate or render obvious the '926 claims: IPR2024-01190 (Wiz v. Orca) was instituted on all claims 2025-01-22, but terminated post-institution by settlement (Board decision 2026-01-13), expungement order 2026-03-05 — no Final Written Decision. Orca v. Wiz, No. 1:23-cv-00758 (D. Del.) was dismissed with prejudice 2026-01-13. So everything below is a theoretical § 102/§ 103 assessment.
Interpretive convention used below: If a reference arguably discloses every step of claim 1, it would equally reach the mirror claims 14 (CRM) and 15 (system), which recite the same operation set. I state that once here and do not repeat it per row.
Critical caveat on § 102: Every reference below was cited on the face of the patent and therefore considered during prosecution, and the claims issued over them. A § 102 anticipation theory against the issued claims requires the reference to disclose each and every limitation — most importantly the claim 1 limitation of performing the locate/access steps "using an API or service provided by the cloud computing environment" and the twelve-item enumerated disk-data list ("at least one of unencrypted sensitive data … personally identifiable information … at least one change in at least one area of the virtual disk, as compared to an earlier point in time"). Pre-2019 references almost never recite cloud-provider APIs for snapshot location, so the honest characterization of most of this art is § 103 fodder, not clean § 102 anticipation.
A. The 36 cited references I could verify, with § 102 assessment
| # | Full citation | Date (priority / publication) | Brief description | Claim(s) it could arguably anticipate under § 102 |
|---|---|---|---|---|
| 1 | US 2007/0266433 A1 — Hezi Moore, "System and Method for Securing Information in a Virtual Computing Environment" | 2006-03-03 / 2007-11-15 | Securing information in a virtualized computing environment | Claim 1 (general VM security framework) — weak; no snapshot/cloud-API teaching |
| 2 | US 2008/0189788 A1 — Microsoft, "Dynamic risk management" | 2007-02-06 / 2008-08-07 | Dynamic security risk scoring of assets | Claims 1 (risk-determination/prioritization/reporting limbs), 6, 7 (filtering by risk level; filtering on likelihood of exploitation) |
| 3 | US 2008/0263658 A1 — Microsoft, "Using antimalware technologies to perform offline scanning of virtual machine images" | 2007-04-17 / 2008-10-23 | Offline/out-of-band scanning of VM images rather than in-guest | Claims 1 (analyze an offline copy), 8, 9 (parse and scan config files/logs) — but VM image, not snapshot, and no cloud-API limitation |
| 4 | US 2009/0007100 A1 — Microsoft, "Suspending a Running Operating System to Enable Security Scanning" | 2007-06-28 / 2009-01-01 | Suspending a live OS to allow scanning of its state | Claim 5 (concept of taking a state copy while the machine runs); arguably claim 1's "snapshot" |
| 5 | US 2010/0017512 A1 — IBM, "Method and System For Improvements In or Relating to Off-Line Virtual Environments" | 2008-07-21 / 2010-01-21 | Off-line analysis of virtual environments | Claim 1 (offline disk analysis) |
| 6 | US 2011/0289584 A1 — CA (Computer Associates), "Systems and methods to secure backup images from viruses" | 2010-05-18 / 2011-11-24 | Malware/vuln scanning of backup images | Claim 1 (scanning a point-in-time copy equivalent to a snapshot); claim 8 |
| 7 | US 2012/0072968 A1 — Wysopal (Veracode), "Assessment and analysis of software security flaws in virtual machines" | 2007-02-16 / 2012-03-22 | Static assessment of software security flaws in VMs | Claim 1 (analyze for vulnerabilities); claim 8 (scanning parsed content) |
| 8 | US 2012/0323853 A1 — Microsoft, "Virtual machine snapshotting and analysis" | 2011-06-17 / 2012-12-20 | Take a VM snapshot and analyze it out-of-band | Claims 1, 5, 8, 12, 13 — the closest prosecution-cited reference on the snapshot concept; no cloud-service-API limitation, and no enumerated sensitive-data list |
| 9 | US 2013/0191643 A1 — Fujitsu, "Establishing a chain of trust within a virtual machine" | 2012-01-25 / 2013-07-25 | Integrity/chain-of-trust in a VM | Claim 1 (integrity verification of disk content) — weak |
| 10 | US 2013/0247133 A1 — McAfee, "Security assessment of virtual machine environments" | 2011-10-13 / 2013-09-19 | Security posture assessment of VM environments | Claim 1 (assess VM for threats); claims 8, 9 |
| 11 | US 2014/0089916 A1 — CA, "Centralized, policy-driven maintenance of storage for virtual machine disks (VMDKs) and/or physical disks" | 2012-09-26 / 2014-03-27 | Managing/accessing VMDK storage | Claim 12 (determining the virtual disk allocated to the asset); claim 13 (disk location) |
| 12 | US 2014/0096135 A1 — IBM, "Method for authenticated distribution of virtual machine images" | 2012-10-01 / 2014-04-03 | Authenticated VM image distribution | Claim 1 (image handling) — weak |
| 13 | US 2014/0137190 A1 — Rapid7, "Methods and systems for passively detecting security levels in client devices" | 2012-11-09 / 2014-05-15 | Passive, non-agent detection of security levels | Claim 1 (agentless/passive detection) |
| 14 | US 2015/0052520 A1 — IBM, "Method and apparatus for virtual machine trust isolation in a cloud environment" | 2013-08-19 / 2015-02-19 | Trust isolation of VMs in a cloud | Claim 1 (cloud VM context) — weak |
| 15 | US 9,069,983 B1 — Symantec, "Method and apparatus for protecting sensitive information from disclosure through virtual machine files" | 2009-04-29 / 2015-06-30 | Detecting sensitive data exposed via VM disk files | Claim 1's "unencrypted sensitive data" / "personally identifiable information" limbs, and the specification's higher-priority alerting for sensitive data |
| 16 | US 9,177,145 B2 — Sophos, "Modified file tracking on virtual machines" | 2009-03-24 / 2015-11-03 | Tracking modified files on a VM disk | Claim 1's "at least one change in at least one area of the virtual disk, as compared to an earlier point in time" limb; claims 2, 3, 4 (unexpected change; added/changed files without installation; cryptographic-hash comparison of a disk area). This is the single best § 102 match to the change-detection claim family |
| 17 | US 9,229,758 B2 — IBM, "Passive monitoring of virtual systems using extensible indexing" | 2011-10-28 / 2016-01-05 | Passive (out-of-band) monitoring of virtual systems | Claim 1 (passive/agentless analysis) |
| 18 | US 2016/0004449 A1 — Hedvig, "Storage system with virtual disks" | 2014-07-02 / 2016-01-07 | Virtual-disk storage architecture | Claims 12, 13 (virtual disk infrastructure) — weak |
| 19 | US 9,268,689 B1 — Symantec, "Securing virtual machines with optimized anti-virus scan" | 2012-03-26 / 2016-02-23 | Offloaded/optimized AV scanning of VM disks | Claims 1, 8 (scanning disk content for threats) |
| 20 | US 2016/0094568 A1 — IBM, "Automated response to detection of threat to cloud virtual machine" | 2014-09-25 / 2016-03-31 | Automated response/remediation on cloud-VM threat detection | Claims 10, 11 (mitigate: block traffic, halt VM, quarantine) and claim 6 (risk-based filtering); also relevant to claim 1's reporting step |
| 21 | US 2016/0241573 A1 — Fisher-Rosemount, "Security event detection through virtual machine introspection" | 2015-02-13 / 2016-08-18 | Detecting security events by VM introspection | Claim 1 (out-of-guest inspection) |
| 22 | US 9,519,781 B2 — Cyphort, "Systems and methods for virtualization and emulation assisted malware detection" | 2011-11-03 / 2016-12-13 | VM/emulation-assisted malware detection | Claim 1 (analyze a virtualized instance for threats) |
| 23 | US 2016/0364255 A1 — IBM, "Optimizing provisioning through automated virtual machine template generation" | 2015-06-15 / 2016-12-15 | VM template/image generation | Claim 12 (image/disk determination) — weak |
| 24 | US 2017/0011138 A1 — Synopsys, "System and method for hierarchical power verification" | 2015-07-07 / 2017-01-12 | Chip power verification | No cyber/VM-security relevance — cited for background only |
| 25 | US 2017/0031704 A1 — Hewlett-Packard, "Network port profile for virtual machines using network controller" | 2015-07-31 / 2017-02-02 | VM network profile management | No relevant claim — background |
| 26 | US 9,563,777 B2 — IBM, "Security policy generation based on snapshots of similar virtual machines" | 2015-04-29 / 2017-02-07 | Using VM snapshots to generate security policy | Claims 1, 5, 12, 13 (snapshot obtainment and comparability) |
| 27 | US 2017/0111384 A1 — SecludIT, "Method for detecting vulnerabilities in a virtual production server of a virtual or cloud computer system" | 2015-10-16 / 2017-04-20 | Detecting vulnerabilities in a production virtual/cloud server by inspecting its disk/instance rather than via agent or network scan | The best prosecution-cited candidate for § 102 against claim 1, and for claims 8, 9, 12, 13. It is squarely on-point for "screen the production virtual machine's disk for vulnerabilities"; the open questions are whether it locates/accesses a snapshot via cloud-provider API/service and whether it recites the enumerated disk-data list, per-threat risk scoring and prioritization |
| 28 | US 9,734,325 B1 — Forcepoint Federal, "Hypervisor-based binding of data to cloud environment for improved security" | 2013-12-09 / 2017-08-15 | Hypervisor-level data binding in cloud | Claim 1 (out-of-guest cloud data access) — weak |
| 29 | US 9,756,070 B1 — Amazon Technologies, "Scanning machine images to identify potential risks" | 2014-11-10 / 2017-09-05 | Cloud-provider service that scans machine images (AMIs) to identify potential security risks | Claims 1, 8, 12 — highly relevant: a cloud-provider-native scanning service. Distinguishing features: machine images rather than snapshots of a virtual disk of a live asset, and no per-threat risk/prioritization/alerts |
| 30 | US 9,858,105 B1 — Amazon Technologies, "Service for managing custom virtual machine images" | 2015-11-24 / 2018-01-02 | Cloud service for managing custom VM images | Claims 12, 13 (disk/image location via cloud service) |
| 31 | US 2018/0052762 A1 — Red Hat, "Build failure management in continuous integration environments" | 2016-08-22 / 2018-02-22 | CI build-failure management | No relevant claim — background |
| 32 | US 2018/0137032 A1 — Atlassian, "Systems and methods for testing source code" | 2016-11-11 / 2018-05-17 | Source-code testing | No relevant claim — background |
| 33 | US 2018/0255080 A1 — ResponSight, "System and Method for Cyber Security Threat Detection" | 2017-03-02 / 2018-09-06 | Cyber-threat detection (behavioral) | Claim 1 (threat detection/reporting) — weak |
| 34 | US 10,079,842 B1 — Amazon Technologies, "Transparent volume based intrusion detection" | 2016-03-30 / 2018-09-18 | Intrusion detection by inspecting cloud volumes out-of-band (transparently, no agent) | Claim 1 (agentless, out-of-band volume inspection via the cloud platform) — significant for the "without an agent / cloud-service access" theme; no vulnerability/PII list |
| 35 | US 2018/0293374 A1 — Red Hat, "Runtime non-intrusive container security introspection and remediation" | 2017-04-11 / 2018-10-11 | Non-intrusive (agentless) introspection plus remediation of running containers | Claims 1, 10, 11 (agentless introspection; block/halt/quarantine remediation) |
| 36 | US 2019/0065754 A1 — Microsoft Technology Licensing (title truncated in the supplied record — unverified) | 2017-08-31 / 2019-02-28 | Not confirmed | Date note: published 2019-02-28, after the 2019-01-28 priority date, so it is not § 102(a)(1) art; it could only qualify under § 102(a)(2) (U.S. application publication effectively filed 2017-08-31, naming another inventor). Claim mapping not assessable on the information I have |
Not retrieved (≈14 of the 50): I cannot supply citations, dates, or claim mappings for the remaining entries beyond US 2019/0065754 A1. I am explicitly flagging these as unknown rather than reconstructing them.
B. Most relevant prior art overall — including art the examiner did not cite
The prosecution citations above are largely generic VM-inspection art. The materially most probative prior art on this family came from the IPR record, not the patent face:
- U.S. Patent No. 11,216,563 (Veselov), filed 2017-05-19, assigned to Amazon — the primary reference in IPR2024-01190, relied on for all claims 1–15 of the '926 patent in an obviousness combination with Mohanty. Per Wiz's district-court briefing, Veselov "disclosed the same 'agentless' security solution as that described in Orca's Asserted Patents," and the same Veselov-based combination was the primary art across all six asserted Orca patents. (I did not independently confirm Veselov's pre-grant publication number; its issue date is 2022-01-04, which is after the '926 priority date, so § 102(a)(2) status would depend on its earlier publication/effectively-filed date — unverified.)
- § 102 vs § 103: Notably, Wiz asserted Veselov only in § 103 combinations, not as a standalone § 102 anticipation reference. That is a meaningful signal that even the best art was not viewed as a clean § 102 hit against claim 1.
- Mohanty — secondary reference in Ground 1 (Veselov + Mohanty); declaration of Dr. Angelos Stavrou addresses the combination as to elements 1.4/14.4/15.4, 1.5–1.6, 1.7, and claim 13. Full identifier/date not confirmed by me.
- U.S. Pat. No. 9,467,465 B2 ("Hibbert") — appears in the IPR2024-01190 exhibit record (Orca Ex. 2010). Identifier/date confirmed as listed; its role (owner-side background vs. petitioner art) not confirmed.
- U.S. Pat. No. 10,298,599 B1 ("Zhang") and U.S. Pat. No. 9,594,912 B1 ("Thioux") — Orca Exs. 2011–2012 in the same exhibit list; roles not confirmed.
- U.S. Pat. No. 8,011,010 B2 (Michael et al.) — cited in Wiz's reply declaration (Ex. 1129); note it is also on the district-court "patent documents" excerpt accompanying the complaint. Not on the '926 face.
- Other IPR-record art (background/state-of-the-art): CreateSnapshot AWS API documentation (Wayback, 2014-12-26), Rapid7 Nexpose User's Guide v5.16 (2015), Tenable Nessus Enterprise for AWS (2014), and Birk, "Technical Challenges of Forensic Investigations in Cloud Computing Environments" (2011). The AWS
CreateSnapshotarchive is particularly relevant to the claim 1 "using an API or service provided by the cloud computing environment" limitation.
Ranked short list of the strongest § 102 candidates against claim 1 (all require the cloud-API limitation to be read in): (i) US 2017/0111384 A1 (SecludIT); (ii) US 9,756,070 B1 (Amazon, scanning machine images); (iii) US 10,079,842 B1 (Amazon, transparent volume-based IDS); (iv) US 2012/0323853 A1 (Microsoft, VM snapshotting and analysis); (v) Veselov US 11,216,563 + Mohanty as a § 103 combination rather than § 102. For the dependent change-detection claims, US 9,177,145 B2 (Sophos) is the closest single reference (claims 2–4); for the sensitive-data limbs, US 9,069,983 B1 (Symantec); for remediation, US 2016/0094568 A1 (IBM) and US 2018/0293374 A1 (Red Hat); for risk scoring/filtering, US 2008/0189788 A1 (Microsoft).
C. Explicit uncertainties and contradictions
- Citation list incomplete. 36 of 50 face-cited references recovered; ~14 unverified. Do not treat Section A as the complete examiner citation set.
- No adjudicated prior art. Because IPR2024-01190 settled (2026-01-13) and the Delaware case was dismissed with prejudice (2026-01-13), no reference was ever held to anticipate or render obvious any '926 claim. The adverse PTAB Final Written Decisions of 2025-12-08 (all claims unpatentable) were on the sibling patents 11,663,031; 11,663,032; and 11,693,685 (IPRs -00863/-00864/-00865) — different claims, not the '926 patent.
- § 102 vs § 103. I searched for the identity of Mohanty and for Veselov's publication number but did not complete verification; treat both as unconfirmed IDs. Do not auto-populate them.
- Consistency with the earlier sections: this analysis agrees with the prior "Patent summary" and "Litigation summary" (same IPR number, same institution/termination dates, same patents asserted). One item to flag from that earlier work: the '926 specification's Fig. 3 passage about "over-privileged roles vulnerabilities in serverless functions" is residual text inconsistent with the rest of the disclosure — noted there as an observed inconsistency; it has no bearing on the prior-art analysis above but may be worth recalling if a § 112 written-description argument is ever reached.
Generated 9/29/2026, 10:23:09 AM
Obviousness
Combinations of prior art that suggest the claimed invention would have been obvious under 35 U.S.C. § 103.
I'll ground this analysis in the prior-art references cited on the face of the '926 patent, and check whether the IPR petition grounds are public.
Excellent — the IPR record is public. Let me pin down the exact grounds and the primary references.
Let me confirm the exact '926 IPR grounds and whether the primary references appear on the patent's own face.
Obviousness Analysis — U.S. Patent No. 11,740,926 B2 under 35 U.S.C. § 103
Patent: US 11,740,926 B2, "Techniques for securing virtual machines by analyzing data for cyber threats" (Orca Security Ltd.; inventor Avi Shua)
Critical date: January 28, 2019 (earliest priority; provisional 62/797,718)
Claim set analyzed: independent claims 1 (method), 14 (CRM), 15 (system) — all three recite the same seven-step operation set — plus dependent claims 2–13.
0. Sourcing note and scope — what I treated as "the Prior Art section"
Google Patents' page for this patent does not have a heading literally labelled "Prior Art." It has (a) a "Prior art keywords" tag list (virtual / virtual disk / snapshot / cloud / cyber threats), and (b) a "Citations (50)" table — the references cited against the '926 patent, marked cited by examiner or cited by third party. I treated that Citations table as the Prior Art section.
Two important limitations on that source, stated up front:
- The list was truncated in the material supplied to me. Only 36 of the 50 cited references are visible; the 36th ends mid-entry at "US20190065754A1 — Microsoft Technology Licensing." I therefore could not perform a complete, closed review of the 50-item citation set. Where I rely on a reference that is not in the visible 36, I say so.
- I supplemented the citation list with the public IPR record for this exact patent (IPR2024-01190, Wiz, Inc. v. Orca Security Ltd.), because the Board's institution decision on the '926 patent is direct evidence of what the art was understood to teach and of the specific § 103 combinations actually asserted. I flag clearly which statements come from the IPR record rather than from the patent's own face.
- I did not use the "Families Citing this family (144)" list as prior art. Those are forward citations (Lacework/Fortinet/Wiz patents that cite the Orca family). Several carry a 2017 Lacework priority, but they cite this 2019-priority family, so they cannot be prior art to it. Treating them as prior art would be an error.
A note on the date discrepancy: the task header states April 26, 2026; the system context states September 29, 2026. The PTAB/docket facts relied on below (institution 2025-01-22, FWDs 2025-12-08 on sibling patents, settlement termination 2026-01-13) are consistent with either date. Nothing in this analysis turns on the difference.
1. Bottom line
On the art cited on the face of the '926 patent, claim 1 is, in my assessment, more likely than not obvious under § 103, and the dependent claims add little. The strongest single combination is:
US 2017/0111384 A1 (Loureiro et al., SecludIT) — in view of — US 11,216,563 B1 (Veselov et al., Amazon) — in view of — Basavapatna (vulnerability risk metrics / alert prioritization).
The SecludIT reference alone is a striking near-miss: it expressly teaches (i) an out-of-band system that connects to a cloud/virtual system, (ii) using the cloud provider's own API to make a disk copy of the production server's virtual disk, (iii) analyzing that copy agentlessly, without administrator keys, (iv) checking configuration files, logs, cryptographic checksums to detect modifications, and trend changes, and (v) "generat[ing] alerts when the analysis system identifies a critical vulnerability." That maps onto claim 1 elements 1–4 and 7 with little strain. What SecludIT does not supply — snapshot semantics (the claim's "snapshot," as distinguished from a clone/disk copy) and per-threat risk scoring with prioritization — is supplied by Veselov (snapshot capture/access via the virtualization layer's APIs) and Basavapatna (threat-centric and vulnerability-centric risk metrics driving alert process).
The two genuine weak points in the § 103 case are:
- "Snapshot," not "clone." Orca's whole IPR defence was a narrowing construction: an "instantiated VM is not a 'snapshot'"; "'analyzing the at least one snapshot' encompass[es] analyzing the snapshot itself." If "snapshot" is construed to exclude clone-and-boot or disk-copy-and-mount, SecludIT's disclosure fits imperfectly, and the case leans harder on Veselov.
- "Report at least some … as alerts." Orca argued "reporting assessment results and reporting results 'as alerts' are not equivalent." That is a thin distinction on this record, but it is a live one.
The claim's most distinctive-looking limitation — the twelve-item enumerated data list — is much weaker than it appears, because it is phrased disjunctively ("the data includes at least one of"). A single reference teaching any one of the twelve items satisfies it. "At least one change in at least one area of the virtual disk, as compared to an earlier point in time" is squarely met by the patent's own cited reference US 9,177,145 B2 (Sophos, "Modified file tracking on virtual machines"), and by SecludIT's "verification of the cryptographic checksums to detect modifications."
Corroboration: the PTAB instituted review on all claims 1–15 of the '926 patent on 2025-01-22 (IPR2024-01190) on grounds built on Veselov + Mohanty (Ground 1) and Veselov + Mohanty + Ranum (Ground 2), with Loureiro/SecludIT (US 2017/0111384 A1) appearing as an exhibit in the same proceeding. Institution requires only a reasonable likelihood, not a merits holding; the proceeding then terminated by settlement on 2026-01-13 without any final written decision, so the '926 claims were never adjudicated unpatentable. In the parallel IPRs on the three sibling patents the Board did reach the merits and held all claims of 11,663,031, 11,663,032, and 11,693,685 unpatentable (FWDs, 2025-12-08) on materially overlapping art. That is relevant context, not binding on the '926.
2. Legal framework and level of ordinary skill
Framework. Obviousness is a question of law with underlying factual findings (Graham v. John Deere). The art must be analogous (the same field of endeavour or reasonably pertinent to the problem). Any express or implied motivation — or a showing that the combination was "obvious to try" from a finite number of identified, predictable solutions — suffices (KSR Int'l v. Teleflex). The claim must be assessed as a whole, but where a limitation is claimed disjunctively ("at least one of"), only one alternative need be shown. Objective indicia (objective evidence of non-obviousness) must be considered where a nexus exists (WBIP v. Kohler).
POSITA. Adopting the formulation Wiz advanced and the Board accepted for institution (I found no contrary construction adopted by the Board): a bachelor's degree in CS/CE/EE or related field plus 2–3 years of professional experience in cybersecurity analysis and virtualization, with additional experience substituting for education. Relevant experience includes malware analysis, cloud-computing security analysis, and VM security analysis. This is a relatively low skill bar, which cuts against patentability: an artisan with 2–3 years in cloud/VM security in January 2019 would have been entirely familiar with (a) cloud-native snapshot APIs and (b) hardening-baseline scanning.
Claim construction points that matter:
| Term | Patent Owner's IPR position | Effect on § 103 |
|---|---|---|
| "snapshot" | VM images and VM snapshots are not the same; an "instantiated VM is not a 'snapshot'" | Narrows the primary reference (Veselov instantiates assessment VMs in one embodiment); pushes weight onto direct snapshot-file analysis and onto SecludIT's disk copy |
| "analyzing the snapshot" | Encompasses analyzing "the snapshot itself," not a VM instantiated from the snapshot | The ordinary meaning accepted by the Board for institution encompassed both direct analysis of snapshot data and analysis of an instantiated assessment VM |
| "reporting … as alerts" | Reporting results ≠ reporting "as alerts" | Thin distinction; SecludIT expressly discloses alert generation |
Note the § 103 tension Orca created for itself: it argued narrowly to the PTO (agentless, at-rest, direct snapshot analysis) while arguing broadly to the district court that "snapshot is simply 'a copy of data.'" The narrow constructions help validity only if the claims can also be narrowed away from SecludIT's clone/disk-copy disclosure — and SecludIT's disk copy is, functionally, "a copy of data" from the virtual disk.
3. The prior-art pool from the patent's own Citations section
Grouped by the function each reference performs relative to the claim elements. All are from the visible 36-entry citation list unless marked otherwise.
A — Agentless, out-of-band VM/cloud security assessment via copy of the disk (core art):
- US 2017/0111384 A1 — Loureiro et al. / SecludIT (pub. 2017-04-20; FR priority 2015-10-16; granted as US 10,412,109). The single most damaging reference. Teaches: an analysis system outside the cloud system; using an API present in the cloud system to request cloning/disk copy of the production server's virtual disk(s); the clone/disk copy created in the cloud system; connection to the clone/disk copy; analysis of its vulnerabilities; erasure of the copy; report generation; no agent required; no administrator keys required; disk-image analysis performed with the server not in execution mode, avoiding CPU cost and preventing malware execution; checks of configuration files, log file analysis, "verification of the cryptographic checksums to detect modifications," detection of "changes made in the servers" and "changes of trend," and comparison against history to detect APTs' weak signals; threat-intelligence-fed vulnerability database (public databases, monitoring, hacking forums); configurable scheduled repetition (daily/weekly/monthly); and "alerts … generated when the analysis system identifies a critical vulnerability."
- US 2012/0323853 A1 — Microsoft (pub. 2012-12-20). "Virtual machine snapshotting and analysis" — snapshotting a running VM and analyzing the snapshot out-of-band.
- US 2008/0263658 A1 — Microsoft. "Using antimalware technologies to perform offline scanning of virtual machine images" — offline image scanning.
- US 2009/0007100 A1 — Microsoft. "Suspending a Running Operating System to Enable Security Scanning."
- US 2010/0017512 A1 — IBM. Off-line virtual environments (Improvements in or relating to off-line virtual environments).
- US 2011/0289584 A1 — CA, Inc. "Systems and methods to secure backup images from viruses."
- US 2012/0072968 A1 — Wysopal. "Assessment and analysis of software security flaws in virtual machines."
- US 9,519,781 B2 — Cyphort. Virtualization- and emulation-assisted malware detection.
- US 9,268,689 B1 — Symantec. Securing virtual machines with optimized anti-virus scan.
B — VM/container security assessment with risk scoring and prioritized alerting:
- US 2013/0247133 A1 — Price (McAfee), published 2013-09-19. "Security assessment of virtual machine environments." (Note: this is the "Price" reference Wiz asserted against the sibling '031/'032/'685 patents — and it is on the face of the '926 patent's own citation list, i.e., it was before the examiner.)
- Basavapatna (Ex. 1008 in Wiz's IPRs; identifier not visible in the material I retrieved). Teaches asset configuration data, vulnerability definition data, applicability data, threat-centric and vulnerability-centric risk metrics, and an alert process driven by a determined priority.
- US 2008/0189788 A1 — Microsoft. "Dynamic risk management" — risk-scoring and dynamic risk-driven prioritization.
- US 2018/0255080 A1 — ResponSight. Cyber security threat detection.
- US 2019/0065754 A1 — Microsoft Technology Licensing (entry truncated).
- US 9,567,377 B2 — IBM. Security policy generation based on snapshots of similar VMs (baseline/drift comparison).
C — File-integrity / change detection on a virtual disk (the "at least one change" prong):
- US 9,177,145 B2 — Sophos. "Modified file tracking on virtual machines." Directly on point for claim 1's final enumerated alternative and for claims 2 and 3.
- US 9,069,983 B1 — Symantec. "Protecting sensitive information from disclosure through virtual machines files" — on point for the unencrypted-sensitive-data / PII-on-disk prongs.
- US 9,229,758 B2 — IBM. Passive monitoring of virtual systems using extensible indexing.
D — Cloud-provider APIs, virtual disk and snapshot management (the "using an API or service provided by the cloud computing environment" prong):
- US 2014/0089916 A1 — CA, Inc. Centralized, policy-driven maintenance of storage for VMDKs.
- US 9,758,070 B1 — Amazon. Scanning machine images to identify potential risks.
- US 9,858,105 B1 — Amazon. Service for managing custom virtual machine images.
- US 10,079,842 B1 — Amazon. Transparent volume-based intrusion detection.
- US 2014/0096135 A1 — IBM. Authenticated distribution of virtual machine images.
- US 2015/0052520 A1 — IBM. VM trust isolation in a cloud environment.
- US 2016/0004449 A1 — Hedvig. Storage system with virtual disks.
- US 9,734,325 B1 — Forcepoint. Hypervisor-based binding of data to cloud environment.
E — Agentless introspection / passive assessment / mitigation:
- US 2018/0293374 A1 — Red Hat. Runtime non-intrusive container security introspection and remediation (relevant because the '926 specification defines the protected asset to include containers, micro-services, and serverless functions).
- US 2014/0137190 A1 — Rapid7. Passively detecting security levels in client devices.
- US 2016/0241573 A1 — Fisher-Rosemount. Security event detection through virtual machine introspection.
- US 2016/0094568 A1 — IBM. Automated response to detection of threat to cloud VM — on point for claims 10–11 (mitigation).
- US 2013/0191643 A1 — Fujitsu. Establishing a chain of trust within a VM.
F — Substantively off-point (present in the citation list but of little § 103 value here): US 2015/0170031704 A1 / US 2017/0011138 A1 (Synopsys, hierarchical power verification), US 2017/0031704 A1 (HP, network port profile for VMs), US 2018/0052762 A1 (Red Hat, build-failure management), US 2018/0137032 A1 (Atlassian, source-code testing). Their presence in the citation list reflects the examiner's broad IDS practice, not the merits — which matters, because it means the substantive § 103 combinations below were never actually applied in a rejection (see § 8).
4. Claim 1 — element-by-element mapping and the combination
Claim 1's seven elements, and the references that supply each:
1.1 "receiving a request to scan a protected virtual cloud asset"
Supplied by SecludIT '384 (owner supplies server identifier/IP + cloning key; scans configurable and repeatable "once per day, once per week or once per month"); Veselov (scan request identifying the target resource); US 2012/0072968 (Wysopal); US 2013/0247133 (Price/McAfee). Also met by any competitor's scheduled-scan disclosure. Not a point of novelty.
1.2 "locating, using an API or service provided by the cloud computing environment, a snapshot of at least one virtual disk of the protected virtual cloud asset"
SecludIT '384 expressly: the analysis system "has the following rights of listing the virtual servers in the cloud computer system, listing the network topology for duplication, and cloning or making a disk copy"; and "the analysis system 4 uses an API, present in the system 1, that allows the server 2 to be cloned." Veselov teaches establishing an interface with the target environment via APIs, determining the VM's corresponding virtualization layer, and transmitting a command to that layer to provide snapshot data (or access to it). Infra evidence in the IPR record: the AWS EC2 CreateSnapshot API documentation (archived 2014) and AWS cross-account role authentication, both entered as exhibits. Met by SecludIT alone; met a fortiori by SecludIT + Veselov.
1.3 "accessing, using an API or service provided by the cloud computing environment, the snapshot of the at least one virtual disk"
SecludIT: connect to the clone/disk copy via the cloud API and the generated key. Veselov: obtain the snapshot data, obtain access at the snapshot's storage location without copying, or have another service capture and provide it. Met.
1.4 "analyzing the snapshot … to determine the existence of a plurality of potential cyber threats, each cyber threat based on data stored on the virtual disk, wherein the data includes at least one of: [12 items]"
This is the only element with any facial specificity, and it is satisfied by any one of the twelve alternatives:
| Enumerated item | Reference(s) on the patent's face |
|---|---|
| unencrypted sensitive data; unencrypted system credentials; PII on disk | US 9,069,983 B1 (Symantec) — protecting sensitive information from disclosure through VM files; US 2010/0017512 A1 (IBM); US 2011/0289584 (CA) |
| weak passwords; weak encryption schemes; risky application features (weak cipher suites / auth) | US 2012/0072968 (Wysopal); US 2013/0247133 (Price/McAfee); SecludIT config-file checks |
| disabled ASLR; boot record manipulation; suspicious definitions; services to be run on startup | Hardening-baseline checks (CIS benchmark-style). Veselov expressly recites rule packages including CIS benchmarks and host configuration assessments; the IPR record shows the link between CVEs and "services that were commonly run when the computer system starts up." SecludIT's configuration/compliance-policy checking (and Norton/"good practice" config verifiers) supplies the mechanism. |
| PII in application logs; logs showing the asset accessed PII or a PII-containing computer | SecludIT '384 — log-file analysis and detection of connections to blacklisted/known-bad hosts; Veselov's change-log and log analysis; US 2011/0289584 |
| "at least one change in at least one area of the virtual disk, as compared to an earlier point in time" | US 9,177,145 B2 (Sophos, modified file tracking on VMs) — squarely; SecludIT '384 ("verification of the cryptographic checksums to detect modifications"); US 9,567,377 B2 (IBM) (baseline from snapshots of similar VMs) |
Because the list is disjunctive, element 1.4 collapses to: "did the system scan the copied disk and find something bad?" SecludIT plus Sophos (or SecludIT alone, given its checksum-modification and change/trend detection) meets it.
1.5 "determining a risk associated with each of the determined plurality of potential cyber threats"
Basavapatna (threat-centric and vulnerability-centric risk metrics derived from applicability + configuration data); US 2008/0189788 (Microsoft, dynamic risk management); SecludIT's security policies classifying servers and tests by criticality and threat.
1.6 "prioritizing the potential cyber threats … based on the determined risk"
Basavapatna (alert process based on determined priority); US 2008/0189788; and, per the IPR record, Hufsmith (assigning weights/priorities to detected risks and sending prioritized alerts) and Ranum (relied on by Wiz in Grounds 2 and 3–6 for elements 1.4 and 1.7). SecludIT's policy-driven severity/criticality classification supplies the same function.
1.7 "reporting at least some of the determined plurality of potential cyber threats as alerts prioritized according to their associated risks"
SecludIT '384: "It allows alerts to be generated when the analysis system identifies a critical vulnerability or an event that violates a security policy"; reports and dashboards track results and trends. Basavapatna / US 2008/0189788 / Hufsmith supply the prioritization ordering. The "at least some" language (i.e., filtering) is met by SecludIT's policy-driven depth/frequency selection and by Basavapatna's applicability filtering.
The two proposed combinations
Primary combination (minimal, three references):
SecludIT (US 2017/0111384 A1) + Basavapatna, optionally + Veselov (US 11,216,563 B1)
What each supplies: SecludIT — elements 1.1, 1.2, 1.3, 1.4, and the alerting core of 1.7. Basavapatna — elements 1.5 and 1.6, and the "prioritized according to their associated risks" ordering in 1.7. Veselov — the explicit snapshot vocabulary and API-driven snapshot capture/access (element 1.2/1.3), plus CIS-benchmark/host-configuration assessment (element 1.4's hardening prongs).
Secondary/backup combination (mirrors the art actually asserted in the IPR):
Veselov (US 11,216,563 B1) + Mohanty, as asserted in Ground 1 of IPR2024-01190; and Veselov + Mohanty + Ranum for Ground 2.
This combination is probative because the Board instituted on it as to all claims. I could not retrieve Mohanty's or Ranum's full bibliographic data (title, number, date) within this analysis, so I rely on the IPR record's naming of them and do not assert their contents. Flagged as a verification gap.
5. Why a POSITA would have combined these references (KSR rationales)
Same field, same problem, same solution space. All of SecludIT, Veselov, Price/McAfee, Microsoft '853/'658/'100, IBM '512, CA '584, Sophos '145, Symantec '983, and Red Hat '374 address the identical problem: assessing the security posture of a VM/container/cloud workload without the two acknowledged deficiencies of the prior art — (a) network/traffic inspection that misses encrypted or non-exposed data and misconfiguration, and (b) in-guest agents, which are operationally costly, require admin credentials, and perturb the production workload. Both SecludIT and Veselov expressly frame their inventions that way. A POSITA confronting an Orca-type requirement (agentless, credential-light, complete coverage of the disk) would look first to this body of art.
The combination produces no new structure — only predictable aggregation. Use of cloud provider APIs to identify a volume and take/read a copy of it (AWS CreateSnapshot; SecludIT's cloning API; Veselov's virtualization-layer command) was routine in 2019. Once you have the copy, "scan the disk contents for bad things" and "score and rank what you find, then alert" are each known, and their combination is a combination of prior art elements according to known methods yielding predictable results (KSR).
A recognized, finite design choice with a known trade-off. The art presents exactly two ways to handle the copy — analyze the disk image/clone as data (SecludIT's disk-image mode; Veselov's FIGS. 5A–B) or instantiate a duplicate VM and analyze it (Veselov's FIGS. 3A–B). The patent claims both. Choosing one of two known techniques is the paradigm of obviousness, and SecludIT expressly supplies the reasons to prefer the disk-image route: no extra CPU cost, and malware in an infected image "is not being executed."
Motivation arising from the alerting problem itself. Both SecludIT (reports, dashboards, histories, trends, policies defining severity) and the risk-management references exist precisely because disk-level scanning generates more findings than a human can triage. Basavapatna's and Microsoft '788's risk scoring, and Hufsmith's weighted priorities, solve the recognized problem of alert volume/fatigue, which the '926 specification itself names as the reason for prioritizing ("reduces the number of alerts reported to the user"). The motivation is therefore in the art, not supplied by the patent.
Cloud-service and competitive pressure. As of January 2019 the cloud providers themselves published snapshot APIs and scan services (Amazon '070 "Scanning machine images to identify potential risks"; Amazon '105 "Service for managing custom virtual machine images"). A POSITA building a third-party cloud security product would have had strong market motivation to build on the provider's own primitive (the API-created snapshot) rather than to invent an agent — the "design incentive" and "market pressure" rationales of KSR.
The disjunctive claim language removes the combination burden. Because element 1.4 requires only one of twelve data categories, the POSITA need only be motivated to combine SecludIT with one additional reference teaching one category (e.g., Sophos for change detection, or Basavapatna for config/applicability checks). Obviousness of a claim does not require that a single reference (or a large committee of references) teach everything.
6. Dependent claims 2–13
These add conventional detail and are, in my assessment, the weakest part of the patent:
| Claim | Limitation | Anticipated/obvious over |
|---|---|---|
| 2 | Detect the data by determining an unexpected change on the disk | Sophos US 9,177,145 B2 (modified file tracking on VMs); SecludIT (checksums to detect modifications; changes vs. history); Microsoft '853 |
| 3 | Detect added or changed files without a corresponding installation process | Sophos '145; SecludIT (integrity checks; installation-log reading is also disclosed in the '926 spec's own cited practice); CA '584 |
| 4 | Compute a cryptographic hash of a disk area and compare to an earlier hash | SecludIT '384 — "verification of the cryptographic checksums to detect modifications" |
| 5 | Take or request the snapshot if none exists | SecludIT '384 (requests cloning/disk copy; creates it in the cloud); Veselov ("by executing the snapshot itself, by requesting another service to capture the snapshot …"); AWS CreateSnapshot API |
| 6 | Filter threats by determined risk level | Basavapatna; Microsoft '788; Hufsmith |
| 7 | Filtering based on external intelligence on likelihood of exploitation | Basavapatna (applicability/threat data); SecludIT '384 — vulnerability DB "constructed via public databases, technological monitoring and data taken from online hacking forums (threat intelligence)" |
| 8 | Parse the snapshot copy and scan the parsed copy | Veselov (parse snapshot, determine installed packages, select assessment tasks); SecludIT; Wysopal '968 |
| 9 | Check config files; verify file access times; analyze system logs | Veselov (host configuration assessments, CIS benchmarks); SecludIT (config-file compliance checks, log analysis); Price/McAfee '133; Wysopal '968 |
| 10 | Mitigate a detected threat | US 2016/0094568 A1 (IBM, automated response to detection of threat to cloud VM); SecludIT (correct vulnerabilities on the clone) |
| 11 | Mitigation = block untrusted traffic / halt / quarantine | IBM '568; SecludIT (isolated network zone for the clone; sniffer detecting connections to blacklisted C&C hosts); US 10,079,842 (Amazon) |
| 12 | Determine the virtual disk allocated to the asset | Veselov (determine the corresponding virtualization layer/storage); SecludIT (listing rights for servers and topology); CA '916 (VMDK maintenance) |
| 13 | Query the cloud management console for snapshot and disk locations | Veselov (transmit command to virtualization layer to provide snapshot data); SecludIT (connect to the cloud system and use its API); Amazon '070/'105 |
Nothing in claims 2–13 recites a structure, algorithm, or data structure that is not disclosed in the cited references. Their principal function is to raise the number of references needed; that is exactly the "jigsaw puzzle" objection Orca pressed in the sibling IPRs (and the "five-reference" concern the Federal Circuit has flagged), and it has real weight — but note that the institution decision on the '926 patent went the other way on all claims, which suggests the Board did not view the combinations as unacceptably sprawling.
7. What the patent owner would actually argue (and how strong it is)
These are the non-obviousness arguments Orca made in the parallel proceedings; a rigorous § 103 analysis must engage them.
A. "The prior art uses agents; the invention is agentless and at rest." Strength: moderate but self-defeating. Veselov discloses both agent-based and agentless modes, including analysis of the snapshot as a data file with no instantiated VM. SecludIT discloses no agent at all and expressly does so without administrator keys. The argument requires reading Veselov narrowly while ignoring SecludIT — a species of "attacking references individually," which is impermissible where the rejection rests on the combination.
B. "Veselov does not address VMs at rest; a POSITA would not look to Price because Price uses agents on target VMs, contradicting Veselov's goal." Strength: this is Orca's best technical argument, and it persuaded no one at institution for the '926 patent (the Board instituted). It is weakened by SecludIT, which expressly explains why to prefer a non-executing disk image (no CPU cost; malware not executed; no risk to production) — supplying precisely the rationale Orca says is missing.
C. "Analyzing the snapshot ≠ analyzing a VM instantiated from a snapshot." Strength: real, but it is a narrowing argument that also narrows infringement. And it does not help against SecludIT/Veselov's direct disk-image analysis.
D. "Reporting results ≠ reporting as alerts." Strength: weak. SecludIT textually discloses generating alerts on identifying a critical vulnerability — which is the claimed function.
E. Objective indicia of non-obviousness. Orca asserted, and sought discovery for: skepticism of the SideScanning approach at the time; industry praise; copying by Wiz; and commercial success (funding and valuation, and Wiz's ARR growth attributed to the same approach). If a nexus is established between that evidence and the claimed subject matter, this is the most powerful part of Orca's case, and under WBIP it must be considered. My assessment: the evidence as reported is macro-level (funding rounds, valuations, competitor ARR) and the asserted nexus is to "SideScanning™ technology" as a product, not to the specific claim elements — particularly not to the enumerated data list or to the API-based locating/accessing steps. Commercial-success evidence of this kind is frequently discounted for lack of a specific nexus, but it is a genuine evidentiary battleground, not a formality.
F. The enumerated list as a whole. Orca's most defensible framing is: no single reference teaches scanning a disk snapshot for this specific heterogeneous collection — unencrypted secrets, weak ciphers, disabled ASLR, boot-record manipulation, LD_PRELOAD/PATH definitions, startup services, PII/credential leakage, and disk drift. Response: (i) the list is disjunctive, so only one item need be shown; (ii) each item is a standard member of the security-scanning/hardening-baseline repertoire (CVE assessment, CIS benchmarks, file-integrity monitoring, secrets scanning) that both Veselov and SecludIT describe in class terms; and (iii) grouping known checks into a single scanner is not an inventive combination. I regard (i) as decisive on the face of the claim.
8. Two structural facts that materially affect the § 103 assessment
- No art-based rejection was ever made during prosecution. Per the petition the Board instituted on (for the sibling '345/'798 application and by extension this family), the applications received only non-statutory double-patenting rejections over the parent, resolved by terminal disclaimers; the notice of allowance identified "closest prior art" by listing claim language without explanation. Consequently, the § 103 combinations above were never substantively examined. This weakens any "the examiner already considered this art" argument under § 325(d) and means the issued claims carry little weight as evidence of non-obviousness.
- The Board instituted on all claims, then the case settled before any merits decision. Institution (2025-01-22) is a reasonable-likelihood finding based on the petition and the patent owner's preliminary response. It is probative but not a holding. Because the proceeding terminated by settlement (2026-01-13) with no final written decision, and because the district court action was dismissed with prejudice the same day, the '926 claims have never been adjudicated unpatentable and never been adjudicated valid. By contrast, the Board did reach the merits on the three sibling patents and held all claims of 11,663,031; 11,663,032; and 11,693,685 unpatentable on 2025-12-08 — on art (Veselov-based) that overlaps substantially with the '926 combination. If one accepts that those siblings share the common specification and much of the claim scope with the '926 patent, the sibling FWDs are a meaningful, though not dispositive, cross-check on the strength of the § 103 case here.
9. Confidence, and explicit verification gaps
High confidence:
- SecludIT US 2017/0111384 A1 discloses cloud-API-based cloning/disk-copy acquisition, agentless analysis, no admin keys, configuration/log/checksum-change checking, scheduled scans, and alert generation. I read the specification text and claims directly.
- Veselov is US 11,216,563 B1 (Amazon Technologies, filed 2017-05-19; inventors Vladimir Veselov, Aparna Nagargadde, Adrian-Radu Grajceannu), and teaches snapshot capture/access via APIs and both direct and instantiated-VM analysis.
- Price is US 2013/0247133 A1, and it appears on the '926 patent's own citation list (item 10 in the visible list: "Security assessment of virtual machine environments," 2011-10-13 priority).
- IPR2024-01190 Ground 1 = Veselov + Mohanty; Ground 2 = Veselov + Mohanty + Ranum; six grounds total; instituted 2025-01-22; terminated by settlement 2026-01-13 with no FWD.
Medium confidence / needs verification:
- Mohanty and Ranum: I could not retrieve their bibliographic identifiers (number, title, publication date) within this analysis. They are named in the IPR2024-01190 deposition transcript and the Stavrou reply-declaration table of contents. I have not verified their prior-art dates or contents, and I do not rely on them for any mapping above.
- Basavapatna: relied on in the Wiz IPRs as Ex. 1008 for risk metrics and alert priority. I could not confirm its patent/publication number. It does not appear in the visible portion of the '926 citation list.
- Hufsmith (US 2020/0097662 A1): a 2020 publication. To qualify as prior art against a January 28, 2019 critical date it must carry an earlier effective filing date. I did not verify that. Do not treat Hufsmith as established prior art without checking its priority chain. My § 103 analysis does not depend on it — Basavapatna and Microsoft '788 supply the prioritization element independently.
- The 14 cited references not visible in the truncated list (entries 37–50). I cannot rule out that one of them is an anticipatory or especially on-point reference. I also could not confirm whether Veselov and Basavapatna themselves appear among the '926 patent's 50 citations, though the '798 petition states Veselov was IDS-disclosed across the family.
Low confidence / do not rely on:
- Any inference about the content of Grounds 3–6 of IPR2024-01190. Loureiro/SecludIT US 2017/0111384 A1 was filed as an exhibit in that proceeding (Ex. 1097), which suggests it was used in at least one ground, but I have not verified which ground or for which elements.
Why the § 103 conclusion is framed as "more likely than not" rather than "clear": the outcome depends on claim construction of "snapshot" and on how much weight a trier of fact gives Orca's objective-indicia evidence. If "snapshot" is construed narrowly to exclude clones and disk copies, SecludIT's role becomes supplemental rather than primary and the case rests almost entirely on Veselov — which is still a strong case (the Board instituted on Veselov-based grounds across all claims) but is no longer near-anticipatory. If the objective indicia are credited with a nexus to the claimed elements, they could tip the balance. On the intrinsic record alone, however, the enumerated-data limitation's disjunctive form and the purely conventional character of the remaining steps make non-obviousness difficult to sustain.
Generated 9/29/2026, 10:23:47 AM
Extensions
Patent term adjustments, term extensions, continuations, divisionals, family members, and expiration dates.
Derivative works
Defensive disclosure: derivative variations of each claim designed to render future incremental improvements obvious or non-novel.
Keep exploring
More patents asserted by Orca Security Ltd.
- US 12001549US patent 12001549, titled "Cybersecurity incident response techniques utilizing artificial intelligence," was assigned to Wiz Inc. The inventors are Alon SCHINDEL, Barak Sharoni, Amitai Cohen, Ami Luttwak, Roy Reznik, and Yinon COSTICA…
- US 11722554US Patent 11722554, titled "System and method for analyzing network objects in a cloud environment," was granted to Wiz Inc. The inventors are Shai Keren, Danny Shemesh, Roy Reznik, Ami Luttwak, and Avihai Berkovitz. The patent was filed…
- US 11663031I'll search for authoritative information on this specific patent number, including any 2026 litigation activity. Let me check for the PTAB final written decision and any Federal Circuit 2026 appeal activity. Let me check specifically for…
- US 11663032
- US 11693685I'll search for authoritative information on this specific patent number and any litigation involving it. Let me search for the specific IPR outcome and any Federal Circuit appeal involving this patent. US Patent 11,693,685 B2 — Patent…
- US 11726809I'll search for authoritative information on US patent 11726809. Let me check for Federal Circuit (CAFC) activity and the PTAB proceeding. Let me verify the post-settlement and any Federal Circuit activity. Summary: US Patent No…
- US 11775326I'll verify the patent details and litigation status with targeted searches. US 11,775,326 B2 — Analyst Summary Grounding note: The full text you supplied is the authoritative source and I have used it over the search results wherever they…
- US 11431735I'll search for current information on this patent, including any litigation or CAFC 2026 docket activity. Let me search for the specific PTAB proceeding and any related 2026 litigation developments. US Patent 11,431,735 — Analyst Summary…
Other patents in Software Technology & Computing Systems (T)
- US 6721803Search scope and what it returned I ran targeted lookups on the literal identifier 6721803 (US 6,721,803 B1) across patent databases and litigation dockets. Results: - USPTO/patent records: Found and confirmed — Google Patents, the…
- US 11431735I'll search for current information on this patent, including any litigation or CAFC 2026 docket activity. Let me search for the specific PTAB proceeding and any related 2026 litigation developments. US Patent 11,431,735 — Analyst Summary…
- US 11374982I'll search for authoritative information on this specific patent number. Let me search more specifically for litigation and docket activity involving this patent. Let me look for the actual claim set and any appellate activity. Summary of…
- US 6785727I'll verify this patent number against live sources and check for any litigation or CAFC activity. Let me check for any litigation or CAFC docket activity involving this patent. Let me attempt to retrieve the actual claim text, since the…
- US 11775326I'll verify the patent details and litigation status with targeted searches. US 11,775,326 B2 — Analyst Summary Grounding note: The full text you supplied is the authoritative source and I have used it over the search results wherever they…
- US 11726809I'll search for authoritative information on US patent 11726809. Let me check for Federal Circuit (CAFC) activity and the PTAB proceeding. Let me verify the post-settlement and any Federal Circuit activity. Summary: US Patent No…
- US 11693685I'll search for authoritative information on this specific patent number and any litigation involving it. Let me search for the specific IPR outcome and any Federal Circuit appeal involving this patent. US Patent 11,693,685 B2 — Patent…
- US 4124889I'll run targeted searches for this specific patent number, then summarize. Let me search for the claim text and any litigation records specifically tied to this number. Let me try two more targeted searches for the claim text and any…
This patent in court (2)
2 tracked lawsuits name US 11740926.