Patent 11995205 was granted and assigned to Sophos on May, 2024 by the United States Patent and Trademark Office.
A threat management facility stores a number of entity models that characterize reportable events from one or more entities. A stream of events from compute instances within an enterprise network can then be analyzed using these entity models to detect behavior that is inconsistent or anomalous for one or more of the entities that are currently active within the enterprise network.