Prosecution Insights
Last updated: October 02, 2026
Application No. 18/778,125

CYBER SECURITY SCENARIOS WITH SIMULATED INCIDENTS

Final Rejection §101§103
Filed
Jul 19, 2024
Priority
Jul 20, 2023 — provisional 63/528,009
Examiner
BROWN, CHRISTOPHER J
Art Unit
2439
Tech Center
2400 — Computer Networks
Assignee
Darktrace Holdings Limited
OA Round
2 (Final)
76%
Grant Probability
Favorable
3-4
OA Rounds
1y 2m
Est. Remaining
88%
With Interview

Examiner Intelligence

Grants 76% — above average
76%
Career Allowance Rate
544 granted / 720 resolved
+17.6% vs TC avg
Moderate +13% lift
Without
With
+12.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 5m
Avg Prosecution
36 currently pending
Career history
759
Total Applications
across all art units

Statute-Specific Performance

§101
2.1%
-37.9% vs TC avg
§103
64.0%
+24.0% vs TC avg
§102
11.4%
-28.6% vs TC avg
§112
11.2%
-28.8% vs TC avg
Black line = Tech Center average estimate • Based on career data from 720 resolved cases

Office Action

§101 §103
Notice of Pre-AIA or AIA Status The present application, filed on or after March 16, 2013, is being examined under the first inventor to file provisions of the AIA . Response to Arguments Applicant's arguments filed 6/24/26 have been fully considered but they are not persuasive. Applicant argues that the prior art fails to teach “the engine receives a users responsive action to a simulated event”, “the engine determines that the action modifies the scenarios progression or causes the simulation to progress based on the action”, “generates modified data reflecting the user action” Examiner disagrees. Examiner first asserts that while Applicant points to the specification for the meaning of “cyber security restoration engine”, the Examiner may not import narrow meanings from the specification into the claim language. Examiner broadly, but reasonably interprets the term “cyber security restoration engine” in the claim language. Examiner points to Crabtree [0061] which states “trained machine learning algorithms assist attackers…. Suggests attack avenues…assist defenders of blue team by suggesting defense strategies…especially when attack strategies by the red team are unique and novel. Examiner asserts that thus… the engine determines that an “indication of an action” is taken by a user (red team) the AI/ML algorithm then “determines an action to modify progression” (suggestion of a defensive action to be taken) and “generates data of a modified progression” (reports the results of the simulation and the success of red team and blue team. Examiner notes that the claim recites language in the broadest possible manner and thus lacks any relevant detail that might advance prosecution. For example the phrase “indication of an action” does not specify any relevant action, or if the action is even taken by an attacker or defender. The phrase “determine that the action is to modify a progression” does not teach what the modification is. Examiner asserts that almost any action input would “modify a progression” even if the modification was insignificant, and reaches the same ultimate conclusion. The phrase “generates data representative of a modified progression” is vague and does not specify if for example, an alternate simulation strategy is used, or rather a report is made of the simulation results. The term “generates data representative” is broad and must be read as such. Examiner notes that the limitations are taken from Claim 19, and thus no new matter has been incorporated into the claims. Examiner has cited more paragraphs of the Crabtree reference in an attempt to clarify the current rejection. Examiner cites, but does not rely upon Hadar US 2020/0201992, particularly, [0048] [0053][0058]-[0060][0063] which Examiner believes possibly closer align to Applicant’s intent. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Claims 1-9, 11-20 are rejected under 35 USC 101 as being directed to an abstract idea without being integrated into a practical application or being significantly more. Regarding claims 1-9, 11-20; Claim 1 recites the limitations “generate data representative of a simulated cyber security scenario;” Broadly interpreted, the aforementioned steps are directed to mental processes as said steps could be performed in the human mind. Therefore, the claims recite an abstract idea. Said abstract idea and/or judicial exception is not integrated into a practical application as the claim does not recite any other active steps that could be considered that the abstract idea is being integrated into a practical application. It’s noted that the claim recites the operations “cyber security restoration engine configured to simulate an asset;” However, said operations are not sufficient to consider that the abstract idea is being interpreted into a practical application. Said operations are recited at a high level of generality in gathering/processing/storing information, which are a form of insignificant extra-solution activity. It’s also noted that the claims recite additional limitation/elements (i.e., system, non-transitory medium, etc.,). However, said additional elements are recited at a high-level of generality (i.e., as a generic computing device performing a generic computer functions) such that it amounts no more than mere instructions to apply the exception or abstract idea using generic computer components. Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claims do not include additional elements/limitations/embodiments that are sufficient to amount to significantly more than the judicial exception because the additional elements when considered both individually and as an ordered combination do not amount to significantly more than the abstract idea. As mentioned above, although the claims recite additional elements, said elements taken individually or as a combination, do not result in the claim amounting to significantly more than the abstract idea because as the additional elements perform generic computer content distributing functions routinely used in information technology field. As discussed above, the additional elements recited at a high-level of generality such that they amount no more than mere instructions to apply the exception using a generic computer component. Therefore, the claim is directed to non-statutory subject matter. Claim Rejections - 35 USC § 103 The following is a quotation of 35 U.S.C. 103 which forms the basis for all obviousness rejections set forth in this Office action: A patent for a claimed invention may not be obtained, notwithstanding that the claimed invention is not identically disclosed as set forth in section 102, if the differences between the claimed invention and the prior art are such that the claimed invention as a whole would have been obvious before the effective filing date of the claimed invention to a person having ordinary skill in the art to which the claimed invention pertains. Patentability shall not be negated by the manner in which the invention was made. Claim(s) 1-15, 17-20 is/are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree US 2025/0007942 in view of Barai US 2021/0352100. As per claim 1, Crabtree teaches an apparatus, comprising: a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, which is further configured to: generate data representative of a simulated cyber security scenario involving the asset of the computing network, wherein the simulated cyber security scenario is derived from a real-world cyber security scenario mapped to the asset; and where instructions implemented in software for the cyber security restoration engine are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units. [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response ) Crabtree teaches receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario. Crabtree teaches determine that the action is to modify a progression of the simulated cyber security scenario, and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation) Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset. Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets) It would have been obvious to one of ordinary skill in the art before the effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack. As per claim 2. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is based on a template derived from data representative of an event that occurred as part of a real-life cyber security scenario that occurred on another computing network. [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) As per claim 3. The apparatus of claim 2, Crabtree teaches wherein the template is based on a synthetic cyber security scenario generated based on a historical real life cyber security scenario. [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) As per claim 4. The apparatus of claim 2, Crabtree teaches wherein the template is represented by a graph comprising one or more edges between one or more connecting assets of the computing network. [0013] (attack mission based on knowledge graph including entities, edges, relationships) As per claim 5. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is artificial intelligence (AI) generated. [0013] (AI generated attack scenarios) As per claim 6. The apparatus of claim 5, Crabtree teaches wherein the simulated cyber security scenario is AI generated based on one or more of a graph of interactions between assets in the computing network; and knowledge of threat actor techniques and tactics. [0012][0013] (teaches generating a scenario using contextual information of the network via knowledge graph and TTP information) As per claim 7. The apparatus of claim 5, Crabtree teaches wherein the AI generated simulated cyber security scenario is generated at least one of: prior to the cyber security restoration engine generating the data representative of the simulated cyber security scenario; such that the AI generated simulated cyber security scenario is used as a basis for the data representative of the simulate cyber security scenario; or in response to a change to an environment associated with the computing network triggered by user input while the cyber security restoration engine is generating the data representative of the simulated cyber security scenario. [0006][0013] (teaches generation of cyber security scenario, which is based on network simulation of computing network) As per claim 8. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario comprises an event, and wherein the generated data is representative of an effect that the event has on one or more of: the computing network and an organization associated with the computing network. [0087] (teaches monitoring progress of attack scenario including health indicators and relationship events) As per claim 9. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to: receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario; determine that the action is to modify a progression of the simulated cyber security scenario; and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response ) As per claim 10. The apparatus of claim 9, Crabtree teaches wherein the action comprises one or more of the user instructing a simulated cyber security tool to perform a user-specified action to modify further progression of the simulated cyber security scenario; the user instructing a simulated cyber security tool to autonomously perform an action to modify further progression of the simulated cyber security scenario; and the user providing information about the simulated cyber security scenario to a specified individual in an organization, and the user indicating a response of the specified individual. [0003] [0007] [0061] (red team users, and blue team users perform simulated attack to further progress the scenario, including use of AI attack strategies) As per claim 11. The apparatus of claim 1, Crabtree teaches wherein the simulated cyber security scenario is based on a configuration used by a real-life cyber security tool for protecting the computing network. [0006][0007] (teaches use of real-life tools, EDR, etc) As per claim 12. The apparatus of claim 11, Crabtree teaches wherein the cyber security restoration engine is configured to generate a metric indicative of an effect that the configuration has on the simulated cyber security scenario. [0085] (teaches generating metrics based on the simulated attack) As per claim 13. The apparatus of claim 12, Crabtree teaches wherein the cyber security restoration engine is configured to suggest a change to be made to the configuration of the real-life cyber security tool based on the metric. [0007][0079][0080] (teaches suggestion of additional security measures) As per claim 14. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to progress the simulated cyber security scenario based an interaction of a user with a simulation based on the data representative of a simulated cyber security scenario. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including red team and blue team actions) As per claim 15. The apparatus of claim 14, Crabtree teaches wherein progression of the simulation is displayed on a user interface, and wherein the interaction is input via the user interface. [0006][0007] [0087][0089] (teaches monitoring progress of attack scenario including health indicators and relationship events, and attack/defense progress indicators, including red team and blue team actions) [0063](team portals for implementing security controls) As per claim 17. The apparatus of claim 1, Crabtree teaches wherein the cyber security restoration engine is configured to at least one of reference i) a database of restoration response scenarios stored in the database for the computing network and ii) a prediction engine configured to run Artificial Intelligence-based simulations and use an operational state of a node in a graph corresponding to the asset of the computing network during simulations of cyberattacks on the computing network to restore each node compromised by a cyber threat during the simulation of the cyberattack. [0013][0066][0078][0079] (teaches AI suggestions for actions for remediation, and defense improvement) As per claim 18. Crabtree teaches A computer-implemented method for a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, comprising: generating data representative of a simulated cyber security scenario involving the asset of the computing network, wherein the simulated cyber security scenario is derived from a real-world cyber security scenario mapped to the asset. . [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response ) Crabtree teaches receive an indication of an action taken by a user in response to an event that occurs as part of the simulated cyber security scenario. Crabtree teaches determine that the action is to modify a progression of the simulated cyber security scenario, and generate data representative of a modified progression of the simulated cyber security scenario based on the action. [0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation) Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset. Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets) It would have been obvious to one of ordinary skill in the art before effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack. As per claim 19. Crabtree teaches An apparatus, comprising: a cyber security restoration engine configured to simulate an asset of a computing network that is involved in a simulated cyberattack, which is further configured to: receive an indication of an action taken by a user in response to an event that takes place during a simulation of a cyber security scenario involving the asset of the computing network, wherein the cyber security scenario is derived from a real world cyber security scenario mapped to the asset, and cause the simulation to progress the cyber security scenario based on the action taken by the user; and where instructions implemented in software for the cyber security restoration engine are configured to be stored in one or more non-transitory storage mediums to be executed by one or more processing units. [0006][0007][0008] [0013] (attack mission based on knowledge graph including entities, edges, relationships, generating a simulated cyber-attack based on the computer network) [0069][0070] (generating scenarios based in part on MITRE ATT&CK database which are based on real events) [0087][0089] (teaches monitoring progress of simulated attack scenario including health indicators and relationship events, and attack/defense progress indicators, including blue team incident response ) [0061]-[0064][0078] (tracks and suggests actions such as attacks or defense actions taken by a user in the attack simulation; proceeds with the simulation following said action by a user; generates comprehensive reports including data logs and cyber performance metrics of the simulation) Crabtree teaches simulation of a network but does not *explicitly* teach simulation of a particular asset. Bari more explicitly teaches a cyber security restoration engine configure to simulate an asset of a computing network. [0005][0006][0017][0048][0049][0063] (teaches an attack simulation that is simulated against an emulation of a network including a virtual simulation network that is based on the actual physical network assets) It would have been obvious to one of ordinary skill in the art effective filing date of the claimed invention to use the teaching of Bari with the prior art because it would produce more accurate results of a simulated cyber-attack. As per claim 20. The apparatus of claim 19, Crabtree teaches wherein the cyber security restoration engine is configured to generate a metric indicative of an effect that the action had on the simulation. [0085] (teaches generating metrics based on the simulated attack) Claim(s) 16 is/are rejected under 35 U.S.C. 103 as being unpatentable over Crabtree US 2025/0007942 in view of Barai US 2021/0352100 in view of Risoldi US 2020/0311630 As per claim 16. The apparatus of claim 15, Crabtree and Barai do not *explicitly* teach the following. Risoldi teaches wherein the user interface is configured to display a representation of a plurality of assets of the computing network, and wherein the user interface is configured to allow the user to select, from the plurality of assets, the asset to use in the simulated cyber security scenario. [0045][0068] (teaches a user interface to select assets on the network for risk evaluation) It would have been obvious to one of ordinary skill in the art effective filing date of the claimed invention to use the teaching of Risoldi with the prior art because it improves user accessibility and control. Conclusion Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to CHRISTOPHER BROWN whose telephone number is (571)272-3833. The examiner can normally be reached M-F 8-5. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, Luu Pham can be reached at (571) 270-5002. The fax phone number for the organization where this application or proceeding is assigned is 571-273-8300. Information regarding the status of published or unpublished applications may be obtained from Patent Center. Unpublished application information in Patent Center is available to registered users. To file and manage patent submissions in Patent Center, visit: https://patentcenter.uspto.gov. Visit https://www.uspto.gov/patents/apply/patent-center for more information about Patent Center and https://www.uspto.gov/patents/docx for information about filing in DOCX format. For additional questions, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /CHRISTOPHER J BROWN/Primary Examiner, Art Unit 2439
Read full office action

Prosecution Timeline

Jul 19, 2024
Application Filed
Apr 23, 2026
Non-Final Rejection mailed — §101, §103
Jun 24, 2026
Response Filed
Sep 02, 2026
Final Rejection mailed — §101, §103 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12719928
SYSTEM AND METHOD FOR ADAPTIVE DECEPTION ORCHESTRATION
2y 0m to grant Granted Aug 25, 2026
Patent 12712905
EVALUATING NETWORK FLOW RISKS
3y 11m to grant Granted Aug 18, 2026
Patent 12694100
CREATION AND RETENTION OF IMMUTABLE SNAPSHOTS TO FACILITATE RANSOMWARE PROTECTION
3y 5m to grant Granted Jul 28, 2026
Patent 12689631
USING MESSAGE CONTEXT TO EVALUATE SECURITY OF REQUESTED DATA
5y 10m to grant Granted Jul 21, 2026
Patent 12688291
RANSOMWARE DETECTION AND DATA PRUNING MANAGEMENT
1y 11m to grant Granted Jul 21, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
76%
Grant Probability
88%
With Interview (+12.6%)
3y 5m (~1y 2m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 720 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month