Prosecution Insights
Last updated: October 01, 2026
Application No. 18/806,181

Social Engineering Threat Assessment Platform (SETAP)

Final Rejection §101
Filed
Aug 15, 2024
Examiner
WAESCO, JOSEPH M
Art Unit
3625
Tech Center
3600 — Transportation & Electronic Commerce
Assignee
Bank of America Corporation
OA Round
2 (Final)
46%
Grant Probability
Moderate
3-4
OA Rounds
1y 1m
Est. Remaining
89%
With Interview

Examiner Intelligence

Grants 46% of resolved cases
46%
Career Allowance Rate
219 granted / 471 resolved
-5.5% vs TC avg
Strong +43% interview lift
Without
With
+42.6%
Interview Lift
resolved cases with interview
Typical timeline
3y 3m
Avg Prosecution
40 currently pending
Career history
525
Total Applications
across all art units

Statute-Specific Performance

§101
48.4%
+8.4% vs TC avg
§103
34.9%
-5.1% vs TC avg
§102
2.7%
-37.3% vs TC avg
§112
12.9%
-27.1% vs TC avg
Black line = Tech Center average estimate • Based on career data from 471 resolved cases

Office Action

§101
DETAILED ACTION The following is a Final Office action. In response to Non-Final communications received 12/29/2025, Applicant, on 3/11/2026, amended Claims 1, 8, and 15. Claims 1-20 are pending in this action, have been considered in full, and are rejected below. Response to Arguments Arguments regarding 35 USC §101 Alice – Applicant asserts that the claims are not directed at an abstract idea, either that of a Mental Process or a Certain Method of Organization Human Activity, by stating that the claims recite use of SQL scripts, and that the claims don’t recite one of the enumerated groupings. Examiner disagrees as the claims recite clear abstractions of both mental processes and certain methods of organizing human activity as per the rejection below, as use of an SQL script does not change the fact that this is sending and receiving information to essentially detect fraud or risk, which is a fundamental economic process. This is stated clearly by the office action, and the use of SQL scripts does not change the fact there are two abstract ideas which are identified in the Claims, nor does it make the claims practically integrated. Further, at best this is utilization of current technologies to perform the abstract limitations of the claims, as there is no improvement to the Scripts, any additional element, alone or in combination, any technology, or technological process, and thus “Applying It” similar to Alice, not practically integrated, nor significantly more, and not eligible by the MPEP. Applicant asserts that the claimed subject matter is eligible under 101 because the claim as a whole are directed to an improvement in computer-implemented technologies and provides a specific solution which don’t preempt or monopolize any other solutions or abstract ideas. Examiner disagrees as this is a mere assertion that the claims are eligible under 101. Applicant does not state how or why these would not be considered abstract (other than stating they don’t monopolize other solutions) under Prong 1, nor why they would be integrated with the limitations to overcome 101 under Prong 2 of the Alice Analysis of the MPEP, or even what technologies have been improved. The claims recite limitations which are abstract ideas, as per the rejection below, of both a “Mental Process” and “a Certain Method of Organizing Human Activity”, which are clearly outlined as per the rejection below. Further, the claims are not practically integrated as the additional elements of a computerized system, SQL scripts, etc. are recited at a high-level of generality (i.e., as a generic processor performing a generic computer function of storing, retrieving, sending, and processing data) such that they amount to no more than mere instructions to apply the exception using generic computer components. Applicant asserts the there is an improvement to cybersecurity as this is more than a mere “transaction processing”, and that the claims are necessarily rooted in computing. Examiner disagrees as this is utilization of current technologies, “Applying It”, similar to that of Alice, and does not make these limitations eligible under 101, as there is no improvement to the SQL Scripts, computer system, or any additional element, alone or in combination, such as the system, memory, processor, etc. Further, there is no improvement to a technology or any technological process and performing these actions on a computer would be utilization of current technologies to perform the abstract limitations of the Claims, and any inventive concept would be contained wholly within the abstraction. Therefore, the arguments are non-persuasive, the Claims are ineligible as there is no inventive concept, and the rejection of the Claims and their dependents are maintained under 35 USC 101. Arguments regarding 35 USC §103 – The rejection is hereby removed in light of Applicant’s amendments for the reasons found in the “Allowable Subject Matter” section found below. Claim Rejections - 35 USC § 101 35 U.S.C. 101 reads as follows: Whoever invents or discovers any new and useful process, machine, manufacture, or composition of matter, or any new and useful improvement thereof, may obtain a patent therefor, subject to the conditions and requirements of this title. Alice - Claims 1-20 are rejected under 35 U.S.C. 101 because the claimed invention is directed to an abstract idea without significantly more. Claims 1, 8, and 15 recite limitations to converting social engineering threat data into one or more templates (Collecting and Analyzing the Information, an observation and evaluation, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity),simulating one or more social engineering attacks for a target based on the one or more templates (Analyzing the Information, an evaluation, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), analyzing the one or more simulated social engineering attacks for the target (Analyzing the Information, an evaluation, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), executing the one or more simulated social engineering attacks for the target based on analysis results by initiating one or more simulated vishing phone calls to the target (Transmitting Information, a judgment, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), receiving response data responsive to the one or more simulated vishing phone calls: responsive to the response data including the target answering the one or more simulated vishing phone calls, generating at least one of: one or more simulated smishing text messages or one or more simulated phishing emails, wherein the one or more simulated smishing text messages or the one or more simulated phishing emails include a selectable link, sending the at least one of: one or more simulated smishing text messages or one or more simulated phishing emails (Collecting, Analyzing, and Transmitting Information, an evaluation, observation, and judgment, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), responsive to the response data including the target rejecting the one or more simulated vishing phone calls, generating one or more simulated smishing text messages, wherein the one or more simulated smishing text messages include a selectable link and sending the one or more simulated smishing text messages (Collecting, Analyzing, and Transmitting Information, an evaluation, observation, and judgment, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), responsive to the response data including the target not answering the one or more simulated vishing phone calls, recording an incident and rescheduling the one or more simulated vishing phone calls (Collecting, Analyzing, and Transmitting Information, an evaluation, observation, and judgment, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), and providing as feedback execution results to one or more parties (Transmitting the Analyzed Information, a judgment, a Mental Process; a Fundamental Economic Process, i.e. detecting fraud/mitigating risk; a Certain Method of Organizing Human Activity), which under their broadest reasonable interpretation, covers performance of the limitation in the mind for the purposes of a Fundamental Economic Process, i.e. mitigating fraud/risk, but for the recitation of generic computer components. That is, other than reciting a computing platform having one or more processors, a communication interface, memory, use of a phone, medium, a computing device associated to the target, and use of SQL scripts, nothing in the claim element precludes the step from practically being performed or read into the mind for the purposes of a Fundamental Economic Process. For example, analyzing the one or more simulated social engineering attacks for the target encompasses a supervisor or manager sending out fake phone calls which try to gain information from employees, analyzing the information they get back, and then making decisions from that information in the form of feedback, which is an observation, evaluation, and judgment. If a claim limitation, under its broadest reasonable interpretation, covers performance of the limitation in the mind but for the recitation of generic computer components, then it falls within the “Mental Processes” grouping of abstract ideas, an observation, evaluation, and judgment. Further, as described above, the claims recite limitations for a Fundamental Economic Process, a “Certain Method of Organizing Human Activity”. Accordingly, the claim recites an abstract idea. This judicial exception is not integrated into a practical application. In particular, the claim recites the above stated additional elements to perform the abstract limitations as above. The computing platform, computing device, SQL scripts, one or more processors, communication interface, memory, use of a phone, and medium are recited at a high-level of generality (i.e., as a generic software/module performing a generic computer function of storing, retrieving, sending, and processing data) such that they amount to no more than mere instructions to apply the exception using generic computer components. Even if taken as an additional element, the receiving and transmitting steps above are insignificant extra-solution activity as these are receiving, storing, and transmitting data as per the MPEP 2106.05(d). Accordingly, these additional elements do not integrate the abstract idea into a practical application because they do not impose any meaningful limits on practicing the abstract idea. The claim is directed to an abstract idea. The claim does not include additional elements that are sufficient to amount to significantly more than the judicial exception, when considered both individually and as an ordered combination. As discussed above with respect to integration of the abstract idea into a practical application, the additional element being used to perform the abstract limitations stated above amount to no more than mere instructions to apply the exception using generic computer components. Mere instructions to apply an exception using generic computer components cannot provide an inventive concept. The claim is not patent eligible. Applicant’s Specification states: “[0095]The computing platform 900 may include a processor 902, memory 904, and a communication interface 906. The computing platform 900 may include a bus 910, through which the processor 902, the memory 904, the communication interface 906, and other components of the computing platform 900 exchange information with each other.” Which shows that any generic computer with a processor and memory can be used to perform the abstract limitations, such as a laptop, phone, desktop, etc., and from this interpretation, one would reasonably deduce the aforementioned steps are all functions that can be done on generic components, and thus application of an abstract idea on a generic computer, as per the Alice decision and not requiring further analysis under Berkheimer, but for edification the Applicant’s specification has been used as above satisfying any such requirement. This is “Applying It” by utilizing current technologies. For the receiving and transmitting steps that were considered extra-solution activity in Step 2A above, if they were to be considered additional elements, they have been re-evaluated in Step 2B and determined to be well-understood, routine, conventional, activity in the field. The background does not provide any indication that the additional elements, such as the platform, processor, memory, etc., nor the receiving or transmitting steps as above, are anything other than a generic, and the MPEP Section 2106.05(d) indicates that mere collection or receipt, storing, or transmission of data is a well‐understood, routine, and conventional function when it is claimed in a merely generic manner (as it is here). For these reasons, there is no inventive concept. The claim is not patent eligible. Claims 2-7, 9-14, and 16-20 contain the identified abstract ideas, further narrowing them, with the additional elements of a computing device associated with the organization which is highly generic as per Applicant’s Specification when considered as part of a practical application or under prong 2 of the Alice analysis of the MPEP, thus not integrated into a practical application, nor are they significantly more for the same reasons and rationale as above. After considering all claim elements, both individually and in combination, Examiner has determined that the claims are directed to the above abstract ideas and do not amount to significantly more. Therefore, the claims and dependent claims are rejected under 35 U.S.C. 101 as being directed to non-statutory subject matter. See Alice Corporation Pty. Ltd. v. CLS Bank International, No. 13–298. Allowable Subject Matter Claims 1-20 have overcome the prior art and would be allowable if amended to overcome the 35 USC 101 rejection and any other rejections. The closest prior art of record are Brennan (U.S. Publication No. 2024/009,6234), Albero (U.S. Publication No. 2022/006,0515), and Kras (U.S. Publication No. 2023/000,8987). Brennan, a system and method for user feedback on receiving a simulated phishing message, teaches a method for assessing social engineering threats, converting, by a computing platform having one or more processors, social engineering threat data into one or more templates, simulating one or more social engineering attacks for a target based on the one or more templates, analyzing the one or more simulated social engineering attacks for the target, receiving, from a computing device associated with the target, response data responsive to the one or more simulated communication: responsive to the response data including the target answering the one or more simulated communication, triggering at least one of: one or more simulated smishing text messages or one or more simulated phishing emails to be sent to the computing device associated with the target, responsive to the response data including the target rejecting the one or more simulated vishing phone calls, triggering one or more simulated smishing text messages to be sent to the computing device associated with the target; responsive to the response data including the target not answering the one or more simulated vishing phone calls, recording an incident and rescheduling the one or more simulated vishing phone calls; and providing, as feedback by the one or more processors, and executing the one or more simulated social engineering attacks for the target based on analysis results by initiating one or more simulated phishing campaigns to the target, but it does not explicitly state these are simulated vishing phone calls. Albero, a system and method for user responses to cyber security threats, teaches vishing activity such as phone calls being simulated, as well as mitigation procedures based on the targeted users received information which is determined, but it does not teach providing the execution results to the organization the target belongs to and the results for targets within the organization, nor does either Albero or Brennan teach use of SQL scripts. Kras, a system and method for simulated phishing attacks involving message threads, teaches a simulation system for simulated phishing using links with attachments, in texts, emails, and message threads, but it does not teach use of SQL scripts. None of the above prior art explicitly teaches this explicit manner as to which the SQL scripts are used when there is response data of a target answering or not answering the vishing class, and then generating text messages based upon this, along with the other limitations of the Claims, which Applicant points out on pgs. 5 and 6 of the remarks of 3/11/2026, and these are the reasons which adequately reflect the Examiner's opinion as to why Claims 1-20 are allowable over the prior art of record, and are objected to as provided above. Conclusion The prior art made of record is considered pertinent to applicant's disclosure. US 20240236128 A1 Irimie; Alin et al. SYSTEMS AND METHODS FOR PERFORMING A SIMULATED PHISHING ATTACK US 20240096234 A1 Brennan; Katie SYSTEM AND METHODS FOR USER FEEDBACK ON RECEIVING A SIMULATED PHISHING MESSAGE US 20230008987 A1 Kras; Greg SYSTEMS AND METHODS FOR SIMULATED PHISHING ATTACKS INVOLVING MESSAGE THREADS US 20220070204 A1 Thomas; Jason et al. System and Method for Conducting Social Engineering Red Team Campaigns US 20220060515 A1 Albero; George et al. User Responses to Cyber Security Threats US 20240396937 A1 MORRIS; Sean et al. INTELLIGENT ANTI-PHISHING MANAGEMENT US 20240089285 A1 Jakobsson; Bjorn Markus et al. AUTOMATED RESPONSIVE MESSAGE TO DETERMINE A SECURITY RISK OF A MESSAGE SENDER US 20230388343 A1 Irimie; Alin et al. SYSTEMS AND METHODS FOR AIDA BASED EXPLOIT SELECTION US 20230247052 A1 Kras; Greg et al. SYSTEMS AND METHODS FOR REPORTING BASED SIMULATED PHISHING CAMPAIGN US 20230216879 A1 Sjouwerman; Stu SYSTEMS AND METHODS FOR AN ARTIFICIAL INTELLIGENCE DRIVEN SMART TEMPLATE US 20230012756 A1 Kras; Greg TIME BASED TRIGGERING OF DYNAMIC TEMPLATES US 20210377305 A1 Kras; Greg SYSTEMS AND METHODS FOR SIMULATED PHISHING ATTACKS INVOLVING MESSAGE THREADS US 20210029164 A1 Albero; George et al. USER RESPONSES TO CYBER SECURITY THREATS US 20200296133 A1 Kras; Greg et al. SYSTEM AND METHODS FOR REVERSE VISHING AND POINT OF FAILURE REMEDIAL TRAINING US 11184393 B1 Gendre; Adrien et al. Automated collection of branded training data for security awareness training Applicant's amendment necessitated the new ground(s) of rejection presented in this Office action. Accordingly, THIS ACTION IS MADE FINAL. See MPEP § 706.07(a). Applicant is reminded of the extension of time policy as set forth in 37 CFR 1.136(a). A shortened statutory period for reply to this final action is set to expire THREE MONTHS from the mailing date of this action. In the event a first reply is filed within TWO MONTHS of the mailing date of this final action and the advisory action is not mailed until after the end of the THREE-MONTH shortened statutory period, then the shortened statutory period will expire on the date the advisory action is mailed, and any nonprovisional extension fee (37 CFR 1.17(a)) pursuant to 37 CFR 1.136(a) will be calculated from the mailing date of the advisory action. In no event, however, will the statutory period for reply expire later than SIX MONTHS from the mailing date of this final action. Any inquiry concerning this communication or earlier communications from the examiner should be directed to JOSEPH M WAESCO whose telephone number is (571)272-9913. The examiner can normally be reached on 8 AM - 5 PM M-F. Examiner interviews are available via telephone, in-person, and video conferencing using a USPTO supplied web-based collaboration tool. To schedule an interview, applicant is encouraged to use the USPTO Automated Interview Request (AIR) at http://www.uspto.gov/interviewpractice. If attempts to reach the examiner by telephone are unsuccessful, the examiner’s supervisor, BETH BOSWELL can be reached on (571) 272-6737. The fax phone number for the organization where this application or proceeding is assigned is 571-273-1348. Information regarding the status of an application may be obtained from the Patent Application Information Retrieval (PAIR) system. Status information for published applications may be obtained from either Private PAIR or Public PAIR. Status information for unpublished applications is available through Private PAIR only. For more information about the PAIR system, see https://ppair-my.uspto.gov/pair/PrivatePair. Should you have questions on access to the Private PAIR system, contact the Electronic Business Center (EBC) at 866-217-9197 (toll-free). If you would like assistance from a USPTO Customer Service Representative or access to the automated information system, call 800-786-9199 (IN USA OR CANADA) or 571-272-1000. /JOSEPH M WAESCO/Primary Examiner, Art Unit 3625B 6/24/2026
Read full office action

Prosecution Timeline

Aug 15, 2024
Application Filed
Dec 16, 2025
Non-Final Rejection mailed — §101
Mar 11, 2026
Response Filed
Jun 26, 2026
Final Rejection mailed — §101 (current)

Precedent Cases

Applications granted by this same examiner with similar technology

Patent 12749089
SYSTEMS AND METHODS FOR ATTRIBUTING ELECTRONIC PURCHASE EVENTS TO PREVIOUS ONLINE AND OFFLINE ACTIVITY OF THE PURCHASER
2y 9m to grant Granted Sep 29, 2026
Patent 12725103
AUTOMATED TASK PLANNING SYSTEM AND METHOD USING HEURISTIC EVALUATION VALUE CALCULATED BASED ON CAUSAL ACTION NETWORK
2y 7m to grant Granted Sep 01, 2026
Patent 12718171
SYSTEMS AND METHODS FOR QUANTIFYING NETWORK GROWTH USING ARTIFICIAL INTELLIGENCE AND MACHINE LEARNING MODELS
2y 4m to grant Granted Aug 25, 2026
Patent 12709971
DEVICES, SYSTEMS, AND METHODS FOR GENERATING DRILLING REPORTS
2y 1m to grant Granted Aug 18, 2026
Patent 12664490
SYSTEM AND METHOD FOR INTERMODAL FACILITY MANAGEMENT
4y 2m to grant Granted Jun 23, 2026
Study what changed to get past this examiner. Based on 5 most recent grants.

Strategy Recommendation AI-generated — please review before filing

Get a prosecution strategy drawn from examiner precedents, rejection analysis, and claim mapping.
Typically takes 5-10 seconds — AI-generated, attorney review required before filing

Prosecution Projections

3-4
Expected OA Rounds
46%
Grant Probability
89%
With Interview (+42.6%)
3y 3m (~1y 1m remaining)
Median Time to Grant
Moderate
PTA Risk
Based on 471 resolved cases by this examiner. Grant probability derived from career allowance rate.

Sign in with your work email

Enter your email to receive a magic link. No password needed.

Personal email addresses (Gmail, Yahoo, etc.) are not accepted.

Free tier: 3 strategy analyses per month