| CPC G06F 21/552 (2013.01) [G06F 21/554 (2013.01); G06F 2221/034 (2013.01)] | 20 Claims |

|
1. A system for threat mitigation comprising:
a processor; and
a non-transitory memory coupled to the processor and comprising instructions executable by the processor for:
detecting an occurrence of an event;
matching the event to a behavior rule associated with the event, the behavior rule comprising a plurality of behavior rule instructions and associated with a threat, each of the plurality of behavior rule instructions associated with an occurrence related to the event; and
executing the behavior rule, comprising
executing a first one of the plurality of behavior rule instructions of the behavior rule;
detecting the occurrence associated with the first one of the behavior rule instructions of the behavioral rule and, in response;
executing a second one of the plurality of behavior rule instructions of the behavioral rule, comprising;
executing a threat mitigation action related to the event.
|