Patent 11853779 was granted and assigned to Twistlock on December, 2023 by the United States Patent and Trademark Office.
A host device and methods for efficient distributed security forensics. The method includes creating, at a host device configured to run a virtualization entity, an event index for the virtualization entity; encoding a plurality of events related to the virtualization entity, wherein each event includes a process having a process path; and updating the event index based on the encoded plurality of events.