DCT
3:26-cv-02942
Speech Transcription LLC v. Wazuh Inc
Key Events
Complaint
Table of Contents
complaint Intelligence
I. Executive Summary and Procedural Information
- Parties & Counsel:
- Plaintiff: Speech Transcription, LLC (Wyoming)
- Defendant: Wazuh, Inc. (Delaware)
- Plaintiff's Counsel: SML Avvocati P.C.
- Case Identification: 3:26-cv-02942, N.D. Cal., 04/06/2026
- Venue Allegations: Plaintiff alleges venue is proper in the Northern District of California because Defendant maintains an established and regular place of business in the district and has committed acts of patent infringement from that location.
- Core Dispute: Plaintiff alleges that Defendant's Wazuh Extended Protection and Response (XDR) platform infringes a patent related to a unified, multi-vendor security management system for endpoint devices.
- Technical Context: The technology addresses the management of endpoint security, a field focused on protecting individual computing devices (e.g., PCs, servers) from cybersecurity threats by consolidating security functions from various sources.
- Key Procedural History: The complaint notes that during the patent's examination, the U.S. Patent Examiner cited U.S. Patent No. 7,058,796 as the most relevant prior art. This may indicate a potential area of focus for future validity challenges concerning novelty and non-obviousness.
Case Timeline
| Date | Event |
|---|---|
| 2004-09-14 | U.S. Patent No. 8,938,799 Priority Date |
| 2015-01-20 | U.S. Patent No. 8,938,799 Issue Date |
| 2026-04-06 | Complaint Filing Date |
| 2033-06-07 | U.S. Patent No. 8,938,799 Nominal Expiration Date |
II. Technology and Patent(s)-in-Suit Analysis
U.S. Patent No. 8,938,799 - SECURITY PROTECTION APPARATUS AND METHOD FOR ENDPOINT COMPUTING SYSTEMS
This patent is referred to as the "'799 Patent," issued January 20, 2015.
The Invention Explained
- Problem Addressed: The patent's background describes the state of the art as suffering from a "heterogeneous environment" where multiple security products from different vendors are deployed on each endpoint Compl. ¶14 This approach allegedly burdens the host computer, creates software conflicts, increases management complexity, and leads to a high total-cost-of-ownership '799 Patent, col. 3:49-67
- The Patented Solution: The invention proposes a "unified security management system" that creates a "unified management zone (UMZ)" for endpoints '799 Patent, col. 5:28-30 A key component is a "Security Utility Blade (SUB)," a hardware and software subsystem at the endpoint that functions as an "open platform for repository of defense function software modules... from any participating vendors" '799 Patent, col. 6:51-54 '799 Patent, FIG. 1B This architecture is designed to centralize and standardize security management by terminating and translating commands from various vendor systems, preventing vendors from having direct access to the endpoints themselves '799 Patent, col. 5:32-41
- Technical Importance: The described solution aims to decouple security function provisioning from direct endpoint access, potentially simplifying deployment, reducing system conflicts, and lowering operational costs in complex enterprise environments.
Key Claims at a Glance
- The complaint asserts at least independent claim 14 Compl. ¶33
- Essential elements of claim 14:
- A security subsystem configurable between a network and a host of an endpoint,
- the security subsystem comprising computing resources for providing:
- an open platform for receiving and executing security function software modules from multiple vendors
- for providing defense functions for protection of the host.
- The complaint states Plaintiff may assert infringement of "one or more claims" of the '799 Patent Compl. ¶33
III. The Accused Instrumentality
Product Identification
The Wazuh Extended Protection and Response (XDR) platform (the "Accused Instrumentality") Compl. ¶28
Functionality and Market Context
- The complaint describes the Accused Instrumentality as a "single management platform" that provides security functions including intrusion detection, malware detection, file integrity monitoring, and vulnerability detection Compl. ¶28
- The platform is alleged to protect endpoints by "incorporating open source intelligence (OSINT) sources such as SURICATA, VIRUS TOTAL, Abuse IPDB, and YARA-CI provided by third-party security solutions" Compl. ¶28 The complaint's theory appears to equate these third-party sources with the "multiple vendors" recited in the patent's claims.
IV. Analysis of Infringement Allegations
The complaint references a claim chart in Exhibit B, which was not provided. The following analysis is based on the narrative infringement allegations in the complaint body.
'799 Patent Infringement Allegations
| Claim Element (from Independent Claim 14) | Alleged Infringing Functionality | Complaint Citation | Patent Citation |
|---|---|---|---|
| A security subsystem configurable between a network and a host of an endpoint, | The Wazuh XDR platform is alleged to function as a "single management platform" that protects endpoints. | ¶28 | col. 19:48-52 |
| the security subsystem comprising computing resources for providing: | The Wazuh XDR platform provides security functions such as intrusion detection and malware detection. | ¶28 | col. 20:21-24 |
| an open platform for receiving and executing security function software modules from multiple vendors | The platform allegedly functions as an open platform by "incorporating open source intelligence (OSINT) sources such as SURICATA, VIRUS TOTAL, Abuse IPDB, and YARA-CI provided by third-party security solutions." | ¶28 | col. 6:51-56 |
| for providing defense functions for protection of the host. | The platform provides security functions including "intrusion detection, malware detection, file integrity monitoring, configuration assessment, [and] vulnerability detection." | ¶28 | col. 19:50-52 |
No probative visual evidence provided in complaint.
Identified Points of Contention
- Scope Questions: The central dispute may concern whether the accused platform's alleged "incorporating [of] open source intelligence (OSINT) sources" meets the claim limitation of "receiving and executing security function software modules from multiple vendors." A key question for the court will be whether OSINT data, rulesets (e.g., YARA-CI), or threat feeds constitute "software modules" as understood in the context of the '799 Patent.
- Technical Questions: The complaint does not specify the technical mechanism by which the Wazuh platform "incorporates" third-party sources. The infringement analysis will depend on whether this process involves merely consuming data feeds and rules into a proprietary engine or if it entails the distinct "receiving and executing" of executable code components as the patent may require.
V. Key Claim Terms for Construction
Term: "security function software modules"
- Context and Importance: This term is critical, as the infringement allegation hinges on equating third-party OSINT sources with "software modules." The defendant will likely argue for a narrow construction, while the plaintiff will argue for a broad one.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The patent provides a list of defense functions, such as "Endpoint Firewall 511, Antivirus 512, IDS/IPS 513," which are described as components of the system '799 Patent, col. 11:3-5 Plaintiff may argue that any data or rule set that enables such a function qualifies as a "module."
- Evidence for a Narrower Interpretation: The patent describes a process where software modules "can be downloaded and executed in a Repository and Execution Unit 108" '799 Patent, col. 8:46-49 Defendant may argue this language implies that "software modules" are distinct, executable code packages, not merely data or configuration files like threat intelligence feeds.
Term: "open platform"
- Context and Importance: Whether the Wazuh XDR platform is an "open platform" is a foundational question for infringement. The definition will determine if the accused architecture falls within the claim scope.
- Intrinsic Evidence for Interpretation:
- Evidence for a Broader Interpretation: The specification describes the SUB as functioning as "an open platform for repository of defense function software modules... from any participating vendors" '799 Patent, col. 6:51-54 This language suggests a primary characteristic is vendor-agnosticism.
- Evidence for a Narrower Interpretation: The patent consistently describes the "open platform" in the context of a "Security Utility Blade (SUB)," a specific hardware/software component positioned between the network and the host '799 Patent, col. 5:23-25 '799 Patent, col. 9:6-9 A defendant might argue the term is limited to this particular architecture, which isolates security functions from the host operating system.
VI. Other Allegations
- Indirect Infringement: The complaint alleges inducement, stating that Defendant distributes "product literature and website materials inducing end users and others to use its products in the customary and intended manner that infringes the '799 Patent" Compl. ¶36
- Willful Infringement: The basis for willfulness is alleged knowledge of infringement "at least as of the service of the present complaint" Compl. ¶31 This allegation appears to be limited to post-suit conduct.
VII. Analyst's Conclusion: Key Questions for the Case
- A core issue will be one of definitional scope: can the term "security function software modules," which the patent describes in the context of downloadable and executable units, be construed to cover the "open source intelligence (OSINT) sources" that the accused platform allegedly "incorporates"? The outcome of this claim construction will be pivotal.
- A key evidentiary question will be one of technical mechanism: what is the specific technical nature of the alleged "incorporation"? Discovery will need to reveal whether the Wazuh platform receives and executes distinct software components from third parties, as the patent may require, or if it primarily consumes data feeds and rulesets, potentially creating a functional mismatch with the claimed invention.
Analysis metadata
Loading Complaint
Suggested improvements