Remediation scans can classify files by embedding a classification in the file's properties.
You can classify files as part of a remediation action. The classification is embedded into the file's properties. As a result, the classification is not lost when the files are changed, moved between repositories, uploaded to the web, or sent by email.
To classify files with remediation scans, configure the scan using a network discovery rule with a Classify File As action. When the repository is scanned, files that meet the conditions configured in the rule are classified according to the selected classification. Also, the classification's Tag ID is embedded into the file's properties.
To be classified, files must meet one of the following classification conditions specified in the rule.
Content classification — keyword, dictionary, advanced pattern, proximity, or document properties
Classification with registered documents
File sharing type (Box only)
The classification applied by the rule is selected on the Reaction tab, allowing the user to set the Classify File As classification to be:
The same as the classification on the Condition tab.
A different classification from the Condition tab classification with criteria.
A different classification from the Condition tab classification without any criteria (for labeling).
Limitations
The following limitations apply to applying classifications with remediation scans:
A rule can have only one classification configured in the Classify File As reaction.
A file is limited to five embedded classifications. (That is, up to five rules can apply to one file.)
The user credentials configured in the remediation scan must have read, write, and modify permissions.
Protected or secured files (when Modify isn't allowed) can't be classified.
Only the following file extensions are supported:
aif
mpeg
tiff
aiff
mpg
vsd
avi
msg
vsdx
dng
pdf
vss
doc
png
vst
docm
pot
wav
docx
potm
wma
dot
potx
wmv
dotm
pps
wps
dotx
ppsm
xdcam
eps
ppsx
xls
jpeg
ppt
xlsb
jpg
pptm
xlsm
mov
pptx
xlsx
mp2
ps
xlt
mp3
psd
xltm
mp4
swf
xltx
mpa
tif
xps
Note
For unsupported file types, the operational event
File type is not supported for auto classification.is sent.The content of the file must match its extension or it can't be classified. For example, a txt file with extension changed to .doc is not classified.
PostScript files (*.ps and *.eps) must be at least version 3.0. The standard library doesn't support versions earlier than 3.0, so they are not classified.
MP3 files contain metadata inside a special ID3 tag. This tag usually contains information like track title, artist, and album. For the files to be classified, this tag must exist. MP3 files without such tag are not classified.
*.mpeg and *.mpg files must be of ISO media file format to be classified. To verify this, open the file with Notepad. After the first 4 bits is some text starting with
ftyp, for exampleftypmp42, if the file format is ISO.Files with size=0 are not downloaded, so can't be tagged. The operational event
File is not supported.is sent.
Removing automatic classifications
Note
Discovery rules with the Remove Automatic Classification action are not backward compatible. Rules passed to earlier versions of Trellix DLP Discover use the fallback action No Action.
Remediation scans in File Server, SharePoint, or Box repositories can remove automatic classifications and apply them. Creating a rule with a Remove Automatic Classification action removes the specified classification tag from a file without affecting other tags that might be applied to the file. The rule can specify only one classification, and can't remove tags applied manually.