Classification definitions and criteria

Prev Next

Classification definitions and criteria contain one or more conditions describing the content or file properties.

Available conditions

Property

Applies to:

Definition

Supported products

Advanced Pattern

Definitions, criteria

Regular expressions or phrases used to match data such as dates or credit card numbers.

All products

Dictionary

Definitions, criteria

Collections of related keywords and phrases such as profanity or medical terminology.

Keyword

Criteria

A string value.

You can add multiple keywords separated by semicolon (;) to content classification or content fingerprinting criteria. The default Boolean for multiple keywords is OR, but can be changed to AND.

Proximity

Criteria

Defines a conjunction between two properties based on their location to each other.

Advanced patterns, dictionaries, or keywords can be used for either property. You can add multiple keywords separated by comma (,).

The Closeness parameter is defined as "less than x characters," where the default is 1. You can also specify a Match count parameter to determine the minimum number of matches to trigger a hit.

Document Properties

Definitions, criteria

Contains these options:

  • Any Property

  • Author

  • Category

  • Comments

  • Company

  • Keywords

  • Last saved by

  • Manager Name

  • Security

  • Subject

  • Template

  • Title

Any Property is a user-defined property.

File Encryption

Criteria

Contains these options:

  • Not encrypted*

  • Trellix Encrypted Self-Extractor

  • Trellix Endpoint Encryption

  • Microsoft Rights Management encryption*

  • Azure Rights Management encryption*

  • Unsupported encryption types or password protected file*

  • Trellix DLP Endpoint for Windows (All options are supported)

    Note

    File encryption isn't supported with Trellix DLP Endpoint for Mac.

  • Trellix DLP Discover, Trellix DLP Network Prevent, and Trellix DLP Network Monitor support only the options marked with *

File Extension

Definitions, criteria

Groups of supported file types such as MP3 and PDF.

All products

File Information

Definitions, criteria

Contains these options:

  • Date Accessed

  • Date Created

  • Date Modified

  • File Extension*

  • File Name*

  • File Owner

  • File Size*

  • All products

  • Trellix DLP Network Prevent and Trellix DLP Network Monitor support only the options marked with *

Location in file

Criteria

The section of the file the data is located in; Header, Footer, Body or within the first characters. Specifying the number of characters for the within first (characters) option in a classification looks for the sensitive content in the Header, that is, in the first part of the first page in a document.

  • Microsoft Word documents — the classification engine can identify Header, Body, and Footer.

  • PowerPoint documents — WordArt is considered Header; everything else is identified as Body.

  • Other documents — Header and Footer are not applicable. The classification criteria does not match the document if they are selected.

Third Party tags

Criteria

Used to specify Titus field names and values.

  • Trellix DLP Endpoint for Windows

  • Trellix DLP Network Prevent

  • Trellix DLP Network Monitor

True File Type

Definitions, criteria

Groups of file types.

For example, the built-in Microsoft Excel group includes Excel XLS, XLSX, and XML files, as well as Lotus WK1 and FM3 files, CSV and DIF files, Apple iWork files, and more.

All products

Application Template

Definitions

The application or executable accessing the file.

  • Trellix DLP Endpoint for Windows

  • Trellix DLP Endpoint for Mac

End-User Group

Definitions

Used to define manual classification permissions.

Network Share

Definitions

The network share the file is stored in.

Trellix DLP Endpoint for Windows

URL List

Definitions

The URL the file is accessed from.