Classifying by file location

Prev Next

Sensitive content can be defined by where it is located (stored) or by where it is used (file extension or application).

Trellix DLP Endpoint uses several methods to locate and classify sensitive content. Data-at-rest is the term used to describe file locations. It classifies content by asking questions like "where is it in the network?" or "which folder is it in?" Data-in-use is the term used to define content by how or where it is used. It classifies content by asking questions like "which application called it?" or "what is the file extension?"

Trellix DLP EndpointDiscovery rules find your data-at-rest. They can search for content in endpoint computer files or email storage (PST, mapped PST, and OST) files. Depending on the properties, applications, or locations in the rule classification, the rule can search specified storage locations and apply encryption, quarantine, or RM policies. Alternately, the files can be tagged or classified to control how they are used.