How classification scans work

Prev Next

Classification scans detect classified or sensitive information.Use the results of inventory scans to build classification scans.

A classification scan performs the following:

Action

When scanning a file repository

When scanning a database

Collects the same metadata as an inventory scan

x

x

Analyzes the true file type based on the content of the file rather than the extension

x

Collects data on files or tables that match the configured classification

x

x

Restores the last access time of files scanned

x

Classification scans are slower than inventory scans because the text extractor accesses, parses, and analyzes the files to match definitions in the classification specifications. Classifications consist of definitions that can include keywords, dictionaries, text patterns, and document properties. These definitions help identify sensitive content that might require extra protection. By using the OLAP tools to view multidimensional patterns of these parameters, you can create optimized remediation scans.

The results of classification scans are displayed on the Data Inventory and Data Analytics tabs.

Detecting encrypted files

File repository classification scans detect data with these encryption types:

  • Microsoft Rights Management encryption

  • Azure RMS encryption

  • Unsupported encryption types or password protection

  • Not encrypted

Consider these points when scanning encrypted files:

  • Trellix DLP Discover can extract and scan files encrypted with Microsoft RMS as long as Trellix DLP Discover has the credentials configured. Other encrypted files can't be extracted, scanned, or matched to classifications.

  • Files encrypted with Adobe Primetime digital rights management (DRM) and Trellix® File and Removable Media Protection are detected as Not Encrypted.

  • Trellix DLP Discover supports classification criteria options for Microsoft Rights Management Encryption and Not Encrypted.