Classification scans detect classified or sensitive information.Use the results of inventory scans to build classification scans.
A classification scan performs the following:
Action | When scanning a file repository | When scanning a database |
|---|---|---|
Collects the same metadata as an inventory scan | x | x |
Analyzes the true file type based on the content of the file rather than the extension | x | |
Collects data on files or tables that match the configured classification | x | x |
Restores the last access time of files scanned | x |
Classification scans are slower than inventory scans because the text extractor accesses, parses, and analyzes the files to match definitions in the classification specifications. Classifications consist of definitions that can include keywords, dictionaries, text patterns, and document properties. These definitions help identify sensitive content that might require extra protection. By using the OLAP tools to view multidimensional patterns of these parameters, you can create optimized remediation scans.
The results of classification scans are displayed on the Data Inventory and Data Analytics tabs.
Detecting encrypted files
File repository classification scans detect data with these encryption types:
Microsoft Rights Management encryption
Azure RMS encryption
Seclore Rights Management encryption
Unsupported encryption types or password protection
Not encrypted
Consider these points when scanning encrypted files:
Trellix DLP Discover can extract and scan files encrypted with Microsoft RMS as long as Trellix DLP Discover has the credentials configured. Other encrypted files can't be extracted, scanned, or matched to classifications.
Files encrypted with Adobe Primetime digital rights management (DRM) and Trellix® File and Removable Media Protection are detected as Not Encrypted.
Trellix DLP Discover supports classification criteria options for Microsoft Rights Management Encryption and Not Encrypted.