How classification scans work

Prev Next

Classification scans detect classified or sensitive information.

A classification scan performs the following:

Action

When scanning a file repository

Analyzes the true file type based on the content of the file rather than the extension

x

Collects data on files or tables that match the configured classification

x

Restores the last access time of files scanned

x

Classifications consist of definitions that can include keywords, dictionaries, text patterns, and document properties. These definitions help identify sensitive content that might require extra protection. By using the OLAP tools to view multidimensional patterns of these parameters, you can create optimized remediation scans.

Detecting encrypted files

File repository classification scans detect data with these encryption types:

  • Microsoft Purview Rights Management

  • Azure RMS encryption

  • Seclore Rights Management encryption

  • Unsupported encryption types or password protection

  • Not encrypted

Consider these points when scanning encrypted files:

  • Trellix DLP Discover – SaaS can only scan files encrypted with Microsoft RMS, but can't extract these files because Microsoft RMS is not currently supported. Other encrypted files can't be extracted, scanned, or matched to classifications.

  • Files encrypted with Adobe Primetime digital rights management (DRM) and Trellix® File and Removable Media Protection are detected as Not Encrypted.

  • Trellix DLP Discover – SaaS supports classification criteria options for Microsoft Purview Rights Management and Not Encrypted.