How discovery scanning works

Prev Next

Use endpoint discovery scans to locate local file system or email storage files with sensitive content and tag or quarantine them.

Trellix DLP Endpoint - SaaS discovery is a crawler that runs on client computers. When it finds predefined content, it can monitor, quarantine, tag, or apply an RM policy to the files containing that content. Endpoint discovery can scan computer files or email storage (PST, mapped PST, and OST) files. Email storage files are cached on a per-user basis.

Note

To use endpoint discovery, you must activate the Discovery modules on the Policy CatalogClient configurationOperational Mode and Modules page.

At the end of each discovery scan, the Trellix DLP Endpoint - SaaS client sends a discovery summary event to the Protection Workspace in ePO - SaaS to log the details of the scan. The event includes an evidence file that lists the files that could not be scanned and the reason for not scanning each of these files. There is also an evidence file with files matching the classification and the action taken.

Schedule discovery scans on the Policy CatalogDLP PolicyEndpoint Discovery page. You can run a scan at a specific time daily, or on specified days of the week or month. You can specify start and stop dates, or run a scan when the Trellix DLP Endpoint - SaaS configuration is enforced. You can suspend a scan when the computer's CPU or RAM exceed a specified limit.

If you change the discovery policy while an endpoint scan is running, rules and schedule parameters change immediately. Changes to which parameters are enabled or disabled will take effect with the next scan. If the computer is restarted while a scan is running, the scan continues where it left off.

What content can be discovered?

You define discovery rules with a classification. Any file property or data condition that can be added to classification criteria can be used to discover content.

What happens to discovered files with sensitive content?

You can quarantine or tag email files. You can quarantine, tag, or apply an RM policy to local file system files. You can store evidence for both file types.