Regular expressions for advanced patterns

Prev Next

Trellix DLP advanced patterns use regular expressions (regex) to allow complex pattern matching.

Advanced pattern definitions use the Google RE2 regex syntax. By default they are case sensitive. While a full description of RE2 syntax is beyond the scope of this document, some of the more commonly used terms are listed in the table.

[abc]

Matches a single character a, b, or c

[^abc]

Matches a single character not a, b, or c

[0-9]

Matches a single character in the range 0-9

[^0-9]

Matches a single character not in the range 0-9

(ab|cd)

Matches ab or cd

\d

Matches any ASCII digit

\D

Matches any non-digit character

\s

Matches any whitespace character

\S

Matches any non-whitespace character

\w

Matches any alphanumeric character

\W

Matches any non-alphanumeric character

\b

ASCII word boundary

\ (when used with punctuation, for example \]

Matches ] (Escapes the next character, that is, removes its special meaning.)

.

Any single character

*

Modifies the previous token to match 0 or more times

+

Modifies the previous token to match 1 or more times

{3,4}

Modifies the previous token to match 3 or 4 times

?

Modifies the previous token to match 0 or 1 times (makes it optional)

(?i)

Sets matching to be case insensitive up to next closing ) (Accounts for nested () for example ((?i)insensitive)sensitive

(?-i)

Sets matching to be case sensitive up to next closing )