This task list summarizes the steps for configuring and viewing data exfiltration alerts on a appliance installed in a cloud or on-premises TrellixMVX deployment.
Note
If you use a SmartVision appliance for data exfiltration detection only, you can install the appliance either at the network perimeter or in the network core, depending on the locations of the hosts and networks being monitored.
Prerequisites
Completion of Task list for deploying SmartVision.
Configure the homenet list with local hosts and networks to monitor for data theft.
If the homenet list is empty, private IP address ranges—the network ranges defined in RFC 1918 for IPv4 networks or RFC 4193 for IPv6 networks—are used in place of a configured homenet list. The homenet list is empty by default.
Enable data exfiltration detection.
Data exfiltration detection is enabled by default. If data exfiltration detection has been disabled, you will need to enable it explicitly:
Wait for egress traffic profiles to be built for the monitored hosts and networks.
Important
After you configure or edit the homenet list, it takes 72 hours to build baseline egress traffic profiles for the specified hosts and networks.
Filter the Alerts list for Data Exfiltration alerts only.