Monitor and prevent transfer of confidential data from an endpoint machine to wireless hard drive
search cancel

Monitor and prevent transfer of confidential data from an endpoint machine to wireless hard drive

book

Article ID: 165057

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent Data Loss Prevention Endpoint Discover

Issue/Introduction

Users are connecting their endpoint machines to a wireless hard drive and transferring confidential data between them. They are doing both, mounting the wireless hard drive as a network share or using an HTTP URL to upload and download file or to stream video, audio and pictures.

You want to block this activity or monitor it using Symantec Data Loss Prevention (DLP) Endpoint Agent.

Environment

Windows 7, Windows 8, 10, and 11

Mac OS X

DLP 14.0 and higher

Resolution

Below mentioned steps can be followed to block or monitor this activity:

  1. Log into the Enforce console > System > Agents > Agent Configuration > Agent Monitoring
  2. Enable “Copy to Share” channel. Click Save to save the changes
  3. Create a new policy by following below mentioned steps:
    1. Enforce > Manage > Policies > Policy List > Add Policy > Add a blank policy
    2. Type the name of the policy
    3. Select the policy group to which you would like to assign this policy
    4. Click “Add Rule” > select Protocol or Endpoint Monitoring > click Next > Type the name of the Rule
    5. Select the severity as per your requirement
    6. Select HTTP and HTTPs from Protocol
    7. Select “Copy to Network Share” from Endpoint Destination
    8. Click on the drop down arrow next to “Also match” and select “Endpoint Location” and click Add
    9. Select Location as “Off the Corporate Network” and click Ok
    10. Click Save to save the policy 

Application Monitoring: 

  1. Log into the Enforce console > System > Agents > Application Monitoring
  2. Click on Microsoft Internet Explorer > select Application File Access
  3. Select Read option and save the changes
  4. Repeat same process for Mozilla Firefox and Google Chrome