Part 1: Evolution of Trust - Adapting and Utilising CISA’s Zero Trust Maturity Model in an AI World
Your one stop shop for all things Netskope Data Loss Protection.
Recently active
When a user tries to download any files from his/her BYOD using organization's email platform, the download should be blocked.?? How can we achieve this in Netskope please provide me the steps..
Dear All I tried to setup Netskope Email DLP with Mimecast, however it seems like the message has not successfully deliver to mimecast MTA. 1. Configured SMTP settings (Domain, Tenant ID, Next Hop FQDN which is mimecast smart host, port)2. Configured exchange flow connector to route message to Netskope smart host3. Configured real time policy with action add X header: block when sensitive data is detect4. Setup content examination definitions and policy from Mimecast when receive X header: block 5. Test sending outbound email with sensitive info on the content. Tested sending another email without any sensitive info. (Both email had failed to deliver to recipient)6. Checked on SKope IT > Alerts > noticed that Email DLP policy has triggered with email consisted of sensitive info.7. Checked on Mimecast message tracking, however did't receive any message (for both sensitive and without sensitive message) Is there any steps that I miss out? Thank
I need to modify the default DLP profile for profanity as we have a user with a last name that matches the profanity profile. I raised a helpdesk ticket to follow the steps mentioned in https://docs.netskope.com/en/netskope-help/data-security/data-loss-prevention/dlp-entity/ to copy the Entity. However, I noticed that in the later releases of Netskope, the Entity tab was renamed to "Dictionary" and is different from the old Entity. Can anyone guide me on how to copy and modify the default profanity profile?
Currently for API DLP Policies you can only exclude by Domain. What is the reason behind not being able to exclude by User address? I have had many instances whereby a contractor is hired and only has a Gmail account, which I am not willing to exclude by Domain. This is generating massive amounts of false-positives. Thoughts?
Is there a away to only allow alerts and incidents to be generated on medium severity and above? We have too many alerts being generated on low severity matches.
How can I create an exclusion for DLP Realtime policies for a single user/group to exclude a specific Domain for a Specific DLP policy? Use case is, A user 1/Group 1 to exclude from a Single DLP policy (PCI DLP Policy) to an abc[.]com.But, if any other users/Groups try to upload PCI data we need detection. And, when the same user 1/Group 1 tries to upload PHI Data then we need detection on abc[.]com. Thanks in advance.
Hello Team, Good Day.I'm curious to know the setps or methods for integrating Sentinelone EDR and Netskope DLP solution for the Data analysis part.As a part of my study on Endpoint Security, I feel DLP also play a major role in protection of Data at Endpoints as same as EDR. Seeking guidance here for the integration.Thank you for the help. Regards & Thanks,
Hello,How to restrict any type of file transfer between corporate Laptop and Personal Laptopfor example, i have corporate laptop installed Netskope and i have personal laptop both are connected in home Wi-Fi , how to restrict any file type transfer between the devices. Kindly suggest a solution on this.
We are using Exception through Entities in our rule but it keeps on detecting ssid and ssan keyword while other keywords not. Why ssid is detecting if it is part of url ? how we can exclude url from detection below is the sample url https://www.sharonheightscc.com/default.aspx?p=DynamicModule&PageId=395579&ssid=318084&vnf=1
Hello, I’ve created a data dictionary containing false positive terms (D0). The given expressions does not seem to be working - P0 AND (NOT D0)P0 AND (NOT(P0 AND D0)) Predefined Identifiers(P0) - Full Names (International)Dictionary Identifiers(D0) - DLP-Exclude-Full NamesI’d like to detect all the terms which are IN P0 and NOT IN D0. Could anyone suggest an alternative, please ? Thanks !
Dear community,I am working with SWG and DLP to avoid users uploading sensitive content on corporate Onedrive.All the client has netskope client enabled and everybody run win10.I successfully managed to avoid users to upload on Onedrive via web a sensitive files, due to match with DLP policy, but the same user, while using Onedrive app just receives a warning.Basically, when the user upload the PII file is warned by the netskope client and it is also blocked, when the same file is copy/pasted in the shared onedrive folder, it is only warned, but the action has success.Is that a limitation or are there some configuration part which I am missing?the client configuration is steering everything and the exception part is by default. Thanks.Walter
We have been leveraging the inline DLP policies for over a year, and have struggled to “tune” the policies for false positives for PCI, PII, GLBA rules. Curious for feedback from the community no how you tune your rules/classifier etc to weed out false positives.. Our current route/solution we are looking at is excluding “sites” that generate the majority of the false positive hits. Example: Walmart is notorious for flagging carts with Names of brands next to the item number for SSN & US Names..Any and all feedback is welcome - thank you so much in advance!!
Hi I saw this KB Alert/block upon detection of password protected files - Netskope Knowledge PortalHow can we set "user alert" action for coaching? thankMunster
Hi Team,We configured DLP for all categories with PCI and PII DLP. However, on netskopesecuritycheck.com, DLP PCI and PII block tests are failed. Has anyone had success with these tests? Can you please share the DLP policy configuration that has passed? Thanks & Regards,Indu
Wondering if anyone is aware of an existing dashboard to keep an eye on allowed USB file activity. We're looking to see a line-up of the top users uploading content (regardless of it triggering a DLP event) to USB devices. I've tried piecing something together, but the fields don't appear to be available in Advanced Analytics.
Hello,I have a policy setup to block uploads to a specific instance of an application when any DLP profile matches otherwise alert via the traffic direction functionality in the RTP. This has been working fine for a while. Today, I went to add additional instances and when I had the user test, it was still being blocked, completely bypassing that rule and going to my default deny, its not matching DLP because if it was, it would be blocked by the policy I am talking about, its sliding right by my rule... I tried a separate RTP at the top with just the instance configured the same way with no luck. The only way I could get it to work was to remove the DLP profiles.The specific instance I was testing with was a third instance that was sharepoint.Has anyone seen this?Nate
Hello,Does anyone have an example in a Dictionary csv file to add to Netskope with keywords that you want to analyze?Thank you so much.
Netskope has various built-in (aka predefined) DLP identifiers to detect passwords, public keys, private keys and base64 encoded data. While you can write a regex to detect passwords in your environment, I have highlighted some of the challenges here: Regexes can cause DoS and False positives (at a customer site who has a dedicated team to write regex their complain was email in a string being detected as passwords). There is no single password standard that would work for all the environments. The key sizes are varied length. Best approach for a credential detection policy Use Exact Match capability to identify username of AD account exfiltration Use Netskope's built-in identifiers rather than writing complex regex. Use Custom Entity validator to validate your test data with a corresponding Netskope predefined identifier. Note: You do not have to create a custom entity. Just for the validation purpose call a predefined identifier under a custom entity.
Good morningI need to install on my enterprise mobile devices the Netskope client.On these devices the Microsoft Defender client is installed with VPN already active.I noticed from the logs that the netskope client fails to hook the Vpn because it sees the Defender VPN tunnel already activeCan any exceptions be set so that the two tunnels are active?Thanks
Has anyone used the edm automation script that was talked about in conjunction with DLP 2.0? I've seen it referenced but i can't seem to find how to execute it. I have a daily edm file that gets uploaded and i'm looking for the best method to automate the request-ppd upload process.
Hi Friends- can we utilize endpoint dlp in netskope to inspect/allow WIFI printers .
Hi, We have a real time policy to trigger alerts for any DLP violations for Chat & Other IM Categories. We have however not been successful in getting any alerts with DLP profiles on. I would like to know if DLP works on Telegram and Whatsapp for users that's accessing these apps via browser. I have noticed from the CCI that some of the activities are not supported. Happy to hear your thoughts on the same if you had a similar use case. Thanks!
Anyone using the new SMTP DLP functionality? If you are, how are you doing your alerting to users about blocking/intercepting emails?
We are just getting started with the Advanced Analytics and one of the 1st reports we were asked to run is Top Uploads for the past 7 days. Report ran great and is full of useful data. One area I cannot figure out though is Uploads to YouTube.While I do not believe we have "content creators" uploading while at work, the data is still questionable. Searching the web for info all leads back to uploading a video. I did find YouTube does have tracking capabilities beyond cookies. Looking at just one user at our corporate office, showed only around 1Mb of data uploaded. This is more inline with what I found online with the tracking. The top user for the week was around 805Mb. So not “content creator” I would think, but makes me wonder just how much tracking is going on.This top user also had 60 hours of viewing time. (To be addressed separately) But could the tracking account for 805Mb?Anyone else seeing this an
Hello,We’re looking for some information regarding PII regulation profiles equivalent to GDPR but customized for the LATAM requirements or regulations.Do we have predefined profiles for this region?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.