Skip to main content
Solved

Block Zip File Contains Executable

  • March 5, 2024
  • 5 replies
  • 868 views

munster

Hi

How to block download/upload binary files in zip?

How many layer of zip the engine will unzip for scanning?

thank

Best answer by ejang

You need to use DLP profile, not activity constraint.

  1. create a file profile including binary file types
    https://docs.netskope.com/en/netskope-help/data-security/real-time-protection/profiles/adding-a-file-profile/
  2. create a dlp profile and select the file profile
    https://docs.netskope.com/en/netskope-help/data-security/data-loss-prevention/dlp-profiles/create-a-custom-dlp-profile/
  3. Use the dlp profile in RTP policy.
This topic has been closed for replies.

5 replies

ejang
Netskope Employee
Forum|alt.badge.img+5
  • Netskope Employee
  • 69 replies
  • March 5, 2024

What feature are you referring to? DLP or TP?


munster
  • Author
  • 26 replies
  • March 6, 2024

Hi Ejang

 

TP and SWG.  For SWG, I will want to block any binary files in compression format such as zip, arj, etc.

thank


ejang
Netskope Employee
Forum|alt.badge.img+5
  • Netskope Employee
  • 69 replies
  • March 6, 2024

First, you need to create a file profile that includes all binary files. Then, create a DLP profile with the file profile. Finally, create a RTP policy with the DLP profile. Please see the sample below.

 


munster
  • Author
  • 26 replies
  • March 7, 2024

Hi Ejang

I am using true filetype for blocking.  Binary in zip didnt hit this RTP.  Is this rule correct?

 


ejang
Netskope Employee
Forum|alt.badge.img+5
  • Netskope Employee
  • 69 replies
  • Answer
  • March 7, 2024

You need to use DLP profile, not activity constraint.

  1. create a file profile including binary file types
    https://docs.netskope.com/en/netskope-help/data-security/real-time-protection/profiles/adding-a-file-profile/
  2. create a dlp profile and select the file profile
    https://docs.netskope.com/en/netskope-help/data-security/data-loss-prevention/dlp-profiles/create-a-custom-dlp-profile/
  3. Use the dlp profile in RTP policy.