SEU Focus Training
Learning Outcomes: SMB Scan, Access Risk, GQL, SMB Tagging, Data Risk Survey & Reporting
Setup SMB/CIFS Scan
Navigate to Administration > Connections > CIFS
Enter credentials provided
Make sure to name the connection
Select folder path (this also tests connection)
Select save
To start scan select the circular scan icon on your desired connection
Access Risk
Navigate to Dashboard > Explore
Choose Source > IP address
Alternatively, choose Alias and the name you gave your connection
In the Risk drop-down, select High
For each file row, the right-most icon opens the File’s Permissions, select this
This modal window displays users and their permission levels
Data Risk Survey
Navigate Dashboard > Data Risk Survey
Here is where information is gathered about the organisation that then feeds into the Data Risk reports
The first 25 questions are compulsory to generate these reports
The questions should be answerable by CIO/CISOs, Heads of Engineering, etc…
Once complete, navigate to Reports
Data Risk reports are performed on individual shares, this allows us to identify remediation options more effectively
Select the desired share (SEU01) and Generate Report
Other Reporting
From Dashboard > Reports
Select Generate on any of the reports
Each has actionable insights
All reports except the Risk Report cover all files or users in the database
GQL
On the Explore page, select Switch to advanced search
Select the text box to begin querying
Using the suggestions or typing directly add
fileType=doc AND classification=Confidential AND category=Technical_Documents AND categoryConfidence>=0.7 AND risk=2
Go through different permutations here using
!=
,OR
,<=
,()
, etc…Search for specific data types that would interest particular customers
An interesting use case to search for, are image files that have been classified with OCR
(fileType=jpg OR fileType=png) AND flow=CLASSIFICATION
SMB/CIFS Tagging Global
Navigate to Administration > Connections > CIFS > Tagging rules
Here, enter a GQL filter, at first we can use
flow=CLASSIFICATION
Back on the Connections tab, choose the desired share and select the tagging icon on the right
Once the job kicks off, started checking metadata on the documents in the share
SMB/CIFS Tagging Targeted
Unzip and copy the original folder, rename SEU02
Create new CIFS scan
Create a filter to only tag
docx
files in this folder
Related content
Classified as Getvisibility - Partner/Customer Confidential