Tuesday, December 27, 2016

Filtering Tricks - Notes on a Folder



One of the very handy features of Varonis DatAdvantage is the ability to add Notes to folders and other objects in the Work Area.  An example of where we use Notes on a regular basis is at the start of a remediation project.  We will have a standard security structure that we are going to apply to the folders that we care about.  For example, we will make sure that there is a group with Modify privileges, a group with Read Only privileges, and an Administrative group.  If there are problems with making that change immediately (let’s say that are number of direct user permissions or a number of groups with List permissions) the analyst can Add a Note to the folder and we can come back to it later to discuss with data owner and server teams.

This allows the analyst to maintain his focus on reviewing the server security and make sure that we have a comprehensive issues list that can be reviewed with other members of the organization.

One thing we would like to do is to be able to produce a list of all of folders that have Notes on them.  We are typically going to use the 4f – File System Objects List as are starting point.  However with the Notes on access path filter there is no ability to do a binary selection on whether a folder has a Note or not.  So what we do is create a selection that looks for vowels.



This way, if you utilize words in all of your notes then this will produce just folders that have notes.  We typically create this once, save as a filter and then whenever you need this functionality, just import the filter when you start building the report.

Happy filtering!

Saturday, May 7, 2016

Vera - New Data Protection Solution

Saw a demo of a very interesting product from Vera yesterday.  They have a solution that protects a document (and other files) throughout the entire lifecycle of the data.   The protection and encryption stays with the document, yet users are still able to use native applications to work with the file; as long as they are authorized.  We are going to start a trial of the solution next week and I will keep you posted on our thoughts.

Sunday, January 3, 2016

Running into Mr. Robot

Ran into Mr. Robot in the middle of Manhattan on December 18th.  Christian Slater was very nice.  He indicated that they have yet to start shooting season two.  Loved Season 1 and am anxiously awaiting what dark twists this show will take.


Monday, December 21, 2015

Can Varonis Capture "Copy" Events?



I get asked regularly if Varonis DatAdvantage can identify when a user copies a file?  

It depends. 

  • If the user opens a file on a server and copies it to his desktop, Varonis DOES NOT record the copy to the desktop, only that the file on the server was opened.  
  • If the user copies a file from one folder to another on the same server, we will see a rename event.
  • If the user copies a file from one server to another server, you will see a File Open on the first server and a File Create on the second server.

Based on how must people ask the question, the answer is no.  To really know what the user did with the file you need a Data Loss Prevention solution like Digital Guardian (our choice) or Symantec DLP.