Forum Discussion

AlexRF's avatar
AlexRF
Copper Contributor
Nov 08, 2024

Exclude File Hash's from Data leak/Insider policy

Absolute long shot, but is there any way to exclude file Hashes from the attachments part of a data leak policy, we use a service for our signatures and due to the way it works the images in it keep getting picked up as part of sending external with attachment, the image name changes, but the SHA-256 stays the same.

 

Anyone have any idea if this is or ever will be possible?

2 Replies

  • Hello Alex!

    Did you ever figure out a solution for this. If not, the answer is likely a No-Purview does not support this for attachments. Hashes may appear in Endpoint DLP telemetry but I doubt you can use them as a DLP rule condition or exception.

Resources