Detecting Copy to USB

This use case detects any copy activity to USB.

Set up the Exploration to detect Web File Upload activity.

  1. Open a new Exploration. From the Proofpoint Information and Cloud Security Platform, select the Analytics app.

  2. From the left side-menu, select ActivityExplorations. Click New Exploration button.

  3. Your new exploration opens and you see the source node with the default region, time and source. By default, a new Exploration shows all events captured for the past 24 hours, without any filtering applied.

  4. Hover over this first filter and click the pencil button to edit the filter.

    A pane on the right opens.

  5. In the Filter byTime area, in Over the last, select 7d. All the data over the past 7 days will display. Click Done.

  6. Now, explore Web file upload activity. Click + (add filter button) to add a new filter. A pane opens on the right.

  7. Select Primary CategoryCopy to USB.

    Type Primary Category in Search Fields to locate this field.

    If Copy to USB is not available, then uploads have been captured by the Proofpoint ITM Agent in your environment. Wait for more data to be collected by the Agent or generate some events on your own.

  8. Take a look at the activities. In the Activity Summary pane click Edit Columns

  9. Scroll to DevicesUSB Product Name. Click Done.

    Activity Summary now shows all users who copied files to USB devices next to the names of these devices. This is a quick way to identify whether a user uses an unapproved USB device.

  10. Click the Tree tab in the Activity Summary pane. You can now expand each username individually to easily view all devices for each user.

  11. Click a device for a user. Activity view now shows only USB copies for this specific user and device.


ITM / DLP Explorations and Common Use Cases

ITM / Endpoint DLP Use Cases