What is a one sentence summary of your feature request?
Don’t log files shown in a file picker dialogue as having been uploaded
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
When trying to upload a file (or multiple) to a website, and you open the dialogue window to pick files for the upload (e.g., by clicking a button like “Select file”), the files shown in this dialogue will be seen as having been uploaded.
I’ve had this happen for a bunch of files I had in a folder, where all the files contained content monitored by a CAP policy via a Custom Content denylist.
Simply by opening this file picker dialogue, EPP saw the files and viewed them as having been uploaded even if I simply abort the upload without uploading any files.
Instead of viewing files as having been uploaded when they, in reality, haven’t been, logging a file as having been “uploaded” should instead be done only after said files have actually been uploaded.
How do you currently solve the challenges you have by not having this feature?
Currently, according to Netwrix, this is known behavior and cannot presently be mitigated.
The only real way to mitigate the mass-logging of files (both ones that got uploaded and ones that didn’t) is to drag-and-drop in the files that should be uploaded, instead of ever opening the file picker dialogue.
While this does solve the issue, the fact that users are unlikely to always drag-and-drop files for uploads means excess logging can’t be avoided.
Moreover, files that were uploaded through the file picker dialogue and files that were simply seen by EPP cannot be distinguished from one another.
Because of this, if a malicious user were to upload sensitive files via the file picker dialogue to, e.g., an unauthorized website, any unrelated files simply seen by this dialogue window would be logged just the same as the file/files actually uploaded by the user.
This makes it difficult to prove that the user uploaded sensitive files, not to mention proving which files were uploaded.

