Which aspect of EPP are you submitting for?
Endpoint Protector Server
What is a one sentence summary of your feature request?
Reduce false-positive DLP alerts caused by local file access in Midnight Commander/Total Commander when no actual data transfer occurs.
Please describe your idea in detail. What is your problem, why do you feel this idea is the best solution, etc.
We would like Endpoint Protector to distinguish between local file access and actual data transfer when monitoring applications such as Midnight Commander.
Currently, normal local operations in Midnight Commander, such as browsing folders, searching for files, reading file contents, or accessing file metadata, can trigger DLP data exfiltration events even though no file is transferred outside the endpoint.
This creates a significant volume of false-positive alerts for the customer’s SOC team. In environments where Midnight Commander is widely used, routine file browsing or recursive searches may generate many events that require investigation despite there being no actual exfiltration.
We would like to have a configurable way to suppress or exclude local-only file read and metadata access operations while keeping monitoring enabled for real transfers to configured exit points.
Ideally, DLP events should be generated when data is actually transferred to an exit point, or administrators should have an option to differentiate local file access from file transfer activity.
This would significantly reduce alert noise and improve the signal-to-noise ratio for SOC teams without reducing visibility into legitimate data exfiltration attempts.
Also we previously opened a Support Portal ticket regarding this issue: #00485303 – EPP False Positive Alerts Triggered by File Managers.
How do you currently solve the challenges you have by not having this feature?
Currently, there is no effective technical workaround that allows us to suppress these local Midnight Commander events while keeping the required DLP monitoring enabled.
The customer’s SOC team has to manually review and filter these events to determine whether an actual data transfer occurred. Since a large number of these events are generated by normal local file browsing and search activity, this creates additional workload and alert fatigue.
Disabling the relevant monitoring is not a suitable workaround because it could also reduce visibility into legitimate data transfer or exfiltration activity.