search cancel

Data Copied from Local Disk to Microsoft Virtual Hard Disk (VHD) Generates Removable Storage Incidents

book

Article ID: 162799

calendar_today

Updated On:

Products

Data Loss Prevention Endpoint Prevent

Issue/Introduction

Microsoft Virtual Hard Disks (VHD) on a DLP Endpoint Agent machine used to store sensitive, proprietary, data needed for daily business operations.

Cause

The system storage host controllers and adapters for VHD use a storage bus type similar to a Removable Storage device.

Resolution

To ignore the VHD monitoring from the Removable Storage channel monitoring, you can do this by modifying the Advanced Agent Setting as follows:

FileSystem.IGNORE_STORAGE_BUS_TYPE.str = BusTypeFileBackedVirtual

This should only ignore VHD, all other Removable Storage devices will be monitored as usual. The default value is ‘None’. Setting the value to ‘ALL’ will ignore all non USB disks.

The supported bus type values for Filesystem.ignore_storage_bus_type are:
                
ALL
NONE
BusTypeUnknown
BusTypeScsi
BusTypeAtapi
BusTypeAta
BusType1394
BusTypeSsa                                                                                        
BusTypeFibre
BusTypeUsb
BusTypeRAID
BusTypeiScsi
BusTypeSas
BusTypeSata
BusTypeSd
BusTypeMmc
BusTypeVirtual
BusTypeFileBackedVirtual