Proofpoint | ObserveIT On-Premises Insider Threat Management

Brought in a File - Did What

This topic describes how to define alert rule conditions using the options available in the Brought in a File group category in the Did what? section of the Create Alert Rule page. (For more about the Did what? section, see Defining the "Did What?" Conditions.)

This option is available for alert type rules on Windows and Mac-based operating systems.

The Brought in a File option enables you to define an alert rule that will generate an alert for the following entry points:

  • a file is downloaded from a website/web application
  • a file it taken form cloud storage sync folder or
  • an attachment is saved from an email client
  • By downloading from a website or Web application: An alert is triggered when a file is downloaded from any website or web-application, including webmail, social media sites and file sharing sites.

  • You can specify the website or web application by:

    • All or part of a name of a specific website
    • All or part of a website URL
    • All or part of a window title
    • Website category from the Website Categorization
  • You can specify which file by:

    • Original file name
  • You can specify the MIP label of the file:

    • Original file label
  • By saving an attachment from an email client: An alert is triggered when an attachment from an email client is saved

    You can specify the file you want by:

    • Original filename
    • File size

    You can specify the destination by:

    • Destination path
    • If the destination is a USB
    • If the destination is a sync folder

    You can specify MIP label of the file by:

    • Original file label
  • By taking a file from cloud storage sync folder: An alert is triggered when a tracked file is moved or copied from a local cloud storage sync folder, such as Box.

    In version 7.10, this option is available for Microsoft Box only.

    You can specify the file by:

    • Original file name

    You can specify the cloud storage sync folder by:

    • Vendor name

    You can specify MIP label of the file by:

    • Original file label

Examples of Creating a Rule for Brought in a File

version 7.12.2