Data Loss Prevention

 View Only
  • 1.  NTLM://Domain Name/UserID (Attribute Lookup for AD)

    Posted Jul 23, 2012 03:27 AM

    Hi All,

    One of my client has deployed McAfee Web Gateway as a proxy and are attempting to integrate Symantec DLP with it (Network for Web). The incidents however receive the user information as Sender:-  NTLM://Domain Name/UserID. I know we can perform string operations in python or perl scripting and pass the user ID to AD for attributes lookup so that it can populate the manager's details, however, I dont have any expertise on this programming language I appricate if someone can help me out.



  • 2.  RE: NTLM://Domain Name/UserID (Attribute Lookup for AD)

    Posted Jul 25, 2012 12:11 PM

    Look into this thread:

     

    https://www-secure.symantec.com/connect/forums/liveldaplookup-using-substrings

     

    Bob_B has some nifty LDAP lookup scripts, and the string manipulation needed to accomplish what you are looking for using these scripts is easily accomplished even if you don't know vbscript.

     

    Jeremy



  • 3.  RE: NTLM://Domain Name/UserID (Attribute Lookup for AD)

    Posted Jul 25, 2012 11:46 PM

    like jsneed said it is a great tool, it is fairly easy to setup and has unlimited potential.