DLP and print screen
I've been pondering this a while now and really can't come to any other conclusion than this.
It's rather easy to get around some of DLP's functionality using print screen. Using print screen doesn't trigger a clipboard event. There are two ways to get around this:
- Have the sys admin write a script to disable the print screen key on all clients (extreme)
- Have the print screen key generate an event like this:
- The user hits print screen
- DLP agent immediately scans all visible text
- If any visible text is discovered, generate an event
I'm guessing that it would have to be separate from the clipboard event in the "Protocol or Endpoint Destination" section though.