Unique keyword match counting
Keyword based detection is the most simple detection type, but it is quite powerful. However as each match is counted separately, the following can not be done currently, only with EDM, which is not able to block on Endpoint:
We would like to block content which has eg. more than 6 keywords from a list of 200 keywords. Eg. stock names.
Unique keyword match counting could be very useful to overcome this.
Unique match counting works already with Data identifiers, but unfortunetely Data identifiers support only ASCII characters and a limited number of word lists (around 64).
Please consider this simple, but very useful detection enhancement request!