Microsoft Purview – Evading Data Loss Prevention policies
ID: aa969072-255a-5a67-a7a7-937c7e1ca164
STIX ID: report--aa969072-255a-5a67-a7a7-937c7e1ca164
Feed Name: NVISO Labs
This report demonstrates a data exfiltration technique that bypasses Microsoft Purview DLP by removing sensitivity label metadata: labeled DOCX files are exported to PDF and stripped of labels using ExifTool, allowing successful email and cloud uploads previously blocked by DLP. It outlines detection via Microsoft Defender for Endpoint device timeline (e.g., ExifTool usage and rapid file renames) and prescribes mitigations: auto-classification with SITs/Trainable Classifiers, enforcing encryption on sensitive labels, adding DLP rules for unlabeled and classifier-matched content, and leveraging Insider Risk Management for sequence-based user risk and alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
