Skip to content
Back to skills

Digital Guardian

ASecurity

Expert agent for Digital Guardian (Fortra) DLP. Covers kernel-level endpoint agent, data visibility, classification (manual and automatic), policy configuration, Analytics and Reporting Cloud (ARC), network DLP, and integration with third-party classification tools. WHEN: \"Digital Guardian\", \"Fortra DLP\", \"DG agent\", \"ARC\", \"Analytics Reporting Cloud\", \"kernel-level DLP\", \"digital guardian endpoint\".

  • 4 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 24, 2026
devopsrustgosqlazuregitapibackendsecurity

Works with

  • cli
  • api

Security analysis

A100/100

Scanned September 24, 2026

npx -y skills add chrishuffman5/domain-expert --skill digital-guardian --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Digital Guardian?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Digital Guardian
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-digital-guardian/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-digital-guardian)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: digital-guardian
description: "Expert agent for Digital Guardian (Fortra) DLP. Covers kernel-level endpoint agent, data visibility, classification (manual and automatic), policy configuration, Analytics and Reporting Cloud (ARC), network DLP, and integration with third-party classification tools. WHEN: \"Digital Guardian\", \"Fortra DLP\", \"DG agent\", \"ARC\", \"Analytics Reporting Cloud\", \"kernel-level DLP\", \"digital guardian endpoint\"."
license: MIT
---

# Digital Guardian (Fortra) DLP

This skill covers Digital Guardian Data Loss Prevention, including the kernel-level endpoint agent, cloud-managed platform, data classification, policy enforcement, and Analytics & Reporting Cloud (ARC).

## How to Approach Tasks

1. **Identify the deployment** — Digital Guardian SaaS (cloud-managed) vs. on-premises management server
2. **Identify the component** — Endpoint agent, network DLP appliance, or ARC
3. **Classify the request:**
   - **Agent/endpoint** — Apply kernel-level agent guidance
   - **Policy configuration** — Apply DG policy and rule guidance
   - **Classification** — Manual, automatic classification, or third-party integration
   - **Investigation/analytics** — Apply ARC dashboard and query guidance
   - **Network DLP** — Apply network appliance guidance

## Platform Architecture

### Core Components

```
Digital Guardian Management Console (cloud-hosted via SaaS)
├── Policy management — define policies, rules, and responses
├── Agent management — deploy, configure, and update agents
├── Alert management — view and triage security events
└── Integration hub — SIEM, SOAR, classification tool connectors

Digital Guardian Endpoint Agent
├── Kernel-mode driver — intercepts all I/O operations at OS level
├── User-mode service — policy evaluation, user notification
├── Classification engine — auto-classify data at creation/access
└── Event telemetry — streams events to cloud management console

Analytics & Reporting Cloud (ARC)
├── Big-data analytics backend (cloud-hosted)
├── Pre-built dashboards for DLP, threat, and compliance
├── Custom query builder (SQL-like query language)
├── Alert and watchlist management
└── Forensic investigation tools

Network DLP Appliance (optional)
├── Passive monitoring (SPAN/TAP) — network-based visibility
├── MTA integration — email DLP
└── ICAP integration — web proxy DLP
```

### Kernel-Level Agent: What Makes It Different

Digital Guardian's kernel-level approach provides visibility into every data operation:

```
Every data operation captured:
  File read → File write → File copy → File rename → File delete
  Process create → Process terminate
  Network connection create → data sent → connection close
  Clipboard read → Clipboard write
  Print job create → Print job data → Print complete
  Removable media attach → File copy to media → Media detach
  Registry read/write (for sensitive key data)
  Screenshot capture attempt

Result: Complete data lineage from creation to destination
  → "This credit card number originated in file X, was read by process Y,
     copied to clipboard, and pasted into browser uploading to domain Z"
```

**Agent deployment:**
```
Windows:
  → MSI deployed via SCCM, Intune, or Group Policy
  → Supported: Windows 10, 11, Windows Server 2016+
  → Agent operates at NTFS filter driver level (kernel mode)
  → Minimal CPU overhead: ~1-3% average; higher during file copy operations

macOS:
  → PKG deployed via JAMF or other MDM
  → Supported: macOS 11 (Big Sur)+
  → System Extension model (replaced kernel extension)
  → Full Disk Access required
```

## Data Classification

### Classification Model

Digital Guardian supports a flexible classification scheme:

```
Classification levels (customizable — typical enterprise model):
  Level 1: Public
  Level 2: Internal
  Level 3: Confidential
  Level 4: Restricted

Classification methods:
  1. Manual — user selects classification via right-click or agent prompt
  2. Automatic — agent classifies based on content analysis rules
  3. Policy-driven — classify based on file type, location, or application
  4. Inherited — new files inherit classification of source (copy, save-as)
  5. Third-party — import classifications from Titus, Boldon James, or MIP labels
```

### Automatic Classification Rules

```
Rule types:
  Content-based:
    → Keyword match: classify as Restricted if document contains "TOP SECRET"
    → Regex match: classify as Restricted if SSN pattern detected
    → Data type: classify as Restricted if credit card number detected

  Location-based:
    → Files in \\server\HR\Salaries\ → auto-classify as Restricted
    → Files created by HR applications → auto-classify as Confidential

  Application-based:
    → Files created by SAP → classify as Confidential
    → Files created by EHR application → classify as Restricted

  File type-based:
    → All .dwg (CAD files) → classify as Confidential (engineering IP)
    → All .pfx (certificate files) → classify as Restricted
```

### Third-Party Classification Integration

**Microsoft Purview / MIP Labels:**
- DG can read MIP sensitivity labels applied to documents
- Labels mapped to DG classification levels
- MIP: Highly Confidential → DG: Restricted
- Enables: organizations using Purview for labeling can enforce at DG kernel level

**Titus / Boldon James:**
- DG reads metadata tags applied by Titus or Boldon James plugins
- Classification metadata stored in document properties
- DG enforces policies based on inherited classification values
- Bidirectional sync available (DG classification → Titus metadata update)

## Policy Configuration

### Policy Structure

```
Policy → Rules → Response Actions

Policy: Restricted Data Protection
  Priority: 1 (evaluated first)
  Scope: All users (or specific AD groups)

  Rule: USB Copy of Restricted Data
    IF:
      operation = "copy_to_removable_media"
      AND classification = "Restricted"
    THEN:
      → Block operation
      → Notify user: "Copying Restricted data to USB is not permitted."
      → Create alert: Severity = High
      → Log: Full operation details + file snippet

  Rule: Unclassified File to USB
    IF:
      operation = "copy_to_removable_media"
      AND classification IS NULL (not classified)
      AND content_matches: [Credit Card, SSN regex]
    THEN:
      → Prompt user to classify document
      → If user classifies as Restricted → Block
      → If user classifies as lower → Allow + log
      → If user dismisses prompt → Block (safe default)

  Rule: Email Attachment of Restricted Data
    IF:
      operation = "email_attachment"
      AND classification = "Restricted"
      AND recipient.domain NOT IN [approved_partners.txt]
    THEN:
      → Block + notify user
      → Create alert: Severity = Critical
      → Notify: security_team@company.com
```

### Operation Types

```
File Operations:
  copy_to_removable_media     copy_from_removable_media
  copy_to_network_share       copy_from_network_share
  file_create                 file_delete
  file_rename                 file_move
  file_modify                 file_open
  print                       print_to_file

Clipboard Operations:
  clipboard_copy              clipboard_paste
  clipboard_copy_from_app     clipboard_paste_to_app

Network Operations:
  http_post (upload)          ftp_put
  email_send                  email_attachment
  cloud_sync_upload

Screen Operations:
  screenshot                  screen_recording
```

### Response Actions

| Action | Description |
|---|---|
| Allow | Permit the operation; log the event |
| Monitor | Allow with elevated logging detail |
| Prompt | Show user a message; allow them to proceed or cancel |
| Justify | Require user to enter a justification text before allowing |
| Block | Prevent the operation; show user message |
| Quarantine | Allow operation but move copy to quarantine location |
| Encrypt | Allow operation but encrypt the file (requires DRM integration) |
| Notify | Send alert email to configured recipients |
| Alert | Create alert in management console / ARC |

### Trusted Applications

Define applications that are trusted to handle sensitive data:

```
Example trusted applications:
  → C:\Program Files\SAP\... (SAP ERP — trusted to read Confidential data)
  → C:\Program Files\Microsoft Office\... (Office apps — trusted for document editing)
  → C:\EncryptionTool\... (approved encryption utility — trusted to copy Restricted data)

Untrusted application examples:
  → Personal cloud sync clients (Dropbox, personal OneDrive)
  → Personal browsers accessing webmail
  → Screenshot utilities not on approved list
```

Trusted application rules allow bypassing certain DLP policies while still logging activity.

## Analytics & Reporting Cloud (ARC)

### Dashboard Types

**DLP Overview Dashboard:**
- Policy violation counts by severity and time
- Top violating users
- Top triggered policies
- Violation trend (increasing/decreasing)
- Channel breakdown (endpoint, network, cloud)

**Threat Dashboard:**
- High-risk user activity (classify + exfiltrate patterns)
- Anomalous data access (user accessing unusual data types)
- Bulk data movement (large file operations outside normal pattern)

**Compliance Dashboard:**
- Compliance violation counts by regulation type
- PCI, HIPAA, GDPR breakdown
- Evidence export for audit purposes

### ARC Query Language

ARC supports a SQL-like query language for custom investigation:

```sql
-- Find all Restricted data moved to USB in past 7 days
SELECT
    event_time,
    user_name,
    machine_name,
    file_name,
    file_size,
    destination,
    classification
FROM dlp_events
WHERE
    event_type = 'copy_to_removable_media'
    AND classification = 'Restricted'
    AND event_time >= NOW() - INTERVAL '7 days'
ORDER BY event_time DESC;

-- Users with most blocked operations (potential insider risk)
SELECT
    user_name,
    COUNT(*) as blocked_count,
    COUNT(DISTINCT policy_name) as distinct_policies
FROM dlp_events
WHERE
    response_action = 'Block'
    AND event_time >= NOW() - INTERVAL '30 days'
GROUP BY user_name
HAVING COUNT(*) > 10
ORDER BY blocked_count DESC;

-- Data flow: where is Restricted data going?
SELECT
    destination_type,
    destination_detail,
    COUNT(*) as event_count,
    SUM(file_size) as total_bytes
FROM dlp_events
WHERE
    classification = 'Restricted'
    AND event_time >= NOW() - INTERVAL '30 days'
GROUP BY destination_type, destination_detail
ORDER BY event_count DESC;
```

### Alert Configuration

```
Alert types:
  Threshold alert: Fire when event count exceeds threshold in time window
    → Example: User copies 5+ Restricted files to USB in 1 hour
  
  Pattern alert: Fire on specific operation sequence
    → Example: User accesses HR files AND copies to removable media
  
  Watchlist alert: Monitor specific users, files, or destinations
    → Example: Alert on ANY operation by users on HR-watchlist

Alert routing:
  → Email: DLP team distribution list
  → SIEM: Syslog CEF format
  → SOAR: Webhook to Splunk SOAR / Palo Alto XSOAR
  → ServiceNow: REST API incident creation
```

## Network DLP Component

**Deployment:**
- Hardware appliance or virtual machine
- Passive monitoring: SPAN/TAP port on core switch
- Email inline: SMTP proxy between internal relay and internet gateway
- Web inline: ICAP integration with Zscaler, Blue Coat, or Squid proxy

**Network DLP capabilities:**
- SMTP email inspection (outbound email bodies and attachments)
- HTTP/HTTPS upload inspection (via proxy ICAP)
- FTP transfer inspection
- Detection: same classification engine as endpoint (keywords, regex, ML)
- Network events correlated with endpoint events in ARC

## SIEM and SOAR Integration

**Splunk:**
```
Integration: Syslog CEF → Splunk Universal Forwarder or HEC
Data source: DG management console → Syslog output → Splunk
App: Digital Guardian App for Splunk (available on Splunkbase)
Use cases: Cross-correlate DLP events with authentication, EDR events
```

**Microsoft Sentinel:**
```
Integration: Syslog CEF → Azure Monitor Agent → Sentinel
Custom parser: Parse DG CEF fields to Sentinel schema
Workbooks: Build DLP investigation workbooks
Analytics rules: Alert on high-risk DLP patterns
```

**ServiceNow:**
```
Integration: DG REST API → ServiceNow REST inbound
Workflow: High-severity DLP alert → auto-create ServiceNow incident
Assignment: Route to security operations queue
Enrichment: Pull user/device context from DG into incident
```

## Common Issues and Troubleshooting

**Agent high CPU usage:**
- Likely caused by large file operations (backup jobs, large data copies)
- Configure exclusion paths for backup agent directories
- Set file size limit for content inspection (skip files > 500MB)
- Review ARC for which operations are consuming the most agent resources

**Classification not persisting on file save:**
- Check if application is in the "trusted applications" list — some apps strip metadata
- Verify file format supports embedded metadata (Office formats support it; .txt does not)
- Consider location-based classification as fallback (classify by directory rather than file metadata)

**Policies not enforcing on remote workers:**
- Verify agent internet connectivity to cloud management console (port 443)
- Check policy cache — agent should maintain local policy cache for offline enforcement
- Review certificate trust — corporate certificate required for cloud console

**ARC not showing recent events:**
- Check agent telemetry pipeline: agent → cloud connector → ARC
- Verify agent service is running and cloud endpoint is reachable
- ARC event latency: typically 5-15 minutes; up to 60 minutes under high load
- Check ARC ingestion health dashboard for pipeline errors

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…