Skip to main content

endpoint-sensor-coverage

Explore Articles

Endpoint Sensor Coverage

Cyberhaven Endpoint Sensor can trace and block specific user actions. The following table provides the Endpoint Sensor coverage to trace and block various user actions.

CategoryUser ActionWindowsmacOSLinux
TracingBlockingTracingBlockingTracingBlocking
File Operations
Accessing files in generic appsCreating a file within any appYesNoYesNoYesYes
Creating a file within Google Workspace on supported browsersYesNoYesNoYesNo
Opening existing files within any appYesYesYesYesYesYes
Accessing files in supported appsSaving files in Microsoft OfficeYesYesNoNoNoNo
Saving and exporting files in Microsoft OfficeYes1Yes1NoNoNoNo
Embedding Microsoft Office files in other documents (for example, .xslx in .pptx)Yes1Yes1NoNoNoNo
Sending emails in Microsoft OutlookYes5YesNoNoNoNo
Forwarding emails with attachments in Microsoft OutlookYes5NoNoNoNoNo
Sending emails in New Microsoft Outlook (September 2023)Yes8YesYes8YesNoNo
ArchivingArchiving with Explorer or FinderYesYesYesYesNoNo
Archiving with 7zipYesYesYes1Yes1NoNo
Copying or moving files on the endpoint device and generic appsUsing Explorer or FinderYesYesYesYesYesYes
Using cmd.exe or PowerShell commandsYesYesN/AN/ANoNo
Using command line appsYes1YesYes1Yes1YesYes
Using any other appsYes1Yes1Yes1Yes1YesYes
Moving files to Recycle Bin or TrashYesYesYesYesYesNo
Uploading or downloading from the webUploading to supported browsersYesYesYesYesYesYes
Downloading from supported browsersYesYesYesYesYesYes
Inspecting Content and Tags in uploaded or downloaded filesYes2NoYes2NoYes10Yes10
Folder Operations
Copying or moving foldersMoving folders from one local drive to a different local drive, for example, from C:\ to D:\YesYesYesNo9NoNo
Moving folders from local drive to USB and backYesYesYesNo9NoNo
Moving folders from local drive to network share and backYesYesYesNo9NoNo
Moving folders from local drive to cloud sync drive such as Google Drive and backYesYesYesNo9NoNo
Moving folders from one USB to another USBYesYesYesNo9NoNo
Moving folders from one network share to another network shareYesYesYesNo9NoNo
Moving folders within the same local drive, for example, from C:\* to C:\*YesNo7YesNo9NoNo
Moving folders within the same USBYesNo7YesNo9NoNo
Moving folders within the same network shareYesNo7YesNo7NoNo
Moving folders from a local drive C:\* to cloud sync folders on the same drive, for example, C:\users\*\OneDriveYesNo7YesNo9NoNo
Moving folders from a local drive C:\*to cloud sync backup locations such as Documents, Desktop, etc.YesNo7YesNo9NoNo
Copy and Paste Operations
Copying and PastingCopying using keyboard shortcuts (Ctrl+C)YesNoYesNoNoNo
Pasting using keyboard shortcuts (Ctrl+V)YesNoYesNoNoNo
Copying using menusYesNoYesNoNoNo
Pasting using menusYes6NoYesNoNoNo
Copying and pasting to appsCopying and pasting to OutlookYesNoNoNoNoNo
Copying and pasting to web apps on supported browsersYesYesYes12Yes12NoNo
Copying and pasting to all appsYesNoYes11NoNoNo
Print Operations
PrintingPrinting to a physical printer on the network, or attached locallyYes3Yes3Yes4Yes4NoNo
File transfer using an external medium
Transferring files to removable mediaUsing Explorer or FinderYesYesYesYesYesYes
Using other appsYesYesYesYesNoNo
Transferring files to Windows network driveUsing Explorer or FinderYesYesYesNoNoNo
Using other appsYesYesYesNoNoNo
Transferring files to portable devices using media (MTP) and picture file transfer (PTP) protocolsUsing Explorer or FinderYesNoNoNoNoNo
Using other appsNoNoNoNoNoNo
Transferring files using FTPUsing Explorer or FinderYesYesYesYesNoNo
Using other FTP clientsYes1Yes1Yes1Yes1NoNo
Transferring files using BluetoothUsing Explorer or FinderYesYesYesYesNoNo
  1. User action is recorded but not linked to the original document.
  2. Content is only inspected when the policy action is set to Warn, and not Block. In cases where an upload or download action is blocked, inspection is based on previously scanned content or tags.
  3. Limited to Microsoft Word, Microsoft Excel, and supported browsers. Learn about supported browsers: supported browsers.
  4. The macOS Endpoint Sensor records print operations as a file open event against the printer process.
  5. Tracing is limited to email attachments.
  6. Review the full list of supported paste actions.
  7. The following are the reasons why blocking is not supported in some cases when moving folders.
    • When folders are moved within the same drive, USB, or network share, there is no risk of data leaks, except in the case of cloud sync folders.
    • Moving folders within the same location is very fast (usually less than 1 second) and adding file checks could slow down the process significantly.
  8. Tracing support for New Microsoft Outlook is limited to email attachments within domain accounts. For example, if the Cyberhaven add-in for the new Microsoft Outlook is deployed on a Microsoft account on cyberhaven.com domain, then only activities within that domain are tracked, regardless of any other configured accounts.
  9. Blocking move folder operations on macOS is currently disabled starting with version 24.09 due to potential performance impact. This feature can be re-enabled through a configuration change. If you would like to enable this feature, contact Cyberhaven Support.
  10. On Linux, tracing and blocking are supported through content inspection, but this functionality does not extend to Tags.
  11. macOS tracing of copy and paste action from any app has the following limitations,
    • When sensitive content is pasted into a new or existing file that has not yet been saved, the copy/paste action is traced and recorded. However, content inspection will not include the pasted sensitive data until the file is saved. This is because content inspection is performed on the file on disk, not in memory.
    • Events generated from copy/paste actions traced for new, unsaved files will not contain file name or path information. Once the file is saved, actions performed on it are treated as separate events, and the data lineage is not linked to the initial copy/paste action.
    • Some applications may force-disable the ability to track copy and paste actions, preventing the sensor from tracing these actions.
    • Tracing in non-browser applications is reliably supported only for applications using the English language.
  12. Event tracing is not supported between Incognito and non-Incognito windows of the same browser session. However, tracing functions correctly between Incognito windows within the same session and between Incognito windows and other processes, even those in separate browser sessions.

NOTE

The Endpoint Sensor can only record upload events as app access (open) events for unsupported browsers. As a result, the sensor captures the destination application, causing the events to display the destination files as .exe files.

Change Log

  • Updated on 03/24/2025: Added a footnote to macOS copy-pasting to browser.
  • Updated on 03/14/2025: Added macOS tracing support for copy-paste to all apps.
  • Updated on 02/20/2025: Removed the following from “Accessing files in generic apps”.
    • Editing and saving a file in apps
    • Performing "Save As" or "Export" operations in apps
  • Updated on 01/22/2025: Added Linux blocking coverage.
  • Updated on 01/14/2025: Added condition no. 9 to the coverage table and updated macOS blocking coverage for folder operations.