Detection with the Passwords policy template fails on endpoints in DLP 16.0 MP1
22192
25 May 2023
18 May 2023
The regular expression used in the Passwords policy template results in detection failures on endpoints due to limitations of the Lookahead and Lookbehind assertions. The Passwords policy template was introduced in Symantec Data Loss Prevention 16.0 MP1.
Resolve this issue by modifying the regular expression to remove the second, third, and fourth characters. You can copy the updated regular expression shown below.
(\s|^)(?=\S{0,15}[a-z])(?=\S{0,15}[A-Z])(?=\S{0,15}\d)(?=\S{0,15}[-!@#$&*])(?i)(?!([\d.-]{0,13}(jan|feb|mar|apr|may|jun|jul|aug|sep|oct|nov|dec)))(?![\d.,-]{1,15}\p{Sc}|\p{Sc}[\d.,-]{1,15})(?![\d.,-]{0,13}(AED|AFN|ALL|AMD|ANG|AOA|ARS|AUD|AWG|AZN|BAM|BBD|BDT|BGN|BHD|BIF|BMD|BND|BOB|BOV|BRL|BSD|BTN|BWP|BYN|BZD|CAD|CDF|CHE|CHF|CHW|CLF|CLP|CNY|COP|COU|CRC|CUC|CUP|CVE|CZK|DJF|DKK|DOP|DZD|EGP|ERN|ETB|EUR|FJD|FKP|GBP|GEL|GHS|GIP|GMD|GNF|GTQ|GYD|HKD|HNL|HRK|HTG|HUF|IDR|ILS|INR|IQD|IRR|ISK|JMD|JOD|JPY|KES|KGS|KHR|KMF|KPW|KRW|KWD|KYD|KZT|LAK|LBP|LKR|LRD|LSL|LYD|MAD|MDL|MGA|MKD|MMK|MNT|MOP|MRU|MUR|MVR|MWK|MXN|MXV|MYR|MZN|NAD|NGN|NIO|NOK|NPR|NZD|OMR|PAB|PEN|PGK|PHP|PKR|PLN|PYG|QAR|RON|RSD|RUB|RWF|SAR|SBD|SCR|SDG|SEK|SGD|SHP|SLE|SOS|SRD|SSP|STN|SVC|SYP|SZL|THB|TJS|TMT|TND|TOP|TRY|TTD|TWD|TZS|UAH|UGX|USD|USN|UYI|UYU|UZS|VED|VEF|VND|VUV|WST|XAF|XCD|XDR|XOF|XPF|XSU|XUA|YER|ZAR|ZMW|ZWL))\S{5,16}(?=\s|$)