Detection with the Passwords policy template fails on endpoints in DLP 16.0 MP1

Data Loss Prevention Endpoint Discover

3 more products

22192

25 May 2023

18 May 2023

The regular expression used in the Passwords policy template results in detection failures on endpoints due to limitations of the Lookahead and Lookbehind assertions. The Passwords policy template was introduced in Symantec Data Loss Prevention 16.0 MP1.

Resolve this issue by modifying the regular expression to remove the second, third, and fourth characters. You can copy the updated regular expression shown below.

(\s|^)(?=\S{0,15}[a-z])(?=\S{0,15}[A-Z])(?=\S{0,15}\d)(?=\S{0,15}[-!@#$&*])(?i)(?!([\d.-]{0,13}(jan|feb|mar|apr|may|jun|jul|aug|sep|oct|nov|dec)))(?![\d.,-]{1,15}\p{Sc}|\p{Sc}[\d.,-]{1,15})(?![\d.,-]{0,13}(AED|AFN|ALL|AMD|ANG|AOA|ARS|AUD|AWG|AZN|BAM|BBD|BDT|BGN|BHD|BIF|BMD|BND|BOB|BOV|BRL|BSD|BTN|BWP|BYN|BZD|CAD|CDF|CHE|CHF|CHW|CLF|CLP|CNY|COP|COU|CRC|CUC|CUP|CVE|CZK|DJF|DKK|DOP|DZD|EGP|ERN|ETB|EUR|FJD|FKP|GBP|GEL|GHS|GIP|GMD|GNF|GTQ|GYD|HKD|HNL|HRK|HTG|HUF|IDR|ILS|INR|IQD|IRR|ISK|JMD|JOD|JPY|KES|KGS|KHR|KMF|KPW|KRW|KWD|KYD|KZT|LAK|LBP|LKR|LRD|LSL|LYD|MAD|MDL|MGA|MKD|MMK|MNT|MOP|MRU|MUR|MVR|MWK|MXN|MXV|MYR|MZN|NAD|NGN|NIO|NOK|NPR|NZD|OMR|PAB|PEN|PGK|PHP|PKR|PLN|PYG|QAR|RON|RSD|RUB|RWF|SAR|SBD|SCR|SDG|SEK|SGD|SHP|SLE|SOS|SRD|SSP|STN|SVC|SYP|SZL|THB|TJS|TMT|TND|TOP|TRY|TTD|TWD|TZS|UAH|UGX|USD|USN|UYI|UYU|UZS|VED|VEF|VND|VUV|WST|XAF|XCD|XDR|XOF|XPF|XSU|XUA|YER|ZAR|ZMW|ZWL))\S{5,16}(?=\s|$)