Skip to main content

Who is this article for?

Code42 for EnterpriseSee product plans and features
CrashPlan for Small Business 

CrashPlan for Small Business, no.

Code42 for Enterprise, yes.

Link: Product plans and features.

This article applies to Cloud.

Code42 Support

Forensic File Search file categories

Who is this article for?

Code42 for EnterpriseSee product plans and features
CrashPlan for Small Business 

CrashPlan for Small Business, no.

Code42 for Enterprise, yes.

Link: Product plans and features.

This article applies to Cloud.

Overview

Forensic File Search groups files into categories based on analysis of the file contents and file extension. This categorization enables you to narrow your searches to specific types of files. For example, performing a search for the Image file category returns file activity for .gif, .jpg, .png, and many other known image file types.

A complete list of categories and the types of files in those categories appears below.

Search by file category

To search for file events based on file category:

  1. Sign in to the administration console.
  2. Select Security Center > Forensic Search.
  3. Select search type File Category.
  4. Choose a search operator (includes any or includes none).
  5. Select one or more file categories. 
  6. (Optional) Click the + icon to add additional search criteria.
  7. Click Search.

File category search

File category details

The table below provides examples of the types of files in each category. File extensions are not the only criteria used to determine the file category, but they are listed in the table below to illustrate the types of files typically included in each category.

File categories can help uncover mismatched file extensions
Where possible, Forensic File Search determines the file category based on the file contents, not the file extension. Examining the contents can highlight instances where a user changes a file extension. For example, if a file event has the file category Spreadsheet but the Filename uses the .jpg extension, it may indicate an attempt to hide or exfiltrate data.
File category Specific file type (extension)
Archive 7z, bz2, cab, dmg, gz, iso, rar, tar, tbz2, tgz, zip, zipx
Audio aac, aif, flac, m4a, mp3, oga, ogg, wav, wma
Document doc, docm, docx, odt, pages, rtf, txt, wps
Executable apk, app, appx, cgi, com, deb, dll, exe, jar, msi, msp, mst, osx, out, pkg, rpm, udeb
Image 3dm, 3ds, ai, bmp, cdr, des, djvu, dwg, dxf, eps, gif, ico, jpg, max, png, ps, psd, raw, skp, svg, tif, tiff, wmf
PDF pdf
Presentation key, odp, otp, ppt, pptm, pptx
Script action, bash, bat, cmd, command, csh, job, jse, ps1, psm1, sh, tcsh, vbs, workflow
Source code c, c++, cc, class, cpp, cs, cxx, el, go, h, java, js, lua, m, php, php3, php4, pl, py, r, rb, rs, swift, vb
Spreadsheet ods, xla, xlc, xld, xll, xlm, xls, xlsm, xlsx, xlt, xlw
Video 3gp, asf, avi, flv, m2ts, mkv, mov, mp4, mpeg, mpg, mts, vob, webm, wmv
Virtual Disk Image dsk, hdd, hds, vdi, vhd, vhd, vhdx, vmdk