Reviewing Results After a Discovery

Reviewing Results After a Discovery

After the discovery process is complete, GEODI offers several ways to analyze the results: Reports, Dashboards, and Predefined Queries.


If any risky findings are detected, actions such as Secure Delete, Quarantine, or Masking should be considered to mitigate the risk.

 

 

How to Query Risky Findings

GEODI Discovery offers you numerous insights into the data. Compliance with PCI/DSS, KVKK, GDPR, or another national regulation and AI-based deep analysis for fraud, threat, and more...

 

predefined:PII → Selects all content that has PII info, that is, ID or Name, along with phone, address, blood type, etc.

predefined:PCI → Selects all content that has IBANs, CVVs, credit card numbers, and similar financial data.

(predefined:PCI OR predefined:PII) source:<Risky> → Now you select PII and PCI on a risk source, i.e., common file sharing.

(predefined:PCI OR predefined:PII) predefined:10Y → Content that has PII or PCI data and older that 10 years.

 

You write a GEODI Query like the ones above, take a report, look at a panel, or start remediation, such as deleting, masking, or quarantining. GEODI’s semantic queries give you razor-sharp targeting.

Risky information di

Querying Old Files

GEODI also provides queries for content older than a certain number of years:

predefined:O5Y

predefined:O10Y

predefined:O15Y

 

Combine with other filters for deeper insights:

predefined:O5Y predefined:PII

predefined:O5Y (predefined:PII veya predefined:PCI)

predefined:O5Y (predefined:PII veya predefined:PCI) source:<risky>

 

👥 User-Based Analysis

GEODI allows you to intersect queries by user or group, making it possible to analyze what a specific user can access:

 

user:<user|group>

user:<user|group> and source:<risky>

 

With the GEODI Access Management license, you can also report on and update user permissions via workflows.

 

🗃️ Duplicates and Deletion

Duplicates are a common issue and can disrupt workflows. GEODI helps identify original files, duplicates, and similar content:

🔗 Learn more

 

Malicious Email Discovery:EMail Threat AI

This is a capability provided by GEODI Q and can be included in email discovery for PII or PCI purposes. After filtering out problematic emails, you can perform from/to and frequency analyses. The standard GEODI Discovery reports are sufficient.

https://support.decesoftware.com/space/geodien/5229150209/%F0%9F%92%A3%F0%9F%93%A7+Email+Threat+AI

 

🧠 GEODI Q – AI & LLM Integration

GEODI Q brings advanced AI capabilities to GEODI discovery:

  • Email Threat AI is just one sample.

  • Detects document types, fraud patterns, competition violations

  • Performs summarization, CV analysis, sentiment analysis, and flags offensive emails

🔍 Searching for Anything

Beyond predefined queries like PCI or PII, GEODI supports flexible keyword and rule-based searches:
🔗 Full Search Guide

This is especially valuable for Data Subject Access Requests (DSAR) under GDPR or KVKK. You can easily search for a person’s name, isolate internal content, and generate a content list report.

📊 Discovery Dashboard

GEODI includes a ready-to-use Discovery Panel, offering summarized insights driven by queries.
Accessible to system admins and ACC.Discovery group members. Only visible in projects where:

json "GenericSettings": { "ACC.Discovery": true }

The panel includes:

  • Finding Breakdown: e.g., number of PII IDs, how many VISA cards

  • Trend Analysis: See how findings evolve week by week (default: last 8 weeks)

  • Source Filtering: e.g., source:<Risky> shows counts by source

image-20250210-070847.png

 

 

Reports

Queries affect not only dashboards but also reports and actions.

Examples:

  • Use predefined:PII to generate reports listing all relevant findings

  • Use duplicate queries to list all redundant files

 

Actions and Workflows

Queries can trigger actions—manually or as part of automated workflows.

Examples:

  • Use a duplicate query to securely delete files

  • Use predefined:PII to perform bulk masking

Actions can include:

  • Secure Delete

  • Quarantine

  • Masking

  • Send Email

  • Generate Report

Workflows

 

Destructive actions and other operations that alter data often require user consent. For this purpose, GEODI offers a simple solution that involves data owners in the process.

🛡️ Consent based Remediation


 

 

📌 Other Predefined Queries

Predefined queries make complex or hard-to-remember rules easy to use.

Query

Purpose

Query

Purpose

predefined:Money

Recognizes multiple currencies ($, €, £, SAR, etc.)

predefined:CreditCard

Covers over 10 CC types and test cards

predefined:DB

Brings DB files like SQL Server, Oracle, SQLite, MDB

predefined:Videos

Finds video files

predefined:Images

Finds image files

predefined:Web

Web content, including email

predefined:Maskcontent

Maskable content

predefined:Local

Local-only content

predefined:GDE

GDE-fed content

predefined:PII

PII-related content, adaptable to local rules

predefined:scpd_religion

Religion

predefined:scpd_race

Ethnicity

predefined:scpd_MaritalStatus

Marital status

predefined:scpd_health

Health-related terms

predefined:scpd_unions

Unions

predefined:scpd_PoliticalOpinion

Political views

predefined:scpd_foundations

Foundations

predefined:CV

CV-related documents

predefined:AbleToClassifyByLabel

Classifiable by tag

predefined:AbleToClassifyByADS

Classifiable by ADS rules

predefined:SourceCode

Source code files

**