DISCOVER Quick Start Guide
Overview
GuardWare DISCOVER is a cross-platform data discovery, investigation, and remediation system that locates, analyses, and manages sensitive data across endpoint devices, file servers, email systems, and cloud storage.
DISCOVER follows a simple operating flow:
Scan finds sensitive data across selected targets.
Investigation lets you flag files of interest and securely download and review them.
Remediation lets you move, delete, copy, and classify the sensitive data detected across scanned systems and send emails regarding the results to end users or data owners.
See Introduction to DISCOVER for the platform overview.
DISCOVER has three core components:
Management Console: The central web application. Stores configuration and results. Schedules scan jobs. Displays scan status, reports, investigations, and remediation options.
Scanning Server: A Windows service where the scanning agent is installed. It performs scans on target devices and shows the scan results in the Management Console.
Targets: The systems being scanned. Can include endpoints, SMB file shares, Exchange Online, and SharePoint Online.
Architecture: Local vs Agentless scanning
Local scan: A local scan is performed when the agent is installed on a target device, and the device scans itself for sensitive data.
Agentless scan (Remote scan): An agentless scan is performed using a scanning server where the agent is installed. The scanning server remotely connects to target devices that do not have the agent installed using protocols such as WinRM, SSH, or SMB (for file servers) and performs the scan on those devices.
We recommend using remote scanning for centralised coverage across devices and services.
Classifications, data types, and data owners
DISCOVER uses a simple governance model:
Classifications define sensitivity levels.
Data Types define what DISCOVER detects.
Data Owners define who is notified.
The relationship is direct:
A data type belongs to a classification.
One or more data owners can be assigned to a data type.
A file inherits the highest sensitivity classification from matched data types.
See DATA GOVERNANCE for the full governance model.
What this guide covers
Console access
Scanning Server configuration
Connecting Microsoft 365
Target discovery, scanning, and review
Investigation and remediation
This guide introduces the essential steps for quickly initiating scan jobs and getting visibility into your sensitive data landscape.
Before getting started, make sure you have installed the GuardWare Server and can access the GuardWare Management Console.
Download the Agent
Navigate to ORGANISATION > Agent Download > DISCOVER Agent.
Set the Location and click Update.
Click Submit. The Download link only appears after the configuration is complete.
Once the installation settings are complete, the Download Installer link becomes available. Click it to download the agent with the configured settings.
Configure the Scanning Server
For local scan, install the downloaded agent on a target device.
For agentless/remote scan, install the downloaded agent on a Windows host. The Windows host becomes the Scanning Server and scans multiple remote systems across the network.
Complete the setup wizard.
Confirm the Scanning Server appears as Online in the Console.
For remote scan, each target device must be configured to accept connections from the Scanning Server host using the appropriate protocol. GuardWare provides PowerShell scripts that enable the required services, set permissions, and configure firewall rules.
For Microsoft 365 targets, no script is required on target devices. The Scanning Server host needs outbound HTTPS access and valid Microsoft Entra ID credentials.
See Scanning Server Deployment Guide for remote access configuration.
Connect Microsoft 365
Connect your Microsoft 365 environment to enable scanning of Exchange Online and SharePoint Online. Ensure you have the Global Administrator account's credentials ready.
Navigate to ORGANISATION > Integrations.
Click Connect Microsoft 365.
Sign in with a Global Administrator account.
Review the requested permissions.
Select Consent on behalf of your organisation.
Click Accept.
Define classifications and data types
Set up classifications and data types before you run scans. This makes results easier to review and act on.
Navigate to DATA GOVERNANCE > Data Classification.
Create classifications manually with +Add Classification, or click Sync to import published Microsoft Purview Information Protection sensitivity labels.
Run Sync again after labels are added or changed in Microsoft Purview.
Go to DATA GOVERNANCE > Data Type.
Click +Data Type and enter the data type name and description.
Choose the identifier type:
Sensitive Words
Regular Expressions
Filename Expressions
Assign a classification and data owner.
Click Save.
See DATA GOVERNANCE for more details.
Discover target devices and services
Before you can scan, DISCOVER must know what to scan. Targets are the systems and services DISCOVER scans to detect sensitive data. Properly defining targets ensures scans reach the correct data sources and provide comprehensive visibility across your environment.
Start with your highest-priority systems that are most likely to contain sensitive data and expand gradually based on your requirements.
Devices
Device targets include workstations, laptops, and file servers where sensitive data may reside.
Go to DISCOVER > Target Discovery > Devices and click +New Target Discovery.
Enter a Job Name for the discovery job, and specify the Target IP range to define the network segment in which DISCOVER should search for devices.
Set the Location to filter the list of scanning servers by their assigned location.
Select the appropriate Protocol (WinRM, SSH, or FILE SERVER) to connect to the devices and provide Authentication credentials.
SSH for non-Windows devices.
WinRM for Windows devices.
File Server (SMB) for shared storage and file servers.
Set the Connection Attempt Interval to define how frequently DISCOVER will try to connect to a target.
Set Give-up Trying After to specify the maximum duration DISCOVER will continue attempting the connection before abandoning it.
Click Save.
Services
Cloud services extend DISCOVER's reach to data stored in external platforms, ensuring complete coverage of your digital assets regardless of location.
Go to DISCOVER > Target Discovery > Services and click +New Target Discovery.
Enter the Discovery Job name, then select the Cloud Connector for the service type (Microsoft Exchange or SharePoint).
Specify the Organisation (for SharePoint) and provide the Client ID and Tenant ID for authentication.
Set the Location to filter the list of scanning servers by their assigned location.
Select either Client Exchange Secret or Certificate as an authentication method.
Set the Connection Attempt Interval to define how frequently DISCOVER will try to connect to a target.
Set Give-up Trying After to specify the maximum duration DISCOVER will continue attempting the connection before abandoning it.
Click Save.
Discovered devices and services then appear in Devices/Services Found and can be selected in scans.
After a target discovery job completes, you can use Rediscover from DISCOVER > Target Discovery to run that same job again. Rediscover uses the same settings and target discovery parameters as the original job. You cannot change them during the rerun. Use it when devices in the discovery range were temporarily unavailable or unreachable.
For more details, see Target Discovery.
Create and run a scan
After target devices are found, create your first scan. During a scan, DISCOVER examines the selected devices and services by checking the specified directories (or all directories, if configured) and the specified file types for sensitive data.
It then searches within those files, identifying and reporting any sensitive data it detects. You can run a One-Time Scan for testing or targeted scans, or an Ongoing Scan for routine monitoring.
A One-Time Scan checks new or changed files on the selected targets against your configured data types and classifications. Use it to validate a new rule, perform a targeted check, or test new scan configurations.
Navigate to DISCOVER > Scans and click +New Scan.
Select One-Time Scan and click Proceed.
Enter a Scan Name and give a Description (optional), then click Next.
Select the data types you want to search for and click Next.
Select the targets and services to scan, then click Next.
Configure the File Handling Options, specify the files and folders you want to include or exclude from the scan, and then click Next.
Review the scan configurations and click Save Scan. The scan will begin automatically.
An Ongoing Scan performs a full scan of selected targets and services on a recurring schedule. Use it for routine checks, to validate compliance with data-handling policies, and to maintain continuous visibility into sensitive information across your environment.
Each scan contributes to a historical record that DISCOVER uses to generate trends, enabling you to monitor changes over time, identify emerging risks, and track remedial actions. Ongoing Scans are resource-intensive, so schedule them during off-peak hours to minimise impact on business operations.
Go to DISCOVER > Scans and click +New Scan.
Select Ongoing Scan and click Proceed.
Select data types you want to search for and click Next.
Select the Targets/Services to scan, then click Next.
Configure File Handling Options and filters, then click Next.
Schedule the scan time and click Next.
Review the scan configurations and click Save Scan. The scan will automatically initiate.
During execution, track progress in DISCOVER > Scans.
When the scan completes, open View Result or go to DISCOVER > Results.
Check results
From DISCOVER > Results, you can filter findings and move selected items into an investigation. After a scan completes, you can view details such as what sensitive data was found, which device or service it was found on, how many instances were detected, and any remediation actions that have been applied.
By default, you'll see results from all completed scans. Use the filter options at the top of the page to narrow results by scan job, date range, data type, classification, or target name.
Analyse discovered data
Use the dashboard for trends and the results view for details.
Go to DISCOVER > Dashboard > Dashboard for high-level metrics.
Review widgets such as Potential Sensitive Data, Potential Data by Target, and remediation status.
Go to DISCOVER > Dashboard > Summary Report to review files and targets by data type for a specific scan.
Go to DISCOVER > Results to inspect individual findings and refine filters by scan, target, data type, and classification.
Use this review to confirm risk, prioritise targets, and decide what needs investigation or remediation first.
See DISCOVER Dashboard for more details.
Classify discovered information
DISCOVER classifies files based on the matched data types. The highest matched classification is applied to the result.
Confirm that the relevant data types already have classifications assigned.
Review findings in DISCOVER > Results.
If a file needs a different label, use Remediate > Classify.
If you need to update the default mapping, go to DATA GOVERNANCE > Data Type and assign the correct classification to the data type.
This keeps discovered information aligned with your handling policy.
Create an investigation
Use the Investigation feature when you need to review discovered files more closely.
Before you investigate files, configure the secure location and investigation password first.
Set up a secure location and an investigation password
When DISCOVER identifies sensitive files during a scan, you may need to investigate or remediate them. A secure location is a designated storage area where these files are copied or moved, keeping them in a controlled environment separate from their original location.
Investigation password is the password you need to access the files downloaded using DISCOVER's Investigate function. Set the investigation password before conducting any investigations, and store it securely. If it is lost, previously downloaded files cannot be opened.
Set them in ORGANISATION > Set Up Secure Location.

See Secure Location and Investigation Password for more details.
Create a new investigation
Navigate to DISCOVER > Investigation.
Click + New Investigation.
Enter a name and a short purpose.
Click Create.
Move items into the investigation
Navigate to DISCOVER > Results.
Select one or more findings.
Click Investigate.
Select an existing investigation from the drop-down or create a new one by entering a new name.
Add an optional comment, and click Investigate. Investigation results are made available as password-protected ZIP downloads.
Click the download icon to download the file. The files inside the ZIP are password-protected. Use the password you set up while setting up the secure location.
See Investigation for more details.
Remediate sensitive information
Use Remediate to reduce risk after you confirm a finding. You can move, copy, delete, classify, or notify the right owner.
Go to DISCOVER > Results > Remediate or DISCOVER > Investigation > Remediate.
Select one or more files and click Remediate.
Choose a remediation action from the drop-down.
Move
Relocates the file to a secure location.
Copy
Creates a copy of the file to a secure or alternate location.
Delete
Permanently removes the file.
Classify
Classify file according to selected classification.
Send Email to Data Owner
Notifies the assigned data owner with an email.
Send Email to Device Owner
Notifies the file owner or user who has the device in their possession.
Add a comment (optional) to provide context or notes for the task.
Click Remediate to execute the selected action.
Use DISCOVER > Remediation to track what action was taken, by whom, and when.
See Remediation for more details.
With these steps complete, DISCOVER is ready to scan your selected targets and help you identify, investigate, and remediate sensitive data across your organisation.
Last updated

