Search & Investigate Captured Data

Anexet indexes every intercepted event — emails, messages, files, web traffic, USB transfers — and makes the entire corpus searchable from the Client Console. Full-text and structured searches run on Standard; thesaurus-based queries arrive with Advanced; fingerprint and hash lookup, plus endpoint file discovery, require Premium. Anexet is deployed on-premise; the vendor has no access to your data.

Schedule a Demo
Anexet Client Console showing Information Search and Complex Search modules

The Evidence Is Already There — Finding It Is the Problem

Every DLP deployment accumulates intercepted events faster than any team can manually review — when an incident lands, the question is whether you can locate the right fragment in hours rather than weeks.

Every DLP deployment accumulates intercepted events faster than any team can manually review them. When a data-loss incident or a compliance inquiry lands on your desk, the question is not whether the evidence exists — it almost certainly does — but whether you can locate the right fragment in hours rather than weeks.

Anexet's search layer was built specifically for that moment. The Client Console exposes two complementary search modules — Information Search for fast, filtered retrieval and Complex Search for multi-condition forensic queries — backed by a full-text index across every channel Anexet captures: email (POP3, SMTP, IMAP, MAPI), web traffic (HTTP/FTP), messengers, cloud storage, network shares, USB transfers, clipboard events, and print jobs.

Information-security officers use search to reconstruct the chain of events around a suspected leak, pulling up the exact message, attachment, or file-transfer log that triggered a policy. IT-security analysts and internal auditors use it to answer compliance questions — 'did any document containing these terms leave the company in the past 90 days?' — without writing custom queries or exporting raw logs. The same index feeds Anexet's automated Security Policies, so what you can search manually, a policy can watch in real time.

Why it matters

  • Incident response in hours

    Full-text search across all intercepted channels lets security officers locate the exact message, file, or transfer event that triggered a policy — without exporting raw logs.

  • Forensic-grade queries

    Complex Search chains AND/OR/NOT conditions, wildcards, and field-level targeting; Advanced adds thesaurus synonym groups; Premium adds fingerprint and hash matching.

  • On-premise, no vendor access

    Every intercepted event, every search query, and every result stays within your own infrastructure — Scinero Software Limited has no remote connection to your deployment.

Search Capabilities Across Every Intercepted Channel

Core search is included from the Standard plan. Thesaurus search and File Operations Audit are added with Advanced. Fingerprint search, hash search, and endpoint file-system discovery require Premium.

Core search — Standard

  • Full-text search across all intercepted data

    Standard

    Search body text, subject lines, filenames, and attachment content across every capture channel simultaneously.

  • Search by data type

    Standard

    Filter results to a specific channel or file type — email, messenger, web, files and processes — in a single query.

  • General search parameters

    Standard

    Narrow by interception timestamp, document size, client IP address, and server port.

  • Per-channel search parameters

    Standard

    Additional filters specific to email (sender, recipient, subject), messengers (conversation thread), web (URL, session), and file and process events.

  • Complex Search with combined conditions

    Standard

    Build multi-condition queries with AND/OR/NOT logic, wildcards, and field-level targeting for precise forensic work.

Advanced search — Advanced plan

  • Thesaurus-based search

    Advanced

    Search using synonym groups so a query for 'contract' also surfaces 'agreement,' 'deal,' or custom synonyms your organisation defines.

  • File Operations Audit

    Advanced

    A searchable log of every create, copy, move, rename, and delete operation users perform on files and folders, covering workstations and network shares.

Precision & discovery — Premium plan

  • Digital fingerprint search

    Premium

    Match intercepted content against document fingerprints registered in the system; returns results even when a confidential file is pasted, renamed, or partially altered.

  • Hash search

    Premium

    Identify exact copies of registered files across all interception events using hash banks.

  • File Systems Monitoring — sensitive-data discovery on endpoints

    Premium

    Indexes workstation file systems to find sensitive files stored in unapproved locations on employee PCs. Searches by hash, hash bank membership, or file attributes. Supports remote actions on found files.

File Systems Monitoring is endpoint file-system discovery — it locates data already at rest on managed workstations, not a cloud or database scanner. The exact capability set available in your environment is confirmed during the demo.

On-Premise Index — Searchable from the Client Console

A lightweight endpoint agent captures activity across every monitored channel — email, messengers, web, USB, printers, cloud storage, network shares, and clipboard. Intercepted events are sent to your on-premise server, where the Index Server builds and maintains a full-text index. Security officers query the index from the Information Search or Complex Search module in the Client Console without touching live infrastructure.

Anexet is deployed entirely within your own infrastructure. The vendor has no access to your data: every intercepted event, every search query, and every result remains on your servers. There is no cloud relay, no vendor-side processing, and no third-party storage involved.

Information Search module in the Anexet Client Console
Complex Search query builder with multi-condition logic

How Search Works — 4 Steps

From endpoint capture to a searchable, actionable evidence record.

A lightweight endpoint agent captures activity across every monitored channel and sends intercepted events to your on-premise server, where the Index Server builds a full-text index.

1

Security officers open Information Search or Complex Search in the Client Console, select scope and filters — date range, user, IP, file size — and type a query; results are returned from the index.

2

Complex Search lets analysts chain conditions and apply thesauruses (Advanced) or fingerprint and hash rules (Premium); File Operations Audit provides a parallel timeline of file-system actions tied to the same users.

3

Search results feed directly into Investigations (Premium) for case-building and evidence export; findings can also update Security Policies so future occurrences trigger automatic alerts.

4

A lightweight endpoint agent captures activity across every monitored channel and sends intercepted events to your on-premise server, where the Index Server builds a full-text index.

1

Security officers open Information Search or Complex Search in the Client Console, select scope and filters — date range, user, IP, file size — and type a query; results are returned from the index.

2

Complex Search lets analysts chain conditions and apply thesauruses (Advanced) or fingerprint and hash rules (Premium); File Operations Audit provides a parallel timeline of file-system actions tied to the same users.

3

Search results feed directly into Investigations (Premium) for case-building and evidence export; findings can also update Security Policies so future occurrences trigger automatic alerts.

4

Arrow

Search Capabilities by Plan

StandardCore employee activity monitoring.
Network traffic interception
USB control
Printers monitoring
Messengers interception
Browsers interception
and 4 more
Includes:
Anexet Activity
Most popular
AdvancedAdds DLP and deeper visibility.
Standard plan included
DLP features
Network shares monitoring
Keylogger
Webcam pictures
and 4 more
Includes:
Anexet DLP
Anexet Activity
All-in-one
PremiumAll-in-one solution.
Standard + Advanced plans included
Advanced search (digital fingerprints, hash search)
File systems monitoring
User relations analysis
Risk analysis
and 6 more
Includes:
Anexet DLP
Anexet Inventory
Anexet Activity
Anexet Ultimate

Frequently Asked Questions

Common questions about searching and investigating captured data in Anexet.

What does 'search intercepted data' mean in practice?

When Anexet captures an email, a messenger conversation, a file transfer over USB or FTP, or a web-session event, it indexes the full content and metadata on your on-premise server. Searching intercepted data means querying that index from the Client Console — the same way you would search a document library — to locate specific content across all capture channels at once.

Full-text search across all intercepted data is included from the Standard plan. Thesaurus-based search (synonym groups) requires Advanced. Digital fingerprint and hash-based search require Premium.

Regular search queries the interception index — events that happened when data moved through a monitored channel. File Systems Monitoring indexes the file systems of managed workstations to find sensitive files stored in unapproved locations on employee PCs, regardless of whether those files were ever transferred. It is endpoint file-system discovery, not a DCAP, cloud-scanning, or data-at-rest classification tool. It requires Premium.

Anexet is deployed on-premise; the vendor has no access to your data. Every intercepted event, every search query, and every result stays within your own infrastructure. Scinero Software Limited has no remote connection to your deployment.

Yes. The Information Search module searches across all capture channels simultaneously unless you explicitly filter by channel. A single query can surface results from email, desktop messengers, web traffic, cloud storage transfers, and USB events together.

Information Search is designed for fast, single-condition retrieval with per-channel filters — the tool you reach for first when you know roughly what you are looking for. Complex Search is for multi-condition forensic queries: combine AND/OR/NOT operators, apply wildcards, target specific fields, and on Advanced, search by synonym thesaurus. Use Complex Search when a simple keyword query returns too much noise or when you need to satisfy a compliance request with documented search logic.

File Operations Audit — the log of file create, copy, move, rename, and delete actions on workstations and network shares — is available from the Advanced plan.

Three professionals collaborating and looking at a tablet in a meeting

Find What Your Employees Are Sending — Before It Becomes an Incident

Tell us about your investigation and compliance requirements — we will map them to the right plan and arrange a demo or a free trial of Anexet Ultimate.

I accept that my personal data can be processed in accordance with the Privacy Policy