Overview
Smart Scan is an intelligent scanning mode for Netskope DSPM that uses adaptive, metadata-driven clustering to discover sensitive data across large unstructured data stores. Instead of scanning every file, Smart Scan groups files by characteristics (such as file name, file type, folder structure, and size) and concentrates scanning where sensitive data is most likely located.
Smart Scan is the default scanning mode for all new DSPM scans. It is currently supported for AWS S3 and SMB File Shares.
How Smart Scan Works
Smart Scan automatically includes newly added and modified files in subsequent scans to keep your risk assessment current. It applies the following sampling logic per data store:
The clustering algorithm applies to all data stores regardless of their total file count. By using this logic, Smart Scan identifies at least 90% of all Entity Data Types (EDTs) in a data store while scanning only a fraction of the total files.
As the scan runs, results appear progressively in the UI. During the initial phase, the Data Store Inventory page displays a “Preparing Metadata” scan stage while the clustering algorithm processes file metadata prior to sampling.
Smart Scan vs. Advanced Scan
When connecting an AWS S3 or SMB data store, you can select between two scanning modes:

| Scanning Mode | Definition | File Selection | Recommended For |
| Smart Scan | Default. Automates file selection using metadata-driven clustering. | Determined by the clustering algorithm based on file metadata. | Most use cases. Provides a fast, representative risk assessment. |
| Advanced Scan | Optional. Allows manual definition of sample rate and file scope via regex. | User-defined sample percentage and optional regex filter. | Cases where you need to define a specific scan scope or sample rate. |
Data Store Overview Fields
When a data store uses Smart Scan, the Data Store Inventory page displays the following fields:

| Field | Description |
|---|---|
| Scan Type | Displays “Smart Scan” or “Advanced Scan”. (Note: This field only appears for S3 and SMB data stores). |
| Total Files | The total number of files in the data store. |
| Scanned Files | The number of files actually scanned by Smart Scan. |
| Sensitive Files | The number of files found to contain sensitive data. This value represents files identified by Smart Scan and may be lower than the actual total in the data store. (Note: Present for all unstructured data stores). |
| Sensitive Files Rate | The percentage of scanned files that contain sensitive data. (Note: This field only appears for S3 and SMB data stores scanned with Smart Scan). |
| Sensitive Data Size | The volume of sensitive data based on the files that have been scanned. This represents the size of the files classified as “Sensitive Files” and is not extrapolated to the entire data store. |
Supported Platforms
Support for additional data store types is planned for future releases. Currently, the feature availability is as follows:
| Platform | Smart Scan Supported | S3 Inventory Supported |
|---|---|---|
| AWS S3 | Yes | Yes |
| SMB File Share | Yes | No |

