diff --git a/src/content/docs/waf/detections/malicious-uploads/index.mdx b/src/content/docs/waf/detections/malicious-uploads/index.mdx index e5c3e0a7b55..a88127d003e 100644 --- a/src/content/docs/waf/detections/malicious-uploads/index.mdx +++ b/src/content/docs/waf/detections/malicious-uploads/index.mdx @@ -82,7 +82,7 @@ This means a request whose content was only partly scanned can produce the same :::note[Notes] - The AV scanner will not scan some particular types of files, namely the following: - - Password-protected archives + - Password-protected files. Refer to [Encrypted content](#encrypted-content) for supported file types. - Archives with more than three recursion levels - Archives with more than 300 files - PGP-encrypted files @@ -91,6 +91,19 @@ This means a request whose content was only partly scanned can produce the same ::: +## Encrypted content + +Content scanning detects when a content object is password-protected (encrypted), for the following file types: + +- ZIP archives +- RAR archives +- PDF files +- Microsoft Office files (`.docx`, `.doc`, `.xlsx`, `.xls`, `.pptx`, `.ppt`) + +When content scanning detects an encrypted content object, it sets `cf.waf.content_scan.has_encrypted_obj` to `true`. The scanner cannot determine whether encrypted content is malicious, so the content object's result in `cf.waf.content_scan.obj_results` is reported as `not scanned`, and `cf.waf.content_scan.has_failed` is not set for encrypted content. + +To block or challenge encrypted uploads, use `cf.waf.content_scan.has_encrypted_obj` in a custom rule. + ## Custom scan expressions Sometimes, you may want to specify where to find the content objects, such as when the content is a Base64-encoded string within a JSON payload. For example: @@ -118,6 +131,7 @@ When content scanning is enabled, you can use the following fields in WAF rules: | Number of malicious content objects
[`cf.waf.content_scan.num_malicious_obj`][3]
| The number of malicious content objects detected in the request (zero or greater). | | Content scan has failed
[`cf.waf.content_scan.has_failed`][4]
| Indicates whether the file scanner was unable to scan any of the content objects detected in the request. | | Content scan truncated
[`cf.waf.content_scan.truncated`][9]
| Indicates whether the request body exceeded the size limit for content scanning and was truncated before scanning, meaning the scan results may be incomplete. Refer to [Size limit](#size-limit). | +| Has encrypted content object
[`cf.waf.content_scan.has_encrypted_obj`][10]
| Indicates whether the request contains at least one password-protected (encrypted) content object. Refer to [Encrypted content](#encrypted-content). | | Number of content objects
[`cf.waf.content_scan.num_obj`][5]
| The number of content objects detected in the request (zero or greater). | | Content object size
[`cf.waf.content_scan.obj_sizes`][6]
| An array of file sizes in bytes, in the order the content objects were detected in the request. | | Content object type
[`cf.waf.content_scan.obj_types`][7]
| An array of file types in the order the content objects were detected in the request. | @@ -132,5 +146,6 @@ When content scanning is enabled, you can use the following fields in WAF rules: [7]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_types/ [8]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_results/ [9]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.truncated/ +[10]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.has_encrypted_obj/ For examples of rule expressions using these fields, refer to [Example rules](/waf/detections/malicious-uploads/example-rules/). diff --git a/src/content/fields/index.yaml b/src/content/fields/index.yaml index d264d688d26..6fadaf82532 100644 --- a/src/content/fields/index.yaml +++ b/src/content/fields/index.yaml @@ -1220,6 +1220,28 @@ entries: # Block requests to a specific endpoint whose content was not fully scanned cf.waf.content_scan.truncated and http.request.uri.path eq "/upload" + - name: cf.waf.content_scan.has_encrypted_obj + data_type: Boolean + categories: [Request] + keywords: + [ + request, + cloudflare, + content scanning, + malicious uploads, + client, + visitor, + ] + plan_info_label: Enterprise add-on + summary: Indicates whether the request contains at least one password-protected (encrypted) content object. + description: |- + Requires a Cloudflare Enterprise plan with [malicious uploads detection](/waf/detections/malicious-uploads/). + + Refer to [Encrypted content](/waf/detections/malicious-uploads/#encrypted-content) for the file types this field covers. + example_block: |- + # Block requests containing password-protected uploads + cf.waf.content_scan.has_encrypted_obj and http.request.uri.path eq "/upload" + - name: cf.waf.content_scan.num_obj data_type: Integer categories: [Request]