diff --git a/src/content/docs/waf/detections/malicious-uploads/index.mdx b/src/content/docs/waf/detections/malicious-uploads/index.mdx
index e5c3e0a7b55..a88127d003e 100644
--- a/src/content/docs/waf/detections/malicious-uploads/index.mdx
+++ b/src/content/docs/waf/detections/malicious-uploads/index.mdx
@@ -82,7 +82,7 @@ This means a request whose content was only partly scanned can produce the same
:::note[Notes]
- The AV scanner will not scan some particular types of files, namely the following:
- - Password-protected archives
+ - Password-protected files. Refer to [Encrypted content](#encrypted-content) for supported file types.
- Archives with more than three recursion levels
- Archives with more than 300 files
- PGP-encrypted files
@@ -91,6 +91,19 @@ This means a request whose content was only partly scanned can produce the same
:::
+## Encrypted content
+
+Content scanning detects when a content object is password-protected (encrypted), for the following file types:
+
+- ZIP archives
+- RAR archives
+- PDF files
+- Microsoft Office files (`.docx`, `.doc`, `.xlsx`, `.xls`, `.pptx`, `.ppt`)
+
+When content scanning detects an encrypted content object, it sets `cf.waf.content_scan.has_encrypted_obj` to `true`. The scanner cannot determine whether encrypted content is malicious, so the content object's result in `cf.waf.content_scan.obj_results` is reported as `not scanned`, and `cf.waf.content_scan.has_failed` is not set for encrypted content.
+
+To block or challenge encrypted uploads, use `cf.waf.content_scan.has_encrypted_obj` in a custom rule.
+
## Custom scan expressions
Sometimes, you may want to specify where to find the content objects, such as when the content is a Base64-encoded string within a JSON payload. For example:
@@ -118,6 +131,7 @@ When content scanning is enabled, you can use the following fields in WAF rules:
| Number of malicious content objects
[`cf.waf.content_scan.num_malicious_obj`][3]
| The number of malicious content objects detected in the request (zero or greater). |
| Content scan has failed
[`cf.waf.content_scan.has_failed`][4]
| Indicates whether the file scanner was unable to scan any of the content objects detected in the request. |
| Content scan truncated
[`cf.waf.content_scan.truncated`][9]
| Indicates whether the request body exceeded the size limit for content scanning and was truncated before scanning, meaning the scan results may be incomplete. Refer to [Size limit](#size-limit). |
+| Has encrypted content object
[`cf.waf.content_scan.has_encrypted_obj`][10]
| Indicates whether the request contains at least one password-protected (encrypted) content object. Refer to [Encrypted content](#encrypted-content). |
| Number of content objects
[`cf.waf.content_scan.num_obj`][5]
| The number of content objects detected in the request (zero or greater). |
| Content object size
[`cf.waf.content_scan.obj_sizes`][6]
| An array of file sizes in bytes, in the order the content objects were detected in the request. |
| Content object type
[`cf.waf.content_scan.obj_types`][7]
| An array of file types in the order the content objects were detected in the request. |
@@ -132,5 +146,6 @@ When content scanning is enabled, you can use the following fields in WAF rules:
[7]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_types/
[8]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.obj_results/
[9]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.truncated/
+[10]: /ruleset-engine/rules-language/fields/reference/cf.waf.content_scan.has_encrypted_obj/
For examples of rule expressions using these fields, refer to [Example rules](/waf/detections/malicious-uploads/example-rules/).
diff --git a/src/content/fields/index.yaml b/src/content/fields/index.yaml
index d264d688d26..6fadaf82532 100644
--- a/src/content/fields/index.yaml
+++ b/src/content/fields/index.yaml
@@ -1220,6 +1220,28 @@ entries:
# Block requests to a specific endpoint whose content was not fully scanned
cf.waf.content_scan.truncated and http.request.uri.path eq "/upload"
+ - name: cf.waf.content_scan.has_encrypted_obj
+ data_type: Boolean
+ categories: [Request]
+ keywords:
+ [
+ request,
+ cloudflare,
+ content scanning,
+ malicious uploads,
+ client,
+ visitor,
+ ]
+ plan_info_label: Enterprise add-on
+ summary: Indicates whether the request contains at least one password-protected (encrypted) content object.
+ description: |-
+ Requires a Cloudflare Enterprise plan with [malicious uploads detection](/waf/detections/malicious-uploads/).
+
+ Refer to [Encrypted content](/waf/detections/malicious-uploads/#encrypted-content) for the file types this field covers.
+ example_block: |-
+ # Block requests containing password-protected uploads
+ cf.waf.content_scan.has_encrypted_obj and http.request.uri.path eq "/upload"
+
- name: cf.waf.content_scan.num_obj
data_type: Integer
categories: [Request]