Malware Protection Events
Focus
Focus
Prisma Browser

Malware Protection Events

Table of Contents

Malware Protection Events

Malware protection events are generated when Prisma Browser detects malicious content in files, websites, or browser extensions.

Event Types

Event TypeUI NameDescription
maliciousFileMalicious file identifiedA file was identified as malicious by one or more scan engines
maliciousWebsiteMalicious websiteA website was classified as malicious by URL reputation or real-time analysis
maliciousExtensionMalicious extensionA browser extension was identified as malicious

Context Fields — Malicious File

FieldUI LabelDescription
file.nameFile nameThe name of the malicious file
file.extensionFile typeThe file extension
file.sha256File SHA-256The SHA-256 hash of the file
file.urlFile URLThe URL from which the file was downloaded
content.scanEngineScan engineThe engine that detected the threat (Talon, CrowdStrike, CrowdStrike Quick Scan, CrowdStrike Indicators, OPSWAT MetaDefender Core, Yazamtech, Symantec, Votiro, AWF)
classification.maliciousCategoriesReasonThe malware categories identified (Keyloggers, Malware, Phishing, Spyware and Adware, Botnet, Spam)
classification.reputationReputationNumeric reputation score

Context Fields — Malicious Website

FieldUI LabelDescription
network.urlURLThe malicious URL
network.classificationsWebsite classificationURL categories assigned
network.webScanEngineWeb Scan EngineThe engine that classified the URL (PAN-DB, URL Real-Time, Live Page Scanning, ADNS, Hosts File)
network.webScanEnginesWeb Scan EnginesAll engines that contributed to the classification
network.webRiskLevelRisk LevelThe risk level of the URL
classification.maliciousCategoriesReasonThe threat categories (Keyloggers, Malware, Phishing, Spyware and Adware, Botnet, Spam)

Live Page Scanning Detection

When a malicious website is detected by real-time page scanning rather than URL reputation:
FieldDescription
content.liveScanning.scanMethodDetection method used (Content analysis, Injected script, Screenshot analysis)
content.liveScanning.triggeredByUser action or automatic page behavior
content.liveScanning.maliciousObjectThe type of malicious object (Iframe, Webpage, Service worker, Clipboard)
content.liveScanning.maliciousContentUrlURL of the malicious content

Context Fields — Malicious Extension

FieldUI LabelDescription
browserExtension.nameExtension nameThe name of the malicious extension
browserExtension.idExtension IDThe Chrome Web Store extension ID
browserExtension.versionExtension versionThe extension version
extensionRisk.riskRiskThe risk level assigned (Low, Medium, High, Malicious, Unknown)
extensionRisk.initiatorInitiatorWho initiated the action (User, Policy, Automatic)
extensionRisk.triggerTriggerWhat triggered the detection (ID, Permissions, Risk)

Scan Engines

Prisma Browser uses multiple scan engines to detect threats. The following engines may appear in malware protection events:
EngineDescription
TalonPrisma Browser built-in scan engine
CrowdStrikeCrowdStrike file reputation check
CrowdStrike Quick ScanCrowdStrike cloud-based quick scan
CrowdStrike IndicatorsCrowdStrike indicator-based detection
OPSWAT MetaDefender CoreOPSWAT multi-scan engine
YazamtechYazamtech file analysis
SymantecSymantec file scan
VotiroVotiro content disarm and reconstruction
AWFAdvanced WildFire sandbox analysis

Web Scan Engines

For website classification:
EngineDescription
PAN-DBPalo Alto Networks URL filtering database
URL Real-TimeReal-time URL classification
Live Page ScanningReal-time analysis of page content, scripts, and iframes
ADNSAdvanced DNS-based classification
Hosts FileLocal hosts file-based filtering

Malicious Categories

Events may include one or more of the following threat categories:
CategoryDescription
KeyloggersKeystroke logging malware
MalwareGeneral malware
PhishingCredential harvesting or social engineering
Spyware and AdwareTracking or advertising software
BotnetCommand-and-control communication
SpamSpam-related content

Examples

Malicious File — Blocked on Download
FieldValue
TypeMalicious file identified
CategoryMalware
Userjohn.smith@acme.com
URLwww.sketchy-downloads.net/free-tool.exe
File namefree-tool.exe
Scan engineCrowdStrike
ReasonMalware
ActionBlocked
SeverityHigh
Malicious Website — Phishing (PAN-DB)
FieldValue
TypeMalicious website
CategoryMalware
Userjane.doe@acme.com
URLwww.acme-login-verify.fake-domain.com/signin
Web Scan EnginePAN-DB
ReasonPhishing
Risk LevelHigh
ActionBlocked
Malicious Website — Detected by Live Page Scanning
FieldValue
TypeMalicious website
CategoryMalware
Userbob.jones@acme.com
URLwww.legitimate-news.com/article/12345
Web Scan EngineLive Page Scanning
Scan methodContent analysis
Malicious objectIframe
Malicious content URLmalware-cdn.evil.net/payload.js
ReasonMalware
ActionBlocked
SeverityVery high
Malicious Extension — Detected by Risk
FieldValue
TypeMalicious extension
CategoryMalware
Usersarah.kim@acme.com
Extension nameSuper PDF Converter
Extension IDabcdefghijklmnop
RiskMalicious
TriggerRisk
InitiatorPolicy
ActionBlocked
SeverityHigh