bowbridge Anti-Virus for Salesforce Documentationbowbridge Anti-Virus for Salesforce
Configuration

Active Content Configuration

Overview

  • Active content is executable or dynamic content in files, for example JavaScript in PDFs, macros in Office documents, or scripts in SVG images.
  • This page lets you enable or disable detection for each content type in each Protection Profile.

Accessing Active Content Settings

  1. Go to Settings → File Scan
  2. Scroll to Advanced Configuration
  3. Click the Active Content Configuration tab

How It Works

When active content is detected in a file and the Block Active Content setting is enabled in Scan Configuration, the file is blocked.

Common Active Content Types

Content TypeFound InRisk
JavaScriptPDF, HTML, SVGScript execution, phishing
VBA MacrosWord, Excel, PowerPointMalware delivery, data exfiltration
Embedded OLE ObjectsOffice documentsHidden executables
DDE (Dynamic Data Exchange)Excel, WordRemote code execution
Flash/ActionScriptPDF, SWFExploits, malware
Embedded FilesPDFHidden payloads
Auto-Open ActionsPDF, OfficeAutomatic execution on open
External LinksOffice, PDFData exfiltration, phishing

Each Protection Profile can have different active content settings.

Best Practices

  1. Start with all detections enabled and disable only what your business needs.
  2. Always block JavaScript in PDFs because this is a common attack vector.
  3. Review changes carefully

On this page