bowbridge Anti-Virus for Salesforce Documentationbowbridge Anti-Virus for Salesforce
Configuration

File Scan Settings

Overview

The File Scan settings control both the general scanning behavior and the advanced antivirus engine configuration for each Protection Profile.

Accessing File Scan Settings

  1. Go to Settings → File Scan

File Scan Settings

Profile Selection
  • At the top of the File Scan panel, select the Protection Profile whose settings you want to configure. If you haven't created additional profiles, the Default Profile is selected automatically.
  • All settings below apply only to the selected profile.
File Protection
SettingDescription
File ProtectionMaster switch to enable or disable file scanning for the selected profile.
Scan On (Trigger Events)

Configure when files are scanned:

OptionDescription
UploadFiles are scanned when uploaded to Salesforce.
DownloadFiles are scanned when a user attempts to download them.
Action on Threat

Define what happens when a threat is detected:

ActionDescription
BlockThe file is blocked and inaccessible to users until an admin releases it.
Allow and notifyThe file is allowed through, but administrators and/or users are notified about the detected threat.
Replace Harmful Files
SettingDescription
Replace fileWhen enabled, a blocked file's content is replaced with a harmless placeholder indicating it was removed for security reasons.

Advanced File Scan Settings

The advanced settings provide granular control over the antivirus engine's behavior.

Accessing Advanced File Scan Settings

  1. Go to Settings → File Scan
  2. Scroll to Advanced Configuration
Content Detection & Blocking
SettingDescriptionDefault
Block Encrypted FilesBlock files that are password-protected or encrypted and cannot be scannedDisabled
Block Active ContentBlock files containing active content (macros, JavaScript, etc.)Disabled
Block HTML in PDFBlock PDF files containing dictionary elements that may be interpreted as HTMLDisabled
HTML Detection LevelControls the sensitivity of HTML content detection in non-HTML filesSAFE
File Type Controls
SettingDescriptionDefault
Enable MIME Type ChecksActivate MIME type related checks including allow list, block list, and extension matchingDisabled
Enforce Extension MatchingValidate that file content matches filename extensionEnabled
Apply MIME Policy in ArchivesEnforce MIME policy for files inside archives and compressed filesEnabled
Blocked MIME TypesComma-separated list of MIME types that are always blockedEmpty
Allowed MIME TypesComma-separated list of allowed MIME types that skip file scanningEmpty
Blocked File ExtensionsComma-separated list of file extensions that are always blockedEmpty
Allowed File ExtensionsComma-separated list of allowed file extensions that proceed to antivirus scanningEmpty
Archive & Compression Settings

These settings control how the engine handles compressed archives (ZIP, RAR, 7z, TAR, etc.).

SettingDescriptionDefault
Enable Archive ScanningExtract and recursively scan archive contentsEnabled
Skip Virus Scan in ArchivesSkip virus scan for extracted archive content and apply policy checksDisabled
Detect Active Content in ArchivesEnforce active content detection for files inside archivesDisabled
Maximum Archive DepthMaximum depth to which nested archives are extracted20
Archive Expansion RatioMaximum ratio of extracted size to archive size128
Max Files per ArchiveMaximum number of elements allowed in an archive0 (unlimited)
Max Extracted Size (bytes)Maximum extracted archive size in bytes, with 0 meaning unlimited0 (unlimited)
Scanning Behavior
SettingDescriptionDefault
Scan All File TypesForce scanning of all file types regardless of extension filtersEnabled
Scan Best EffortContinue scanning even if some content cannot be fully processedEnabled
Scan Embedded ContentScan all embedded objects and enable embedded content analysisEnabled
Scan Base64 ContentDecode and scan Base64 encoded content within filesDisabled
Scan UU-Encoded ContentDecode and scan UU encoded content within filesEnabled
Deep XML ScanningScan every element in parsed XML filesDisabled
Scan Timeout (milliseconds)Maximum duration in milliseconds before a scan operation failsNo default
Content Type Handling
SettingDescriptionDefault
SVG Content HandlingDefine how SVG related content type handling is appliedSVG
XML Content HandlingDefine how XML related content type handling is appliedXML

On this page