CAPABILITIES
What it provides
- Multipart file inspection and optional whole-body scanning for raw upload endpoints.
- Exact verification after Bloom screening, plus custom SHA-256 allowlists and blocklists.
- Block or Log only policies for confirmed matches; a separate policy for incomplete scans.
- A default 10 MiB budget shared across request files and fields, with complete-file hashing only.
DEPLOYMENT WORKFLOW
How to use it
- 01
Obtain an abuse.ch Auth-Key and save it under Admin → Security Data → MalwareBazaar.
- 02
Choose Check access & update hashes, then verify database source, count, and synchronization on each WAF agent.
- 03
Enable Malicious Uploads Detection in the project WAF settings. Start with Log only and Forward and log, then validate before blocking.
CONFIGURATION & OPERATION
Where it fits in your setup
The provider key is encrypted on the control plane and is not distributed to agents. The control plane downloads hash lists and sends them through authenticated connections. Uploaded files are not submitted to MalwareBazaar. Updates from the settings screen run when requested.
COVERAGE & LIMITS
What to account for
Unknown or modified malware may not match; archives are not unpacked. Missing downloaded data can leave only the EICAR test signature, and this fallback is not currently classified as an incomplete scan. Verify the actual feed separately from EICAR tests. Incomplete scans default to forwarding with a log; other WAF policies still apply.