SALESFORCE ANTIVIRUS | MALWARE-PROTECTION | FILE SCANNING
Advanced protection against malware and ransomware
WithSecure Cloud Protection scans every file in Salesforce in real time, blocking malware, ransomware, and hidden cyber threats before they reach your users.
Detects zero-day malware
AV-TEST awarded engines


Salesforce is a blind spot for malware
Your Salesforce environment accepts files from anyone: employees, customers, and partners. Your users can upload malicious files loaded with malware to your Salesforce via forms, emails, or apps. Those files are trusted by default, but Salesforce doesn’t scan them for malware or cyber threats.
Perimeter defenses like email gateways or endpoint antivirus don’t reach inside the platform. Once a malicious file is uploaded to your Salesforce instance, it can spread across it before anyone realizes.
That gap makes Salesforce an attractive target: attackers know they can bypass your existing security stack and distribute malware where users least expect it.
Next-gen antivirus inside Salesforce
Dynamic protection
Detect both known malware and sophisticated zero-day attack methods.
Fast detection
Scan every upload and download in real time, without slowdown for users.
Proven effectiveness
Engines are validated by AV-TEST: 100% detection against commodity and zero-day malware.
Real-time visibility
Get clear alerts, recommended actions, and audit-ready logs.
How File Protection works
Files enter Salesforce and introduce risk
File uploads come in through Experience Cloud, Service Cloud, Sales Cloud, email-to-case, Agentforce use cases and integrations. Malware hidden in PDFs, Office docs, image files or archives bypass perimeter defenses and land directly inside Salesforce.


Scan every file in real time
WithSecure Cloud Protection for Salesforce scans each file at the moment of upload or download – across standard and custom Salesforce objects and fields. Files are analyzed against global threat intelligence bases. Unknown files are analyzed in-depth with next-gen antivirus engines, heuristics, and behavioral threat analysis, All in isolated sandbox environments.
Block threats instantly
When malware is detected, the file is stopped before anyone can open or share it. Users see a clear notification, and admins get instant alerts with recommended actions. Blocked files can be replaced with safe “notice files,” so workflows continue without disruption.


Visibility for security teams
Every detection is logged with full detail. Admins get audit-ready reporting, possibility for SIEM/SOAR integration, and the ability to trace incidents back to the source. Instead of blind spots, you gain actionable visibility inside Salesforce. This means empowering real-time threat hunting.
Award-winning anti-malware engines
WithSecure Security Cloud powers File Protection with award-winning anti-malware engines, consistently rated “Best Protection” by AV-TEST. Backed by real-time telemetry from millions of endpoints and cloud systems, it delivers proven accuracy against both common and zero-day malware.
WithSecure™ Security Cloud analyzes over 8 million files per day
The service processes more than 5 billion client requests daily
Algorithms are constantly tweaked by analysts and new threat data
Under the hood: how every file is analyzed
Every file uploaded into Salesforce is inspected through multiple detection layers in the WithSecure Security Cloud. This multi-step process combines speed, depth, and accuracy to stop both common malware and advanced zero-day threats before they spread.
1. Fingerprinting & cache check
Each file gets a unique fingerprint and is matched against an always-updated reputation cache for instant results.
2. Threat intelligence lookup
Unknown files are checked against global threat intelligence drawn from millions of endpoints and cloud systems.
3. Multi-engine scanning
Multiple antivirus engines analyze files in real time, catching both known malware and suspicious patterns.
4. Sandboxing for zero-days
High-risk files run in a secure sandbox where hidden exploits and zero-day threats are exposed safely.
Protection applies across Salesforce Sales Cloud, Service Cloud, Experience Cloud, and Agentforce workflows, covering every file interaction from upload to download.
Certified and audit-ready
Trusted by public sector organizations, Fortune 500 enterprises, and highly regulated industries.




Advanced file security capabilities
Detect and block malicious files across your Salesforce instance
File Protection is a feature of WithSecure Cloud Protection for Salesforce. It scans every file that enters or moves through Salesforce, across Sales Cloud, Service Cloud and Experience Cloud, and including both standard and custom objects.
Files uploaded through forms, cases, portals, emails, APIs or automations are analyzed in real time using multi-engine antivirus, heuristics, and sandboxing behavioral analysis. The NextGen Antivirus for Salesforce detects and blocks malware, ransomware, file type spoofing, and even malicious links hidden inside files – including behind QR codes.
It also covers advanced scenarios such as password-protected archives and large files, ensuring threats are stopped before they reach users or cause disruption.
Integrate real-time threat intelligence
The Security Cloud constantly learns and adapts to emerging threats by harnessing real-time global threat intelligence. It proactively monitors and responds to new threats instantly, ensuring swift and effective protection across all user devices. As the system detects new threats, it updates its database and algorithms continuously. The system updates automatically in the cloud and requires no manual updates.
Additionally, we integrate unique data from our partnerships with Fortune 500 companies to enhance our threat detection capabilities. This collaborative approach enriches our threat database, and as a result provides broader protection in an evolving digital threat landscape.
Detect zero-day threats with behavioral threat analysis
Even if initial scans and reputational checks fail to identify a file as malicious, a suspicious profile triggers a deeper investigation. In such cases, the file goes to a securely isolated sandbox environment in Security Cloud. Security Cloud analyses the file in-depth by performing behavioral assessments. This behavior-based threat analysis identifies even highly sophisticated threats like zero-day malware.
WithSecure™ Cloud Protection for Salesforce governs file sandboxing through a proprietary set of rules designed to optimize threat detection. These rules consider a range of indicators within the files, including behavioral patterns and other suspicious activity.
By combining both static and dynamic analysis in antivirus capabilities, we minimize false positives and ensure accurate threat detection on Salesforce. The result is a comprehensive and nuanced understanding of the sample, which significantly enhances our ability to identify and counteract threats.
Detect malicious QR codes
QR codes embedded in documents and images are inspected for malicious destinations. Obfuscation such as shortened links inside the code is detected and blocked. This closes a growing phishing vector that targets mobile devices and bypasses user training.
Learn more in the dedicated QR code protection page. CThe protection cvers both QR code images and embedded QR codes in other file types like PDFs.
Detect malicious URLs hiding inside files
Attackers hide links in PDFs, Office documents, and other formats. File Protection extracts and evaluates embedded URLs, including those behind redirects or shorteners. Dangerous destinations are blocked before users open or share the file.
These vectors are also a common delivery path for ransomware payloads, which can lock critical Salesforce data and connected systems if not stopped at upload.
Wipe out executables with file type filtering
You can block entire categories of risky formats by extension or true type. Common examples include executables such as EXE and COM, script files such as VBS and PS1, and other high-risk formats. Policies stop these files at upload so they never circulate in Salesforce.
Stop file type spoofing with intelligent file type recognition
Detection looks at the actual file content and structure, not only the extension name of the file. This prevents spoofing where an executable is renamed as a PDF or image. Precision recognition reduces false negatives and closes a common evasion path.
Detect and block out password protected archives
Password-protected archives commonly conceal malware, offering attackers a method to evade scanning by traditional anti-malware solutions like endpoint protection. This poses a significant risk, particularly in highly targeted industries. WithSecure™ Cloud Protection for Salesforce proactively addresses this threat with its advanced feature that detects and blocks password-protected archives in real-time.
These vectors are also a common delivery path for ransomware payloads, which can lock critical Salesforce data and connected systems if not stopped at upload.
Protect large files
Uploads up to 800 MB are supported without degrading user experience. Scanning reaches inside nested archives and container formats to expose hidden malware. This covers for example large media assets used in enterprise workflows.
Max out efficiency with automated threat removal
When a file is confirmed malicious, the upload is blocked immediately. You can replace it with a notice file (.txt) that explains what was stopped and when. Users stay informed and workflows continue, while administrators receive actionable alerts.
Scan in real-time and on-demand
Our real-time protection on Salesforce scans files for threats both when users upload them to the platform, and whenever they download them. With this proactive approach, WithSecure Cloud Protection for Salesforce can effectively block evolving threats such as polymorphic malware types.
Admins can run manual sweeps across existing Salesforce content. Scheduled scans ensure older files and seldom-touched records are re-evaluated under current policies. This reduces residual risk from historical uploads and policy changes.
Stay compliant with strict data handling protocols
User privacy is a top priority for us. Data is anonymized and encrypted in transit and at rest. Personally identifiable information is not required for analysis. Processing can be kept in region with data centers in the EU, US, Australia, Singapore, and Japan to support regulatory needs.
An average enterprise receives millions of files to their Salesforce per year

File Protection helps you close the malware blind spot
Get a Free Demo
THE #1 SALESFORCE MALWARE PROTECTION SOLUTION
Fill the form and get:
Free 15-day trial – test the product without limitations
Real attack simulation and product demo
Free customized and actionable risk assessment