Netskope Threat Labs

EMF file identify

IPS-CFWIPS-SWG

1 SID: 150002

Detects Windows enhanced metafile (EMF) content in transit by its header signature. The rules never alert on their own; they set the file.emf marker so downstream exploit and inspection rules can condition alerts on an EMF file being present in the session, since crafted metafiles have historically reached vulnerable graphics parsers.