Skip to main content

AD_4nXf3pwYpMtYBL8w9-ISSVWRGCaTylBmAH1fKTAun1KaLhvnSoAMpRaZ9uGqorJ-TZyKBWlT0_jrB6mebQFic31oSMczaEosIXvxfwUHD4xeQv8EIFlCSLZMM6JB50peM2i24J5WF4A?key=Qg3yPpBI-usLS4z09NBgXXQs

Netskope Global Technical Success (GTS)

Implement Threat Protection Controls for WhatsApp Web using Netskope RBI

 

Netskope Cloud Version - 122

 

Objective

Implement Threat Protection Controls for WhatsApp Web using Netskope RBI

 

Prerequisite

  • Netskope CASB Inline
  • Netskope RBI (Remote Browser Isolation)
  • Backend Flag - ‘E2E Encrypted Apps: Inspection Through RBI’ needs to be enabled on your Netskope Tenant

 

Context

This document aims to provide a comprehensive guide on implementing Threat Protection controls for WhatsApp Web using Netskope RBI

 

Do You Know?

WhatsApp can be accessed via a web browser or through its native application:

 

WhatsApp Web

  • Netskope acknowledges WhatsApp web as a Cloud Application and provides a pre-defined cloud app connector.
  • As of Jan 15, 2025 with Netskope’s WhatsApp predefined connector, customers can exercise control over the following activities:

Image i

AD_4nXdbjV-N9NEvFIjXdBvJQOS3GTWtwbCM9XOQpDKKggrSN85vE9m0EcE6HEiO6Lak-iuqsP_ofhsM2hCr0dznIEnMNVcx6VkuIa7tdZ5rZayT56XYK1Xi_Kj87jsvttH_SCJ1rtRfTQ?key=Qg3yPpBI-usLS4z09NBgXXQs

  • WhatsApp Web employs end-to-end encryption by default for all activities.
  • At the moment, 'Post' activity detection is not available, which means no DLP & Threat Protection control can be applied when a customer posts a message over WhatsApp Web.

 

WhatsApp Native Application

  • The WhatsApp Windows native app utilizes a non-HTTP protocol for all activities, which means we do not support activity detection for this application.

 

Details

  • Step 1: Create a RBI Template

Path: Netskope Tenant UI >>> Policies >>> Templates >>> RBI >>> New Template

 

Image ii

AD_4nXebpCPINbaNSV9cRizsS7qLYXsruasKRUt64537PSixl56PHROOLb0275i1jZ03LYa6IZuTL1wux7UuI4JSUzXvRE7xDEj9apP8VBhh5Ny_Y5FZzbGax3pA1zSg37fZnA-4g95Xuw?key=Qg3yPpBI-usLS4z09NBgXXQs

 

  • Step 2: Create a Real-time Protection Policy (Threat Policy)

Path: Netskope Tenant UI >>> Policies >>> New Policy

a. For this lab recreation, I am creating the policy shown in Image iii. As per Netskope's recommendation, if you already have a Global Threat Protection policy applied to the web category Chat, IM & Other Communication, this additional policy may not be necessary.

b. The snapshot of the policy I’m referring to is included at the end of this article under Author Notes.

 

Image iii

AD_4nXcFpwaXLfLEASI-4f2Pm1JgqJkLST7OHqUVGEIgqjDBwyimRyyi6z86C_NNPFkjdDcAI5vYlTfhtW67A9li_jovGypcB_dvUlXvNKfDV3XRmgdUX1Dw60qJBz0-8eukd2ysWYCTtg?key=Qg3yPpBI-usLS4z09NBgXXQs

 

  • Step 3: Add another Real-time Protection Policy (RBI Policy)

Path: Netskope Tenant UI >>> Policies >>> New Policy

a. Browser supports ‘Action: Isolate’

Chrome, Firefox, Edge, Opera, Safari, Yandex

 

Image iv

AD_4nXf3K_-bOOhRpBqMS92CcypLn1LDR_xivdl69g8i8jB6DTolaN_3F0OmOpBxkYznmlrkm0PusIcIKtp98jfS9NxGRqppm5tmCeDmGR5Srg2ZkGe3J7xCr7x-eS81dZ7tiytJCm_n?key=Qg3yPpBI-usLS4z09NBgXXQs

 

 

  • Policy Order

Image v

AD_4nXddN65r_9UJY-AvmWn9c_5rgf5r56HsVU49LEiT1xFnni2rLFnPHi4LWCxLvOSW3ufmO-nS38HIjocSPQR2MiwIVpCB605_anPP2DAkElhD8zJ6yXOfMBzaxbbqAcLytItC8o-KBg?key=Qg3yPpBI-usLS4z09NBgXXQs

 

Verification

  • Access WhatsApp Web - https://web.whatsapp.com
  • The Netskope logo will be displayed while loading https://web.whatsapp.com, indicating that RBI is in action.

Image vi

AD_4nXc28nqpo_CY-4cZkswzkG0PfuqPF2ynlYDWXGklY8U-wPtSbsLbxJBxcitpAoH0xASLsJjH9j34HukuuWYuY_olQ7DKGnO32ZbzYV8WcetaiAl07A2fRdP_qobJQv9etrWdbkjhUQ?key=Qg3yPpBI-usLS4z09NBgXXQs

  • For this lab recreation, I downloaded a test malware file from EICAR's official site and shared it with myself using the WhatsApp Native Client. However, when attempting to download the same file via the WhatsApp Web version, the Netskope Threat Engine detected the malware and successfully blocked the download.

EICAR test malware file attached

Image vii

AD_4nXcmbjqWZoBPx5Qp6BVIEahvz3rOuwT2GW4vDs5RXe181aOOItKalbOQcuUSTf5cGHgC8keGxzIkSUcMUSaXQYc2zLP9IHCrrAGzHqPgj-Ydmah7z1VHWRQNugiujzSCnWGuT9yNlw?key=Qg3yPpBI-usLS4z09NBgXXQs

 

  • Let’s review the transactions 

Path: Netskope Tenant UI >>> Skope IT >>> Application Events 

Image viii

AD_4nXcIRoc2FCHDmcBv9aV504biJ1C8JgpGdnKVhdIg_ZpH1hGGtRVnxMjKIxz8F7mIwmkLgiZtHqV4bViG_c-mLrNFR15QhKt1aw1DKBUzMpS3Y2w_GvBqYDwgLqepFfRCyWyxy8mMVA?key=Qg3yPpBI-usLS4z09NBgXXQs

 

Image ix

AD_4nXfKOL3PopSDqyRJ_4gvlAhBt0vps0kA6lsu9JSxbPLJYElUiCovF56eeJTPerx2lYJ7gRMS4l3aEUkuzxJ2EJONWI6fqUsL7ET0BXhOLsy34XIH4i5E1CcSBFtskK4Z56T2FE-HqA?key=Qg3yPpBI-usLS4z09NBgXXQs

 

Image x

AD_4nXfQumNROuL4rTjBmgOrj5eHW3UQwjiGX-_VCI0HDHiIyR4UzkIb1L7ltF7Cm-EDFSubLXKx_DUYhRR1sB-N3n1UwgEb895kSxyqGeATnkrySsxNYfOb_oE3yTh6h8uXIVDbuDjabA?key=Qg3yPpBI-usLS4z09NBgXXQs

 

 

Author Notes

  • Threat Protection can only be applied to the WhatsApp Web version, covering upload and download activities. 'Post' activity detection is not available. 
  • End-to-end traffic encryption can only be decrypted through Netskope RBI (Remote Browser Isolation). While other platforms also use end-to-end encryption, Threat Protection is exclusively available for WhatsApp Web due to current product design.
  • Please note that there is a separate SKU for Netskope RBI. For more information about the SKU, please contact your Netskope Accounts Team.
  • For DLP controls on WhatsApp, kindly review - Link
  • Sample: Netskope Threat Protection Global Policy - Link

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • Netskope Engineering is continuously working on product enhancements. In the future, additional controls may become available to address some of the limitations mentioned earlier. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.


 

What to Read Next?

All about - ‘WhatsApp’

Link

Limitations with Signal Application

Link

Limitations with Telegram (Web Access & Native App)

Link