Proteside Docs

Events and detections

The event types the SDK sends, what each one detects, its severity and when it becomes an alert in the dashboard.

The SDK sends the dashboard two kinds of events: detections (something suspicious happened on the page) and telemetry (pageviews, inventory, payment validations). Detections become alerts; telemetry feeds the Scripts inventory, SDK Health and Payment Integrity.

How an event becomes an alert

  • The dashboard sets the severity, not the SDK. The severity reported by the SDK is recorded on the alert as "Severity reported by the SDK". The tables below show the base severity in the dashboard.
  • Repeated events don't create new alerts. While there's an open alert for the same problem (for example, the same script or the same exfiltration destination), new occurrences are added to the existing alert. If the alert was already resolved, a new occurrence opens a new alert.
  • The notification goes out only when the alert is created. Repeated occurrences don't notify again.
  • Scripts that were already in the HTML when the SDK started don't raise a block alert: they show up in Scripts with a note that they keep loading from the HTML.

See how to handle alerts in Alerts.

Calibration

During the first 30 seconds of each page load (adjustable from 10 to 120 s), the SDK learns what's normal on the page. During calibration, these detections stay silent, and whatever shows up becomes part of the page's baseline: SCRIPT_INJECTION, KEYLOGGER_DETECTED, EXFILTRATION_ATTEMPT, WEBSOCKET_EXFILTRATION, FORM_ACTION_HIJACK, OVERLAY_DETECTED and tampering with the text or image of payment codes.

All other detections work from the start, including rule-based blocks, recipient verification, the clipboard and iframes.

Scripts

EventWhat it detectsSeverityAlert
SCRIPT_INJECTIONA new executable script appears after calibration, outside what the page already had. Framework files from the page's own origin (/_next/static/, /_nuxt/ and similar) are ignored.high, adjustedyes
SCRIPT_MODIFIEDA known script reappears with different content. Only when the content can be read (inline script, or external script with CORS enabled).high, adjustedyes
SCRIPT_BLOCKEDA script matched a blocking rule and was stopped.highyes, unless the script was already in the HTML
GTM_CONTAINER_BLOCKEDA Google Tag Manager container or a gtag.js tag outside the Allowed GTM containers list.highyes

Adjusted severity: for SCRIPT_INJECTION and SCRIPT_MODIFIED, the dashboard raises it to critical when the vendor is flagged as a threat in the catalog, lowers it to low when it's a cataloged vendor, and uses medium for first-party scripts and inline scripts. In all other cases, it stays high.

Customer data

EventWhat it detectsSeverityAlert
KEYLOGGER_DETECTEDA script starts listening to keydown, keyup, input, change or paste on a sensitive field after calibration. One event per listener registration.criticalyes
EXFILTRATION_ATTEMPTA request (fetch, XHR, beacon or image) to an untrusted host carries a card number (Luhn-validated), CPF, CNPJ, email address or Pix key. Images with a long query string sent to an untrusted host are reported even without these patterns.adjustedyes
WEBSOCKET_EXFILTRATIONA WebSocket connection to an unknown host after calibration. Messages aren't inspected.criticalyes
FIELD_ACCESSA script registered a listener on a sensitive field. One event per script, field type and listener type.infono

Trusted hosts for exfiltration are: the page's own origin, the Proteside API, known payment providers and analytics tools, and the hosts the page used during calibration. The SDK inspects up to 64 KB of each body and sends only the names of the patterns it found, never the content.

Adjusted severity: exfiltration is critical when the destination is a vendor flagged as a threat or when the body contains a card number, CPF or CNPJ; it's low when the destination is a payment processor or a cataloged vendor; in all other cases, it's high.

Forms, iframes and overlays

EventWhat it detectsSeverityAlert
FORM_ACTION_HIJACKA form's action attribute changed, including on forms created later.criticalyes
OVERLAY_DETECTEDA positioned element (absolute or fixed, z-index above 100) covers the center of a sensitive field or the payment area. Elements with modal, cookie, consent, gdpr, banner, toast, notification or tooltip in their class or id are ignored. Repeats on every check for as long as it persists.highyes
IFRAME_REPLACEDThe address of a known payment provider's iframe changed.highyes
IFRAME_UNEXPECTEDA payment provider iframe outside the Expected iframe origins, or any iframe covering half or more of an expected iframe. Requires the list to be filled in.highyes
CARD_FIELD_OUTSIDE_VAULTA card field you can type into on the main page, outside the provider's iframe. Requires the origin list to be filled in.highyes

Payment

EventWhat it detectsSeverityAlert
PIX_TAMPEREDThe displayed Pix code changed to one that doesn't match the reference, or the recipient isn't among the trusted ones.criticalyes
BOLETO_TAMPEREDThe digit line changed, or the bank isn't among the trusted ones.criticalyes
CRYPTO_ADDRESS_SWAPThe Bitcoin or Ethereum address changed, or isn't among the trusted ones.criticalyes
UPI_TAMPEREDThe UPI code changed, or the VPA isn't among the trusted ones.criticalyes
QR_TAMPEREDThe code for another QR-based method (PayNow, PromptPay, DuitNow, QR Ph, HK FPS, Transferencias 3.0, CoDi or QR wallet) changed, or a QR code image started coming from a different domain.criticalyes
AMOUNT_TAMPEREDThe code's amount differs from the one passed to expectPayment(), or the same recipient appeared with a different amount.criticalyes
CLIPBOARD_HIJACKThe content copied to the clipboard looks like a payment code and doesn't match the reference.highyes
PAYMENT_VALIDATEDA payment code was read and validated. Feeds Payment Integrity.infono

Details in Payment integrity and Pix.

Environment and installation

EventWhat it detectsSeverityAlert
SERVICE_WORKER_BLOCKEDA registered service worker (new or existing) outside the Allowed service workers. Requires the list to be filled in.highyes
SERVICE_WORKER_REGISTEREDAn allowed service worker was registered.infono
INSTALLATION_ORDER_WARNINGThere are scripts before the bootstrapper in the <head>. Not sent if Installation order is set to Silent.mediumyes

Telemetry

These events never become alerts:

EventWhen it's sent
PAGEVIEWOn every page load and every Proteside.pageChanged(). When the SDK is paused, it's the only event sent.
BASELINE_CALIBRATINGWhen calibration starts.
BASELINE_CLASSIFIEDRight after, with the page's script inventory (address, content hash, size and classification).
BASELINE_ESTABLISHEDWhen calibration ends, with the totals it learned.

Generated by the dashboard

Some alerts don't come from an SDK event, but from server-side checks:

AlertSourceSeverity
SCRIPT_INTEGRITY_MISMATCHAn authorized script's content changed compared to the approved hash.high
HEADER_CHANGEDA security header on the payment page changed value.medium
CSP_VIOLATIONA CSP report sent to Proteside points to a host outside the inventory. See CSP and headers.low
SDK_SILENTA domain with history went 24 hours without real sessions. It resolves itself when traffic comes back.medium

Next steps

On this page