Stay current to protect your environment with F5 Hardened Releases.Learn more

F5 Client-Side Defense

F5 Client-Side Defense protects users from malicious JavaScript while enabling PCI DSS 4.0.1 compliance with requirements 6.4.3 and 11.6.1 through real-time script monitoring and integrity enforcement.

Stop client-side attacks before they steal customer data

Modern web applications rely on multiple levels of third-party scripts, creating security blind spots in the browser. F5 Distributed Cloud Client-Side Defense delivers real-time visibility, threat detection, and protection against malicious JavaScript, digital skimming, and data exfiltration while helping organizations meet PCI DSS 4.0.1 requirements.

Block browser-based threats
Mitigate client side threats and ensure PCI DSS compliance

Gain complete script visibility
Inventory, monitor, and validate every script in real time.

Simplify PCI compliance
Support PCI DSS 6.4.3 and 11.6.1 with continuous monitoring.

Mitigate client side threats and ensure PCI DSS compliance

Prevent browser based attacks

Detect and block malicious scripts before data is stolen

Browser-based attacks like Magecart, formjacking, and malicious JavaScript bypass traditional security controls and target customers directly. F5 Distributed Cloud Client-Side Defense continuously monitors runtime activity, detects malicious behavior, and prevents the exfiltration of sensitive data. Protect payment data, PII, and customer trust with real-time client-side protection.

Detect and block malicious scripts before data is stolen

Understand every script

Full visibility and monitoring for all scripts on your page

Gain complete visibility into first-, third-, and fourth-party scripts running in your applications. F5 continuously inventories scripts, monitors runtime behavior, and detects unauthorized changes in real time. With actionable alerts and detailed insights, security teams can quickly identify risks, investigate anomalies, and maintain confidence in application integrity.

Full visibility and monitoring for all scripts on your page

Simplify PCI compliance

Quickly meet PCI DSS browser security requirements

F5 helps organizations address PCI DSS 4.0.1 requirements 6.4.3 and 11.6.1 with continuous script inventory, integrity monitoring, and real-time change detection. Reduce audit complexity, close compliance gaps, and continuously validate your security posture while protecting payment data and supporting modern web applications.

Quickly meet PCI DSS browser security requirements

Core capabilities

Detect malicious scripts

Identify and block harmful JavaScript in real time.

Prevent data exfiltration
Stop payment and customer data theft in browsers.

Monitor script behavior
Continuously track script activity at runtime.

Inventory all scripts
Discover first-, third-, and fourth-party scripts.

Enforce script integrity
Validate trusted scripts against known baselines.

PCI DSS 4.0.1 compliance

Support PCI DSS 6.4.3 and 11.6.1 requirements.

PCI DSS 6.4.3 Support
Maintain script inventory and authorization controls.

PCI DSS 11.6.1 Support
Monitor pages for unauthorized modifications.

Deploy JavaScript to all pages to be protected

Inject the JavaScript

After you add the domains on which to apply protection, you must inject the Client-Side Defense JavaScript on the web pages to be protected.

Inject the JavaScript

Resources

Frequently asked questions

It is a client-side runtime security solution that detects, monitors, and blocks malicious JavaScript to protect against browser-based attacks.

Unlike WAFs and CSPs that lack browser visibility, F5 Client-Side Defense provides continuous runtime monitoring directly in the browser to detect post-deployment script tampering and exfiltration.

It directly supports PCI DSS v4.0.1 requirements 6.4.3 and 11.6.1 by inventorying scripts on payment pages and detecting unauthorized changes in real time.