Act Before the Incident: Process-Aware Policy in Your SWG

October 8, 2026

We are marching towards a tipping point, where agentic transactions outnumber human-originated internet requests. These requests arrive at a volume and velocity no human can match, so defenses need to work at machine scale. For your secure web gateway (SWG) this has implications, creating a need for real-time policy controls that understand both process name (the name of the program or app that is making a request) and parent process name (the program that launched that program). Endpoint tools can detect and terminate a risky process, but only once it is running on the device, and by that time it is too late; the device is already infected.

To solve this, the Netskope Client now passes the process and parent name to the SWG, so inline controls can act before the next process runs, protecting the user, device and data. And process and parent names are now available for Netskope One NG-SWG real-time policy controls and logging, catching rogue scripts and apps trying to access the internet.

 

Why are process and parent process names important information for security policy?

We have all read about the creative ways AI finds to evade detection. For example, SWGs normally bypass personal finance and personal health related web requests in order to preserve employee privacy. This creates a potentially useful covert channel for AI to exploit. What are the normal processes for this traffic for a user, peer groups, and the company, and when does an anomaly process surface in the bypassed traffic?

What about the scenario where you have a software engineer that appears to have exfiltrated a large volume of source code files to personal cloud storage, but claims to know nothing about how it happened? In this case the process and parent process names are helpful for the subsequent investigation too. Was the employee unknowingly the victim of an AI action that targeted them and their compromised cloud storage where unknown prompts, scripts, and processes completed the data exfiltration under cover?

SWG Process Parent Name Diagram

 

Agentic transactions are already here and context, nuance and granularity are all essential for our defenses. Adding process name and parent process name to Netskope One NG-SWG policy controls and logging enables security teams to increase the context available to policy and investigations.

 

How does the SWG capture all the necessary information?

The working relationship between endpoints and SWGs as layered defenses is an important concept to understand, and will be even more so going forward. Integrated insights are key to any security defense, and these new SWG capabilities are possible because it is feeding off the Netskope Client for that vital information. Working in tandem a new set of real-time policy controls and logging opens up:

  • Contextual enforcement: The ability to define Real-Time Protection (RTP) and SSL do-not-decrypt policies that trigger only when a specific process name (for example, curl.exe) or its parent process (for example, powershell.exe) is detected.
  • Deep visibility: Catch rogue scripts or unapproved apps trying to reach the internet, even when their traffic bypasses SWG inspection.
  • Detailed logging: View process and parent process names in Netskope Transaction Events to trace which application on a device generated a specific request.

 

What else helps improve SWG policy controls, in the modern threat landscape?

If you are curious about other modern Next Generation SWG policy controls, here are three more to consider:

  1. Dedicated egress IP addresses enable access to managed SaaS apps only when accessed from a set of unique IP addresses per customer. This blocks the reuse of compromised access credentials, and avoids issues when sharing poor reputation ratings from address pools.
  2. Application instance awareness capabilities understand company versus personal app instances, detecting data exfiltration between those instances, and invoking advanced threat protection, patient zero protection, remote browser isolation, and other defenses. Netskope One NG-SWG covers more than 500 apps by instance, so that (for example) an organization can review all file and data transfers of company data made to personal cloud storage apps by an organization leaver.
  3. Real-time user coaching provides “in the moment” advice to users who may be about to execute a risky transaction, and recommend alternatives.Rather than simply blocking apps and interrupting productivity, teams can deploy user coaching to collect justifications and allow transactions to complete. Real-time user coaching is a continuous loop of feedback for policy refinement.

Netskope One Next-Gen SWG includes all these, and more; including app risk scoring, app activity controls, user risk scoring based on anomalous behaviors, C2 beacon detection based on ML baselines, and traffic packet captures to remove the blind spot of SSE/SASE platforms. If you are considering an upgrade, replacement, or restart for your SWG deployment, please consider Netskope in your evaluation.

author image

Tom Clare

Tom Clare is a Product Marketing Director, his focus at Netskope centers on product strategy with marketing experience in web/cloud proxies, data protection, and more.
Tom Clare is a Product Marketing Director, his focus at Netskope centers on product strategy with marketing experience in web/cloud proxies, data protection, and more.
Keep a close eye on The Lens