Deep Discovery Director (DDD), from version 3.0, has ability to do suspicious objects synchronization among managed Deep Discovery products.
Deep Discovery appliances (DDI 5.1, DDAN 6.1 and DDEI 3.1) will no longer synchronize suspicious objects with Control Manager (TMCM) after they are managed by DDD 3.0.
If you use both DDD and TMCM, you must update your TMCM server to version 7.0 with the hot fix to synchronize the consolidated list of suspicious objects from DDD instead of from individual Deep Discovery appliances.
This article will show you how to register DDD into TMCM, with TMCM as the suspicious object source.
To help other Trend Micro products which are integrated with TMCM get consolidated suspicious object list from DDD, applying TMCM 7.0 Patch 1 with the corresponding hot fix is needed.
TMCM 7.0 Patch 1 can be downloaded from the Download Center.
For the hot fix information, contact Trend Micro Technical Support.
After applying the TMCM patch and hot fix, do the following to complete the registration flow:
On the TMCM web console, go to Administration > Managed Servers > Server Registration.
Choose Deep Discovery Directoras the Server Type.
Click Add then key in all DDD related information.
After registering, TMCM will issue the following requests to DDD every 10 minutes:
- Upload Virtual Analyzer Suspicious Object (VASO) to TMCM.
- Push full exception list if there is an item changed (eg: Add/Delete from TMCM console).
As for the User-Defined Suspicious Object (UDSO), DDD will download them every 30 seconds.