Configuring Suspicious Object Settings

Trend Micro Control Manager consolidates and synchronizes the Virtual Analyzer and user-defined suspicious object lists with Trend Micro Email Security. Enable this feature to implement the lists during scanning.

Before you begin configuring this feature, make sure that:

  • You have installed Control Manager 7.0 with hot fix HF2964, and your Control Manager has a serving Deep Discovery product, which can be a Deep Discovery Inspector, Deep Discovery Email Inspector, or Deep Discovery Analyzer.

  • Your Trend Micro Email Security has been registered to a required Trend Micro Control Manager.

  • You have enabled Web Reputation settings in the spam policy you want to apply the suspicious URL list to.

  1. Go to Administration > Suspicious Objects.
  2. Select the Enable check box to enable this feature.
  3. Under Security Level for Files, specify the security level for files to determine whether to take actions on the files:
    • High: Applies actions on files that exhibit any suspicious behavior.

    • Medium: Applies actions on files that have moderate to high probability of being malicious.

    • Low: Applies actions on files have high probability of being malicious.

    Suspicious URLs are detected during Web Reputation scanning. Therefore, when you configure Web Reputation settings in your spam policy, specify the security level to determine whether to take actions on the URLs.

    Note:

    Trend Micro Email Security classifies all files and URLs in the user-defined suspicious object lists as the "High" risk.

  4. Check additional information about suspicious object list synchronization from the Control Manager.
  5. Click Save.