Deep Discovery Inspector provides two types
of file submission rules. Each rule type requires a specific set of criteria.
-
Basic: Checks files based on detection type and other properties
-
Advanced: Checks files based on detection rules and other properties
Select the following optional criteria when creating basic or advanced file submission
rules.
-
Protocol
-
Common Internet File System (CIFS)
-
File Transfer Protocol (FTP)
-
Hypertext Transfer Protocol (HTTP)
-
Instant Messaging (IM)
-
Internet Message Access Protocol (IMAP)
-
Post Office Protocol 3 (POP3)
-
Simple Mail Transfer Protocol (SMTP)
-
-
File TypeOptionFile TypeExample File Extensions7zip7-zip archive.7zALZALZip compressed file.alzBZIP2BZIP2 archive.bz2CHMCompiled HTML (CHM) help file.chmEGGALZip archive file.eggELFExecutable and Linkable Format binary file.elfJARJava™ Archive.jarJava AppletJava™ class file.classLNKMicrosoft™ Windows™ Shell Binary Link shortcutMicrosoft™ Windows™ 95/NT shortcut.lnkMach-O
Mach-O x86/x64 No extension for most executablesMac OS X Installer PackageMac OS X Installer Package.pkgOFFICEMicrosoft Office file.doc.docx.ppt.pptx.xls.xlsxOpenDocumentOpen Document file.odt.odp.odsPDFAdobe™ Portable Document Format (PDF).pdfRARRAR archive.rarSWFAdobe™ Shockwave™ Flash file.swfTARTAR archive.tarWIN_EXEWindows executable file.exeZIPPKWARE PKZIP archive (ZIP).zip
Note
To submit Mac OS X Installer Packages, you must select Mac OS X Installer Package for the File Type option and specify pkg for the File Extension option. -
File ExtensionType one or more file extensions. Separate multiple entries with a comma (,).
-
File SizeSpecify a value that is less than or equal to the maximum file size configured at .
-
Direction
-
Internal hosts: Hosts in monitored networks
-
External hosts: Hosts outside the network
-
-
Src / Dest IP
-
All
-
Specific IP address
-
IP address from any monitored network group
-
-
URLType up to 20 URLs. Separate multiple entries with a comma (,).Syntax: [http://]<Domain>[:<Port>][/<URI-prefix>]
-
[http://]Accepted and ignored
-
<Domain>Wildcards (*) are only allowed in a prefix. When a wildcard is used in a prefix, it must be connected with ". ". Only one wildcard may be used in a domain.
-
[:<Port>](Optional) If unassigned, the default is ":80" (Port 80).Assign a specific port with a whole number between 1 and 65,535, or use a wildcard (*) to assign all ports.
-
[/<URI-prefix>](Optional) If unassigned, the default is a wildcard that matches all paths.Use "/" and "/*" to match a URL without a path.Example:
www.abc.com/*matcheswww.abc.com[/<URI-prefix>] is always applied as a prefix matching. Only one wildcard is accepted in a prefix.URI matching is not case-sensitive.

Tip
If you add URL criteria, Trend Micro recommends also adding a new criteria for Protocol. For example, add HTTP or email related protocols. -
