Deep Discovery Inspector

Detect targeted attacks and targeted ransomware
anywhere in the network

Key Features

Monitor everything

Hackers try to exploit unmonitored network ports or use a specific network protocol that isn’t being monitored, but Trend Micro™ Deep Discovery™ Inspector provides 360 degrees of visibility by monitoring all network ports and over 105 different protocols. A single Deep Discovery Inspector appliance monitors East-West traffic (also known as lateral movement) and North-South traffic.

WindowsTM Mac AndroidTM iOS new Power Up

Extensive detection techniques

Deep Discovery Inspector uses XGen™ security, a blend of cross-generational techniques to ensure the highest detection rate with the lowest false positives:

  • Web filtering with URL reputation
  • Local network content correlated with comprehensive threat intelligence
  • Lateral movement detection
  • Behavioral analysis
  • Machine-learning optimized relevance pattern for detecting command-and-control (C&C) behavior
  • Custom sandbox analysis
WindowsTM Mac AndroidTM iOS new Power Up

Custom sandboxing

Custom sandboxes use virtual images to match operating system configurations, drivers, installed applications, and language versions. Difficult for hackers to evade, they include a “safe live mode” to analyze multi-stage downloads, URLs, C&C, and more. Sandboxing is offered as part of an integrated appliance, or as a scalable, stand-alone capability.

WindowsTM Mac AndroidTM iOS new Power Up

Optimized and connected

  • A single appliance monitors all ports and over 105 protocols
  • Centralized visibility and control delivered through Trend Micro Control Manager with prioritized alerting by severity or host
  • Integration with popular SIEMs such as HP Arcsight, IBM QRadar and Splunk
WindowsTM Mac AndroidTM iOS new Power Up


  Model 500/1000 Model 4000
Hardware Model
510/1100 4100
Sandboxes Supported
2 (500), 4 (1000) 20
Form Factor
1U Rack-Mount, 48.26 cm (19") 2U Rack-Mount, 48.26 cm (19")
19.9 kg (43.87 lb) 31.5 kg (69.45 lb)
Dimensions (WxDxH)
43.4 cm (17.09") x 64.2 cm (25.28") x 4.28 cm (1.69") 
48.2 cm (18.98")  x 75.58 cm (29.75”) x 8.73 cm (3.44”) 
Management Ports
10/100/1000 BASE-T RJ45 Port x 1
iDrac Enterprise RD45 x 1
10/100/1000 BASE-T RJ45 Port x 1
iDrac Enterprise RD45 x 1
Data Ports
10/100/1000 BASE-T RJ45 Port x 5
10Gb SFP+ with SX transceiver x 4
10/100/1000 Base-T RJ45 x 5
AC Input Voltage
100 to 240 VAC
100 to 240 VAC
AC Input Current
7.4A to 3.7A
10A to 5A
Hard Drives
2 x 1 TB 3.5" SATA 
4 x 1TB 3.5" NLSAS
RAID Configuration
RAID 1+0
Power Supply
550W Redundant
750W Redundant
Power Consumption (Max.)
847W (Max.)
2133 BTU/hr (Max.)
2891 BTU/hr (Max.)
50/60 Hz
50/60 Hz
Operating Temp.
10-35 °C (50-95 °F)
10-35 °C (50-95 °F)
Hardware Warranty
3 Years
3 Years

Prevent data breaches

Deep Discovery Inspector is available as a physical or virtual network appliance. It’s designed to quickly detect advanced malware that typically bypasses traditional security defences and exfiltrates sensitive data. Using specialised detection engines and custom sandbox analysis, breaches can be detected and prevented.

Gain visibility

Deep Discovery Inspector gives you 360 degrees of visibility that lets you monitor all network ports and over 105 protocols from a single appliance. This visibility lets you monitor East-West, or lateral traffic to detect C&C behavior indicative of a targeted attack. Deep Discovery Inspector provides a single management dashboard for all capabilities, including other Trend Micro security products.

Detect targeted ransomware

Organisations are increasingly becoming victims of targeted ransomware when advanced malware bypasses traditional security, encrypts data, and demands payment to release the data. Deep Discovery Inspector uses known and unknown patterns and reputation analysis to detect the latest ransomware attacks, including WannaCry. The customised sandbox detects mass file modifications, encryption behavior, and modifications to backup and restore processes.

Reduce costs

The Deep Discovery Appliance provides the fastest ROI. A recent study from ESG Group concluded that a typical Deep Discovery Inspector use case yields a 145% ROI, which can be achieved in under 10 months. Existing security investments can be enhanced by the ability to share threat insight and provide an added layer of security.

Simplify your decision

NSS Labs

What customers say

Republic National Distributing Company (RNDC) 

"Trend Micro Deep Discovery is looking at those dark corners of the network to see if there is traffic that deviates from baseline. It gives us visibility into our network, so we can immediately see and shut down anything malicious before it becomes a problem." read more

John Dickson,
Director IT Infrastructure, RNDC

More success stories

Get started with Deep Discovery Inspector

Protect more

Protect more

Deep Discovery Inspector is part of the Network Defence family of network security products including Intrusion Prevention Systems (IPS).  

Deploy Deep Discovery Email Inspector to protect end users from spear phishing attacks, the most common attack vector of targeted attacks and ransomware.

Add sandboxing capabilities to existing security products to detect unknown threats with Deep Discovery Analyser.

Deploy Deep Discovery Inspector to get 360 degree of detection of advanced threats through network monitoring.