You can directly add suspicious objects or import suspicious objects contained in CSV, OpenIOC, and STIX files to the Suspicious Object List.
TrendAI Vision One™ can extract suspicious domains, file SHA-1, file SHA-256, IP addresses, sender addresses,
and URL objects from imported files.
Procedure
- Go to .
- Click Add.
- Select the Method.
-
Wildcards (*) are not supported for domains, URLs, sender addresses, or CIDR IP addresses.
-
The maximum file size for import is 1 MB.
-
Each CSV or OpenIOC file can contain a maximum of 2,000 objects.
-
For STIX files, only versions 2.0 and 2.1 are supported.
-
- Select a risk level.
- Specify the actions that connected products apply after detecting the object.
- Select an expiration option.
- Type a description.
- Click Submit.
Connected products receive the new object information from TrendAI Vision One™ during the next synchronization.
