After obtaining a properly formatted Structured Threat Information Expression (STIX) file (*.xml) from a trusted external source (a security forum or other Deep Discovery Virtual Analyzer product), import the file to Apex Central to extract the suspicious file SHA-1, IP address, URL, and domain objects to the User-Defined Suspicious Object list. When uploading a file, you can also specify the scan action that supported Trend Micro products perform after detecting the suspicious objects.
For more information about manually adding suspicious objects to the User-Defined Suspicious Object list, see Adding Objects to the User-Defined Suspicious Object List.
Apex Central only supports uploading properly formatted STIX files that have *.xml file extensions and conform to the following STIX and Cybox releases:
-
STIX 1.1
-
STIX 1.1.1
-
STIX 1.2
-
Cybox 2.1
Apex Central automatically extracts suspicious objects to the User-Defined Suspicious Object list when the STIX file is imported.