Data Export allows Enterprise customers to access, download, and automate the export of threat intelligence data — including historical archives, bulk datasets, IOFA feeds, organization-specific feeds, and IP context insights.
Whether you're conducting in-depth analysis, integrating data with third-party tools, or maintaining compliance, Data Export provides scalable, flexible options in a single centralized location.
Prerequisites
Enterprise subscription with appropriate permissions
API key for automated exports (see Knowledge Base)
Some features require add-ons (e.g., IP Context)
Key Export Categories
Click the Category button at the top of the Data Export page to browse and multi-select categories.
Archive Export
Historical threat data for domains and IPs — ideal for forensic analysis and audit trails.
How to Access: Defend → Data Export → Click Category → Select Archive Export
Bulk Data Export
Large AWS-hosted datasets (New Domains, Nameservers, Mail Servers, etc.).
How to Access: Defend → Data Export → Click Category → Select Bulk Data Export
IOFA Export
Centralized access to all Indicators of Future Attack (IOFA) feeds.
How to Access: Defend → Data Export → Click Category → Select IOFA Export
Organization Export
Central hub for your organization's custom threat indicator feeds.
How to Access: Defend → Data Exports → Click Category → Select Organization Export
Export Options (All Categories)
Automated Export
Click Automate Export → Choose format → Copy API Endpoint (valid for 3 hours) → Use cURL, Python, or PHP snippets.
Manual Download
Click Download File → Select desired format (CSV, JSON, RPZ, STIX, etc.).
Tips
Use descriptive names and tags
Test API endpoints in your browser first
Prefer JSON or CSV for high-volume feeds
API URLs expire after 3 hours — schedule pulls accordingly
Monitor download credits (especially for Organization Exports)
Contact support if expected features are missing