Get Started with Data Export

Prev Next

Data Export allows Enterprise customers to access, download, and automate the export of threat intelligence data — including historical archives, bulk datasets, IOFA feeds, organization-specific feeds, and IP context insights.

Whether you're conducting in-depth analysis, integrating data with third-party tools, or maintaining compliance, Data Export provides scalable, flexible options in a single centralized location.

Prerequisites

  • Enterprise subscription with appropriate permissions

  • API key for automated exports (see Knowledge Base)

  • Some features require add-ons (e.g., IP Context)

Key Export Categories

Click the Category button at the top of the Data Export page to browse and multi-select categories.

Archive Export

Historical threat data for domains and IPs — ideal for forensic analysis and audit trails.

How to Access: Defend → Data Export → Click Category → Select Archive Export

Bulk Data Export

Large AWS-hosted datasets (New Domains, Nameservers, Mail Servers, etc.).

How to Access: Defend → Data Export → Click Category → Select Bulk Data Export

IOFA Export

Centralized access to all Indicators of Future Attack (IOFA) feeds.

How to Access: Defend → Data Export → Click Category → Select IOFA Export

Organization Export

Central hub for your organization's custom threat indicator feeds.

How to Access: Defend → Data Exports → Click Category → Select Organization Export

Export Options (All Categories)

Automated Export

Click Automate ExportChoose formatCopy API Endpoint (valid for 3 hours) → Use cURL, Python, or PHP snippets.

Manual Download

Click Download File → Select desired format (CSV, JSON, RPZ, STIX, etc.).

Tips

  • Use descriptive names and tags

  • Test API endpoints in your browser first

  • Prefer JSON or CSV for high-volume feeds

  • API URLs expire after 3 hours — schedule pulls accordingly

  • Monitor download credits (especially for Organization Exports)

  • Contact support if expected features are missing