Exporting investigation results

Kaspersky Threat Intelligence Portal enables you to export investigation results about requested objects for further analysis. You can export the following data:

You can run another request in a separate browser tab or window while Kaspersky Threat Intelligence Portal prepares and downloads a file with the investigation results of your previous request.

To export all investigation results:

  1. On the Threat Lookup (Lookup.) → Threat Lookup results page, click Export results at the top of the Threat Lookup results page.
  2. In the drop-down list, select the file format that you want to export investigation results to: CSV archive, OpenIOC, or STIX.

    For reserved IP addresses, only CSV archive format is available. The archive will only contain IpProperties.csv and WHOIS.csv files.

    The Save As window opens.

    Preparing a file with all investigation results for download may take several minutes.

    Kaspersky Threat Intelligence Portal exports up to 1000 items from each data group.

  3. Select the location and click Save.

The file with investigation results for the requested object from all available data groups is saved to the specified location.

Detailed information about exporting results in various formats is provided in the following sections in Appendices.

To export investigation results from a selected data group:

  1. On the Threat Lookup (Lookup.) → Threat Lookup results page, click the Download data button near the name of the table that contains data you want to export.

    The Save As window opens.

    Kaspersky Threat Intelligence Portal exports up to 1000 items from a data group.

  2. Select the location and click Save.

    You can change the file name if necessary.

    See a file name example

The archive containing a CSV file with investigation results from the data group is saved to the specified location.

See also

Threat Lookup: Exporting to OpenIOC

Threat Lookup: Exporting to STIX

Page top