Threat Lookup: Exporting to STIX

Expand all | Collapse all

This section contains examples of STIX files with investigation results for a hash, IP address, domain, and web address.

This format is not available for exporting investigation results for reserved IP addresses.

By default, the format of the file name is as follows: <request type>_<request>_stix.xml

Here:

You can change the file name if necessary.

See a file name result

STIX for a hash

Below is an example of investigation results that Kaspersky Threat Intelligence Portal may return for the hash 495DB359D61411F0688211C8DD473CB7 in STIX format.

See result example

STIX for an IP address

Below is an example of investigation results that Kaspersky Threat Intelligence Portal may return for the IP address 195.175.254.2 in STIX format.

See result example

STIX for a domain

Below is an example of investigation results that Kaspersky Threat Intelligence Portal may return for the domain ddns.net in STIX format.

See result example

STIX for a web address

Below is an example of investigation results that Kaspersky Threat Intelligence Portal may return for the web address go.spaceshipads.com-afu.php-zone in STIX format.

See result example

Below is an example of investigation results that Kaspersky Threat Intelligence Portal may return for the web address 54.171.124.134/upd/updsetup.exe in STIX format.

See result example

Page top