Export & Sharing

Standardized Threat Intelligence Export

Export indicators in the formats used by government, military, intelligence, and law-enforcement sharing communities. STIX 2.1 and MISP are the interoperable standards for CTI exchange.

Build Export

Pull Endpoints — Every Format

Any format is also a stable URL (schedulable / EDL-pollable). Params: format, type, tlp, limit.

STIX 2.1 bundle
export.php?format=stix&type=ip&limit=5000
MISP event
export.php?format=misp&limit=5000
OpenIOC 1.1 (XML)
export.php?format=openioc&type=domain
CEF (ArcSight/SIEM)
export.php?format=cef&limit=20000
LEEF 2.0 (QRadar)
export.php?format=leef&limit=20000
Zeek/Bro intel
export.php?format=zeek
Snort/Suricata rules
export.php?format=snort&type=ip
Palo Alto EDL (poll)
export.php?format=edl&type=ip&limit=100000
BIND RPZ zone
export.php?format=rpz&type=domain
hosts blackhole
export.php?format=hosts&type=domain
iptables drop script
export.php?format=iptables&type=ip
NDJSON (Elastic)
export.php?format=ndjson
CSV / JSON / XML
export.php?format=csv&type=domain

Also live: TAXII 2.1 server · MISP/RSS feed · REST API · Integrations

Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php