CTIX
Network live
CTIXPOST

Generate Export File

Source docs
POSThttps://cs-testv2.cyware.com/ctixapi/ingestion/export/

Initiates export of threat data objects to a CSV file based on the CQL input. This API returns a file ID to retrieve the export file download link. You can export a maximum of 100,000 threat data objects in one API request.

The Column Object

Each column object includes the key and value of a column. You can include the following columns in the export file:

TEXT
name
Value


type
Type


tlp
TLP


tags
Tags


sources
Source


source_collections
Source Collection


published_collections
Published Collections


ctix_created
System Created Date


ctix_modified
System Modified Date


country
Country


analyst_score
Analyst Score


source_confidence
Source Confidence

Body Parameters

NameTypeRequiredDescription
formatstringrequired

Pass the export file format. Currently, Intel Exchange supports only the CSV format.

componentstringrequired

Pass the component you want to export.
Currently, Intel Exchange supports only threat_data.

querystringrequired

Pass the CQL query to filter threat data objects.
Tip: You can copy the CQL from the Intel Exchange user interface. Press the following keys to copy the CQL code to use in the API request payload:
Windows: Windows + Shift + C
MacOS: Command + Shift + C

columnsarrayrequired

Pass the list of columns you want to export. For the allowed list of columns, see The Column Object.

Run it

Use the Request parameters panel to enter path IDs, query values, JSON body, and credentials. Then run any snippet below — all languages use the same values. Base URL: https://cs-testv2.cyware.com/ctixapi (change in API Settings).

Playground

Request parameters

Edit values here before running any snippet below (cURL, JavaScript, or Python). Code blocks are reference only — your inputs above are what gets sent.

CTIXConnect to Intel ExchangeRequired to change data
Credentials required for POST

Open API (HMAC signature) · Get credentials from Cyware Admin → Open API → Generate Credentials.

Signature and Expires are generated when you run a request. Access ID and Secret Key stay in memory for this tab only.

Credentials from Authentication auto-fill here for this product. If fields are empty after connecting, refresh this page or open the product docs again.

Request body (JSON)Valid JSON
cURL
curl --request POST \
  --url "https://cs-testv2.cyware.com/ctixapi/ingestion/export/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E" \
  --data '{
  "format": "csv",
  "component": "threat_data",
  "query": "type = \"tool\"",
  "columns": [
    {}
  ]
}'

View-only example — running live API calls requires a role with snippet testing access.

JavaScript
const url = "https://cs-testv2.cyware.com/ctixapi/ingestion/export/?AccessID=%3Cyour%20access%20id%3E&Signature=%3Cyour%20signature%3E&Expires=%3Cyour%20expires%3E";

const response = await fetch(url, {
  method: "POST",
  headers: {},
  body: JSON.stringify({
    "format": "csv",
    "component": "threat_data",
    "query": "type = \"tool\"",
    "columns": [
      {}
    ]
  }),
});

const text = await response.text();
let data;
try { data = JSON.parse(text); } catch { data = text; }
console.log(response.status, data);

View-only example — running live API calls requires a role with snippet testing access.

Python
import requests

url = "https://cs-testv2.cyware.com/ctixapi/ingestion/export/"
params = {
    "AccessID": "<your access id>",
    "Signature": "<your signature>",
    "Expires": "<your expires>"
}
headers = {}
payload = {
  "format": "csv",
  "component": "threat_data",
  "query": "type = \"tool\"",
  "columns": [
    {}
  ]
}
response = requests.request("POST", url, params=params, headers=headers, json=payload)
print(response.status_code)
print(response.text)

View-only example — running live API calls requires a role with snippet testing access.

Request Body
{
  "format": "csv",
  "component": "threat_data",
  "query": "type = \"tool\"",
  "columns": [
    {}
  ]
}

View-only example — running live API calls requires a role with snippet testing access.

Example Response
{
  "details": "Export is in progress. You will receive a notification once the export is complete.",
  "file_id": "48294eb5-ad7a-439e-83e4-d99da6921076"
}

View-only example — running live API calls requires a role with snippet testing access.