Download domains filtered by risk rule in CSV/Splunk or STIX format for SIEM and firewall integration.
What this endpoint does
This endpoint downloads a bulk file of domains, designed for integration into SIEMs, firewalls, proxy servers, and threat intelligence platforms. By default it returns the "default" risk list, which surfaces higher-scoring (Malicious-tier and above) domains; use the list parameter with a risk rule name to filter to domains that trigger that specific rule. You can filter by any of approximately 70 risk rules such as recently detected phishing sites, botnet domains, C2 nameservers, or typosquatting domains—use the Domain Risk Rules endpoint to retrieve the full list of valid rule names and their descriptions. The output is available in CSV/Splunk (default), STIX 1.1.1, STIX 1.2, or STIX 2.1 formats. Use the companion HEAD Domain Risk List endpoint to check file metadata and ETags before downloading, which is useful for polling workflows that only fetch updated lists.
Response data
The response is a binary file download (not JSON). In the default CSV/Splunk format, each row contains a domain name, its composite risk score, a risk string showing the ratio of triggered to total rules, and a JSON-encoded evidence details field. The evidence details break down every triggered risk rule with human-readable descriptions, criticality levels, source counts, sighting counts, and timestamps. When using STIX output formats, the same intelligence is structured as STIX indicators and observables suitable for automated threat intelligence sharing.
