Export aggregations / commonalities from a threat

🚧

Special privileges required

This endpoint is only available to users with Google Threat Intelligence (Google TI) Enterprise or Enterprise Plus licenses.

Examples

Export commonalities from a threat actor.

import requests import urllib object_id = "threat-actor--bcaaad6f-0597-4b89-b69b-84a6be2b7bc3" format = "csv" url = f"https://www.virustotal.com/api/v3/collections/{object_id}/aggregations/download/{format}" headers = {"accept": "application/json","x-apikey": <api-key>} response = requests.get(url, headers=headers)

Export commonalities from a malware or toolkit.

import requests import urllib object_id = "malware--350aa703-7750-5e07-997b-476375955828" format = "csv" url = f"https://www.virustotal.com/api/v3/collections/{object_id}/aggregations/download/{format}" headers = {"accept": "application/json","x-apikey": <api-key>} response = requests.get(url, headers=headers)

Export commonalities from a campaign.

import requests import urllib object_id = "campaign--24f96f40-b2fa-512c-b1da-2f22a949d12d" format = "csv" url = f"https://www.virustotal.com/api/v3/collections/{object_id}/aggregations/download/{format}" headers = {"accept": "application/json","x-apikey": <api-key>} response = requests.get(url, headers=headers)

Export commonalities from a IoC collection.

import requests import urllib object_id = "alienvault_64edfc5ab93abb1407070292" format = "csv" url = f"https://www.virustotal.com/api/v3/collections/{object_id}/aggregations/download/{format}" headers = {"accept": "application/json","x-apikey": <api-key>} response = requests.get(url, headers=headers)
Path Params
string
required

Threat's ID

string
required

Export format (one of json or csv)

Headers
string
required

Your API key

Responses

Language
Click Try It! to start a request and see the response here! Or choose an example:
application/json