Microsoft Defender Threat Intelligence
General

Sorting Filtering And Downloading Data

In brief

The how-to article covering sorting, filtering, and downloading Defender TI data was deleted. Its notice states that Defender TI will be discontinued and merged into Microsoft Defender, with current access continuing until August 1, 2026.

What Defender admins need to know

Administrators may no longer find this workflow documentation and should account for the stated retirement timeline.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

deleted file mode 100644

title: 'Sorting, filtering, and downloading data using Microsoft Defender Threat Intelligence (Defender TI)' description: 'Learn how to sort, filter, and download data using Microsoft Defender Threat Intelligence (Defender TI).' ms.topic: how-to ms.date: 09/12/2025 ms.custom:

  • template-overview
  • cx-ti
  • cx-mdti

Sorting, filtering, and downloading data

Microsoft Defender Threat Intelligence (Defender TI) lets you access our vast collection of crawling data in an indexed and pivot table format. These data sets can be large, returning expansive amounts of historic and recent data. By letting you appropriately sort and filter the data, we help you surface the connections of interest easily.

In this how-to article, you learn how to sort and filter data for the following data sets:

  • Resolutions
  • WHOIS information
  • Certificates
  • Subdomains
  • Trackers
  • Components
  • Host pairs
  • Cookies
  • Services
  • Domain Name System (DNS)
  • Reverse DNS

:::image type="content" source="/defender/threat-intelligence/media/data-sets-01.png" alt-text="Sorting data sets screenshot." lightbox="/defender/threat-intelligence/media/data-sets-01.png":::

Learn more about data sets

You also learn how to download indicators or artifacts from the following features:

  • Projects
  • Articles
  • Data sets

Prerequisites

Open Defender TI in the Microsoft Defender portal

  1. Access the Defender portal and complete the Microsoft authentication process. Learn more about the Defender portal
  2. Navigate to Threat intelligence > Intel explorer.

Sorting data

The sorting function on each data tab lets you quickly sort our data sets by the column values. By default, most results are sorted by Last seen (descending) so that the most recently observed results appear at the top of the list. This default sorting order immediately provides insight on the current infrastructure of an artifact.

Currently, all data sets are sortable by the following First seen and Last seen values:

  • Last seen (descending) - Default
  • Last seen (ascending)
  • First seen (ascending)
  • First seen (descending)

Data can be sorted across each data set tab for each IP, domain, or host entity that is searched or pivoted on.

  1. Search a domain, IP address, or host in Intel explorer search bar.

  2. Go to the Resolutions tab, then apply the sorting preferences to the First seen and Last seen columns.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-first-seen-last-seen.png" alt-text="Sorting Resolutions." lightbox="/defender/threat-intelligence/media/data-sets-first-seen-last-seen.png":::

Filtering data

Data filtering lets you access a select group of data based on a particular metadata value. For instance, you can choose to view IP resolutions discovered from a select source only, or components of a particular type (for example, servers or frameworks). Data filtering enables you to narrow the query results to items of particular interest.

Because Defender TI provides specific metadata that coincides with particular data types, the filter options are different for each data set.

Resolution filters

The following filters apply to resolution data:

  • System tag: Defender TI creates these tags based on insights discovered by our research team. Learn more
  • Tag: Custom tags that Defender TI users applied. Learn more
  • ASN: Results that relate to a designated autonomous system number (ASN).
  • Network: Results that relate to designated network.
  • Source: The data source that produced the result (for example, riskiq, emerging_threats).

To filter resolution data:

  1. Search a domain, IP address, or host in the Intel explorer search bar.

  2. Go to the Resolutions tab

  3. Apply filters to each of the types of filter options noted previously.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-resolutions.png" alt-text="Filters Resolutions." lightbox="/defender/threat-intelligence/media/data-sets-resolutions.png":::

Tracker filters

The following filters apply to tracker data:

  • Type: The identified tracker type for each artifact (for example, JarmFuzzyHash or GoogleAnalyticsID).
  • Address: The IP address that directly observed the tracker or has a resolving host that observed the tracker. This filter appears when you search an IP address.
  • Hostname: The host that observed this tracker value. This filter appears when you search a domain or host.

To filter tracker data:

  1. Search a domain, IP address, or host in the Intel explorer search bar.

  2. Go to the Trackers tab

  3. Apply filters to each of the types of filter options noted previously.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-trackers.png" alt-text="Filters Trackers." lightbox="/defender/threat-intelligence/media/data-sets-trackers.png":::

Component filters

The following filters apply to component data:

  • Ipaddressraw: The IP address that coincides with the returned hostname.
  • Type: The designated component type (for example, remote access or operating system).
  • Name: The name of the detected component (for example, Cobalt Strike or PHP).

To filter component data:

  1. Search a domain, IP address, or host in the Intel explorer search bar.

  2. Go to the Components tab

  3. Apply filters to each of the types of filter options noted previously.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-components.png" alt-text="Filters Components." lightbox="/defender/threat-intelligence/media/data-sets-components.png":::

Host pair filters

The following filters apply to host pair data:

  • Direction: The direction of the observed connection, indicating whether the parent redirects to the child or the other way around.
  • Parent hostname: The hostname of the parent artifact.
  • Cause: The detected cause of the host parent-child relationship (for example, redirect or iframe.src).
  • Child hostname: The hostname of the child artifact.

To filter host pair data:

  1. Search a domain, IP address, or host in the Intel explorer search bar.

  2. Go to the Host pairs tab

  3. Apply filters to each of the types of filter options noted previously.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-host-pairs.png" alt-text="Filters Host pairs." lightbox="/defender/threat-intelligence/media/data-sets-host-pairs.png":::

DNS and reverse DNS filters

The following filters apply to DNS and reverse DNS data:

  • Record Type: The type of record detected in the DNS record (for example, NS or CNAME).
  • Value: The designated value of the record (for example, nameserver.host.com).

To filter DNS and reverse DNS data:

  1. Search a domain, IP address, or host in the Intel explorer search bar.

  2. Go to the DNS and Reverse DNS tabs

  3. Apply filters to each of the types of filter options noted previously.

    :::image type="content" source="/defender/threat-intelligence/media/data-sets-dns.png" alt-text="Filters DNS." lightbox="/defender/threat-intelligence/media/data-sets-dns.png":::

Downloading data

There are various sections in Defender TI where you can export data as a CSV file. Look out for and select Download Download icon in the following sections:

  • Most data set tabs
  • Projects
  • Intel articles

When you download data from the Resolutions, DNS, and Reverse DNS the following headers are exported:

HeaderDescription
ResolveA record associated with the domain searched (resolving IP address) or domain that resolves to an IP address when the IP address is searched
LocationCountry or region the IP address is hosted in
NetworkNetblock or subnet
autonomousSystemNumberASN
firstSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft first observed the resolution
lastSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft last observed the resolution
SourceSource that observed this resolution
TagsSystem or custom tags associated with the artifact

When you download data from the Subdomains tab, the following headers are exported:

HeaderDescription
hostnameSubdomain of the domain searched
tagsSystem or custom tags associated with the artifact

When you download data from the Trackers tab, the following headers are exported:

HeaderDescription
hostnameHostname that observed or is currently observing the tracker
firstSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft first observed the hostname was using the tracker
lastSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft last observed the hostname was using the tracker
attributeTypeTracker type
attributeValueTracker value
TagsSystem or custom tags associated with the artifact

When you download data from the Components tab, the following headers are exported:

HeaderDescription
hostnameHostname that observed or is currently observing the component
firstSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft first observed the hostname was using the component
lastSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft last observed the hostname was using the component
categoryComponent type
nameComponent name
versionComponent version
TagsSystem or custom tags associated with the artifact

When you download data from the Host pairs tab, the following headers are exported:

HeaderDescription
parentHostnameThe hostname that is reaching out to the child hostname
childHostnameThe hostname that is feeding assets they host to the parent hostname.
firstSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft first observed the relationship between the parent and child hostname
lastSeenDate and time (in mm/dd/yyyy hh:mm format) when Microsoft last observed the relationship between the parent and child hostname
attributeCauseThe cause of the relationship between the parent and child hostname
TagsSystem or custom tags associated with the artifact

When you download data from the Cookies tab, the following headers are exported:

HeaderDescription
hostnameHostname that observed the cookie name
firstSeenDate and time (in mm/dd/yyyy hh:mm format) when the cookie name was first observed to the hostname originating from the cookie domain
lastSeenDate and time (in mm/dd/yyyy hh:mm format) when the cookie name was last observed to the hostname originating from the cookie domain
cookieNameCookie name
cookieDomainThe domain name's server the cookie name originated from
TagsSystem or custom tags associated with the artifact

When you download project lists from Intel projects (My projects, Team projects, and Shared projects), the following headers are exported:

HeaderDescription
nameProject name
artifacts (count)Artifact count within the project
created by (user)User who created the project
created onWhen the project was created
tagsSystem or custom tags associated with the artifact
collaboratorsWho were added as collaborators to the project; this header is only visible for projects downloaded from the My projects and Shared projects pages

When you download project details (artifacts) from a project, the following headers are exported:

HeaderDescription
artifactArtifact value (for example, IP address, domain, host, WHOIS value, or certificate SHA-1)
typeArtifact type (for example, IP, domain, host, WHOIS organization, WHOIS phone, or certificate SHA-1)
createdDate and time (in mm/dd/yyyy hh:mm format) when the artifact was added to the project
creatorEmail address of user who added the artifact
contextHow the artifact was added to the project
tagsSystem or custom tags associated with the artifact
collaboratorsWho were added as collaborators to the project; this header is only visible for projects downloaded from the My projects and Shared projects pages

Downloading threat intelligence public or riskiq indicators exports the following headers:

HeaderDescription
typeIndicator type (for example, IP address, certificate, domain, or SHA-256)
valueIndicator value (for example, IP address, domain, or hostname)
sourceIndicator source (RiskIQ or OSINT)

See also