Hello everyone,
I’ve been evaluating Mandiant Threat Intel for the past three weeks, primarily for enhancing our vendor risk assessment workflows and compliance reporting. Overall, the platform’s data has been incredibly valuable for our due diligence templates. However, I’ve run into a persistent and quite frustrating technical hurdle that’s blocking a key deliverable, and I’m wondering if others have experienced the same.
My issue is specifically with the built-in PDF report generator. Whenever I attempt to generate a consolidated report that includes more than, say, 15-20 indicators of compromise (IoCs) along with the associated context and executive summary, the process consistently times out. The interface simply returns a generic error message after about 8-10 minutes, suggesting the request took too long to complete. This happens without fail when the report scope is moderately comprehensive.
For context, my typical process and parameters are:
* **Data Source:** I’m pulling from a saved collection of IoCs related to a specific threat actor group over a 90-day window.
* **Report Template:** Using the “Detailed Technical Summary” template with all default sections enabled.
* **Filters Applied:** I’ve tried both including all data and filtering to only High-Confidence indicators, but the timeout occurs regardless.
* **My Environment:** Corporate network with stable, high-speed internet. I’ve tested from two different machines with the same result.
I’ve done some basic troubleshooting on my end:
* Cleared browser cache and tried Chrome, Firefox, and Edge.
* Attempted the generation at different times of day (early morning, late evening) to rule out potential platform load.
* Verified my account permissions with our admin, and I have the “Analyst” role which should include full report generation rights.
This is becoming a significant bottleneck. From an accounting and audit perspective, having a reliable, self-contained PDF report is non-negotiable for our documentation and compliance folders. Manually screenshotting or copying data into a separate document defeats the purpose of the automation and introduces risk of error.
So my questions for the community are:
* Is this a known limitation or common issue? I couldn’t find any mention of report size limits in the official documentation.
* Has anyone discovered a reliable workaround? For instance:
* Is there a specific, less verbose template that is more stable?
* Should reports be generated in smaller, iterative batches (e.g., by week instead of by quarter)?
* Are there any hidden settings or API parameters that could increase the timeout threshold?
* If this is a widespread problem, has anyone received official guidance from Mandiant support on the matter?
I’m trying to determine if this is an environmental issue on my side, a platform bug, or an intended restriction. Any insights, shared experiences, or steps you’ve taken would be immensely helpful for my evaluation and for documenting this process for my team. Thank you in advance for your time.
Yep, ran into that exact timeout with larger report sets. The generator seems to hit a hard limit on the backend process.
A workaround that worked for us was breaking the collection into smaller, thematic batches - maybe by IoC type or time period - and generating separate PDFs. We then used a simple script to merge them client-side. It's an extra step, but it unblocked our compliance deliveries while we chased support.
Have you checked if there's a pagination or max-items setting hiding in the advanced template options? Sometimes those aren't on by default.
> "The interface simply returns a generic error message after about 8-10 minutes"
That generic error is the real problem. Not the timeout. Mandiant's platform should be telling you exactly what's hitting the limit, not letting you guess. If you're using this for vendor risk assessments and compliance reporting, you're feeding a PDF into an audit trail that can't handle a few hundred IoCs without falling over. That's a red flag for the reliability of the underlying data pipeline, not just the report generator.
You're better off pulling the raw data via API and building your own compliance reports. A static PDF with a timeout limit is a liability in any SOC 2 or ISO 27001 context. If the auditors ask for evidence and you hand them a truncated PDF, what's your fallback?
— geo