Skip to content
Notifications
Clear all

TIL: You can export chart data from the portal as CSV, it's hidden

1 Posts
1 Users
0 Reactions
24 Views
(@jennyk8)
Estimable Member
Joined: 3 months ago
Posts: 78
Topic starter   [#7337]

Hey everyone, I've been deep in the Mandiant Threat Intel portal this past week building out some internal dashboards and stumbled across a feature that isn't exactly front-and-center, but is a total game-changer for analysts who like to work with the raw data.

I was trying to create a summary view of activity trends over the last quarter, comparing malware family prevalence by region. Manually transposing numbers from the portal charts into my spreadsheet was, as you can imagine, incredibly tedious and error-prone. After some determined poking around, I discovered you can actually export the underlying chart data directly as a CSV. It's not under a prominent "Export" button; you have to hover over the specific chart visualization you're interested in and look for a tiny three-dot menu or a download icon in the upper corner. This exports the precise dataset used to generate that chart.

This is huge for a few reasons, especially for those of us who care about data governance and reproducible reporting:

* **Audit Trails & Custom Dashboards:** You can now pull the clean data directly into Tableau or Power BI to blend it with your internal incident data. This allows for much richer, contextual dashboards than the portal alone can provide.
* **Benchmarking & Historical Analysis:** Having the CSV means you can track changes over time yourself. You're no longer limited to the portal's preset time ranges. Want to compare this month's top threat actors to the same period last year? Just export and analyze.
* **Self-Serve Analytics:** You can empower your security analysts with this data in a format they can manipulate in Excel or their tool of choice without needing to constantly screenshot or manually re-key information.

Here’s a quick comparison of the workflow before and after finding this feature:

| Task | Old Way (Manual) | New Way (CSV Export) |
| :--- | :--- | :--- |
| **Weekly Threat Actor Summary** | Screenshot chart, manually type numbers into report. | Export CSV, link to a live Power BI report that updates with one click. |
| **Calculating Month-over-Month Change** | Note down two numbers, calculate separately. | Export two CSVs, use a simple formula in Excel or a calculated field in Looker. |
| **Sharing Data with Non-Portal Users** | Provide a static image or paragraph summary. | Share a clean data file that can be filtered and sorted as needed. |

The main pitfall is obviously the discoverability. I wish this functionality was more clearly labeled, as it dramatically increases the value of the platform for data-driven teams. It turns the portal from a read-only intelligence feed into a genuine data source.

Has anyone else used this feature? I'm particularly curious if you've found creative ways to blend this exported threat intel data with your internal SIEM or vulnerability data to create risk-prioritized views. Let's share some workflow ideas! 😊

~jenny


Let the data speak.


   
Quote