Logo

What are you looking for?

Get help straight from our team...

Do you support XARF?

Cases Management

Do you support XARF?

Last updated on 20 Mar, 2026

XARF (eXtended Abuse Reporting Format) is an open, standardized JSON-based format used to report internet abuse (such as spam, phishing, and malware) between networks and security teams.

We currently support XARF version 4.0.

We support XARF in the following ways:

Import XARF reports

You can import a case from a XARF v4 JSON report:

  1. Select Create Case

  2. Choose Import XARF

  3. Paste the XARF JSON into the text box

  4. Click Validate to verify the JSON

  5. Once validated, select Import Case

Screenshot 2026-03-20 at 10.35.45 pm.png

Once imported:

  1. The domain name, category, and other relevant details are extracted automatically

  2. A new case is created

  3. The Threat Intelligence Feed is set to Manual

  4. The original XARF report is saved in the Case Notes for reference

Viewing an XARF report

You can view or download the XARF report in the Case details. Select XARF in the top bar of a case.

Screenshot_edit.jpg

Sharing an XARF report

You can share a case as a XARF report via email:

  1. Open the case from the Dashboard

  2. Select Notify

  3. Choose an email template

  4. Enable the Attach XARF checkbox (located below the message body)

A default template, “XARF v4 Report”, is also available that includes the XARF report directly in the body of the email

Screenshot_edit3.jpg

Did you find this article helpful?
Previous

How can I add reports from other sources?

Next