Get the catalog of ~78 domain risk rules with criticality levels, entity counts, and MITRE ATT&CK codes.
What this endpoint does
This endpoint returns the complete catalog of risk rules that Recorded Future uses to evaluate domain risk, serving as a reference lookup for valid rule names needed by other domain endpoints. The rule name values returned here are used as filter parameters in the Domain: Search endpoint's riskRule parameter and the Domain Risk List endpoint's list parameter. Each rule maps to specific threat categories such as phishing, C2 infrastructure, typosquatting, malware distribution, or cryptocurrency mining, and is classified into one of four criticality levels: Unusual, Suspicious, Malicious, or Very Malicious.
Response data
The response contains an array of approximately 78 risk rule objects, each with a machine-readable name, human-readable description, criticality level (both label and numeric value 1-4), a count of how many domains currently trigger that rule, and associated MITRE ATT&CK technique or tactic codes. The count field indicates the volume of domains matching each rule, which is useful for gauging the prevalence of different threat types across the Recorded Future domain intelligence dataset.
