The /v2/{entity_type}/fields endpoint returns the list of valid field names that can be passed via the fields query parameter on Search and Lookup requests. This controls which data blocks are included in each entity result.
Supported entity types: ip, domain, hash, url, vulnerability, company, malware
The following fields are available on all entity types (IP, Domain, Hash, URL, Vulnerability, Company, Malware):
| Field | Description |
|---|
aiInsights | AI-generated risk rule summary |
analystNotes | Recorded Future threat research notes |
counts | Daily reference counts |
entity | Name and unique identifier |
intelCard | Intelligence Card permalink |
metrics | Aggregated recent reference counts |
relatedEntities | Linked entities (threat actors, malware, etc.) |
sightings | Recent observed references from categorized sources |
timestamps | First-seen and most-recent reference timestamps |
These fields are available on most — but not all — entity types:
| Field | IP | Domain | Hash | URL | Vulnerability | Company | Malware |
|---|
risk | Yes | Yes | Yes | Yes | Yes | Yes | — |
riskMapping | Yes | Yes | Yes | Yes | Yes | Yes | — |
enterpriseLists | Yes | Yes | Yes | Yes | Yes | — | — |
links | Yes | Yes | Yes | Yes | Yes | — | Yes |
threatLists | Yes | Yes | Yes | — | Yes | Yes | — |
risk — Risk score, level, evidence details, and triggered risk rules
riskMapping — MITRE ATT&CK technique codes mapped from risk rules
enterpriseLists — Customer-managed list memberships. Not available for Company.
links — Evidence-based indicator linkages. Requires specific access permissions. Not available for Company.
threatLists — Current threat list and allow list memberships. Not available for URL.
| Field | Description |
|---|
dnsPortCert | DNS records, open ports, and SSL/TLS certificate details |
location | Geolocation data (country, city, ASN) |
riskyCIDRIPs | Other risky IP addresses within the same CIDR block |
scanner | Known scanner activity associated with this IP |
vpnCurrent | Current VPN associations for this IP |
vpnHistory | Historical VPN associations for this IP |
proxyCurrent | Current proxy associations for this IP |
proxyHistory | Historical proxy associations for this IP |
| Field | Description |
|---|
fileHashes | Associated file hashes across algorithms (MD5, SHA-1, SHA-256) |
hashAlgorithm | The algorithm type of the queried hash |
| Field | Description |
|---|
commonNames | Common names / aliases for the vulnerability |
cpe | CPE (Common Platform Enumeration) identifiers for affected products |
cpe22uri | CPE 2.2 formatted URI strings |
cvss | CVSS v2 score and vector |
cvssRatings | Aggregated CVSS severity ratings |
cvssv3 | CVSS v3 score and vector |
cvssv3Cna | CVSS v3 score as assigned by the CNA (CVE Numbering Authority) |
cvssv3Nvd | CVSS v3 score as assigned by NVD |
cvssv3Rfva | CVSS v3 score with Recorded Future Vulnerability Assessment adjustments |
cvssv4 | CVSS v4 score and vector |
cvssv4Cna | CVSS v4 score as assigned by the CNA |
cvssv4Nvd | CVSS v4 score as assigned by NVD |
cvssv4Rfva | CVSS v4 score with Recorded Future Vulnerability Assessment adjustments |
lifecycleStage | Current exploit/patch lifecycle stage |
linkedMalware | Malware families known to exploit this vulnerability |
nvdDescription | Description text from the National Vulnerability Database |
nvdReferences | Reference links from the NVD entry |
rawrisk | Unprocessed risk rule data |
relatedLinks | External reference links associated with the vulnerability |
| Field | Description |
|---|
curated | Curated company intelligence and metadata |
| Field | Description |
|---|
categories | Curated set of categories for the malware. |