Enrichment: Field Attributes

The /v2/{entity_type}/fields endpoint returns the list of valid field names that can be passed via the fields query parameter on Search and Lookup requests. This controls which data blocks are included in each entity result.

Supported entity types: ip, domain, hash, url, vulnerability, company, malware


Common Fields

The following fields are available on all entity types (IP, Domain, Hash, URL, Vulnerability, Company, Malware):

FieldDescription
aiInsightsAI-generated risk rule summary
analystNotesRecorded Future threat research notes
countsDaily reference counts
entityName and unique identifier
intelCardIntelligence Card permalink
metricsAggregated recent reference counts
relatedEntitiesLinked entities (threat actors, malware, etc.)
sightingsRecent observed references from categorized sources
timestampsFirst-seen and most-recent reference timestamps

Widely Available Fields

These fields are available on most — but not all — entity types:

FieldIPDomainHashURLVulnerabilityCompanyMalware
riskYesYesYesYesYesYes
riskMappingYesYesYesYesYesYes
enterpriseListsYesYesYesYesYes
linksYesYesYesYesYesYes
threatListsYesYesYesYesYes
  • risk — Risk score, level, evidence details, and triggered risk rules
  • riskMapping — MITRE ATT&CK technique codes mapped from risk rules
  • enterpriseLists — Customer-managed list memberships. Not available for Company.
  • links — Evidence-based indicator linkages. Requires specific access permissions. Not available for Company.
  • threatLists — Current threat list and allow list memberships. Not available for URL.

Entity-Specific Fields

IP Address

FieldDescription
dnsPortCertDNS records, open ports, and SSL/TLS certificate details
locationGeolocation data (country, city, ASN)
riskyCIDRIPsOther risky IP addresses within the same CIDR block
scannerKnown scanner activity associated with this IP
vpnCurrentCurrent VPN associations for this IP
vpnHistoryHistorical VPN associations for this IP
proxyCurrentCurrent proxy associations for this IP
proxyHistoryHistorical proxy associations for this IP

Hash

FieldDescription
fileHashesAssociated file hashes across algorithms (MD5, SHA-1, SHA-256)
hashAlgorithmThe algorithm type of the queried hash

Vulnerability

FieldDescription
commonNamesCommon names / aliases for the vulnerability
cpeCPE (Common Platform Enumeration) identifiers for affected products
cpe22uriCPE 2.2 formatted URI strings
cvssCVSS v2 score and vector
cvssRatingsAggregated CVSS severity ratings
cvssv3CVSS v3 score and vector
cvssv3CnaCVSS v3 score as assigned by the CNA (CVE Numbering Authority)
cvssv3NvdCVSS v3 score as assigned by NVD
cvssv3RfvaCVSS v3 score with Recorded Future Vulnerability Assessment adjustments
cvssv4CVSS v4 score and vector
cvssv4CnaCVSS v4 score as assigned by the CNA
cvssv4NvdCVSS v4 score as assigned by NVD
cvssv4RfvaCVSS v4 score with Recorded Future Vulnerability Assessment adjustments
lifecycleStageCurrent exploit/patch lifecycle stage
linkedMalwareMalware families known to exploit this vulnerability
nvdDescriptionDescription text from the National Vulnerability Database
nvdReferencesReference links from the NVD entry
rawriskUnprocessed risk rule data
relatedLinksExternal reference links associated with the vulnerability

Company

FieldDescription
curatedCurated company intelligence and metadata

Malware

FieldDescription
categoriesCurated set of categories for the malware.