List Hash risk rules

Get the catalog of hash risk rules with criticality levels, entity counts, and malware-focused MITRE ATT&CK codes.

What this endpoint does

Returns the complete catalog of risk rules used to evaluate file hash risk scores (~18 rules). Use this as a reference before calling Hash: Search with the riskRule parameter. Hash risk rules are heavily oriented toward malware analysis: sandbox verdicts, active malware indicators, malware family linkage, and behavioral detections. No parameters required.

Response data

Returns every hash risk rule with its name (the API filter value), criticality level, description, and the current count of hashes triggering it — use this to understand which rules are most active and at what severity. The noKnownRisk rule uses "0" as its criticalityLabel rather than a named label like Unusual or Malicious — handle this case explicitly when parsing.

Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json