Get third-party enrichment for an IP from extensions like Shodan, GreyNoise, Censys, or VirusTotal.
What this endpoint does
This endpoint retrieves enrichment data for a specific IP address from a third-party Intelligence Card extension integrated into the Recorded Future platform. Each extension connects to a different threat intelligence or network intelligence provider such as Shodan, GreyNoise, Censys, VirusTotal, or SentinelOne. Most extensions require that your organization has pre-configured credentials for the corresponding third-party service within the Recorded Future platform; without this, requests will return a credentials error. The Shodan extension works without additional configuration and returns geolocation, open port, and vulnerability data. Use the IP Address: Lookup endpoint or IP Address: Search endpoint to obtain IP entity IDs needed for this call.
Response data
The response contains a data object whose structure varies entirely depending on which extension is queried, since each provider returns different intelligence. For example, the Shodan extension returns geolocation (city, country, coordinates), network ownership (organization, ISP, ASN), open ports with service banners and software versions, CVE vulnerabilities detected on the host, and a direct investigation link to the Shodan platform. An optional metadata object provides explanatory annotations about the response fields when requested.
