For AI agents: visit https://docs.recordedfuture.com/llms.txt for an index of all pages formatted in Markdown and endpoints in OpenAPI. Append .md to any documentation page URL to get its markdown version.
Jump to Content
Recorded Future
API DocumentationChangelog
Recorded Future
API Documentation

Getting Started

  • Recorded Future API Overview
  • API Entitlements
  • LLM Instructions

Alerts

  • Classic Alerts
    • Fetch alert by idget
    • Fetch a flat collection of hitsget
    • Fetch raw image dataget
    • Search for alertsget
    • Search for alert rules.get
    • Update one or several alertspost
  • Search & Management
    • Search for Playbook Alertspost
    • Preview Playbook Alertget
    • Update Playbook Alertput
    • Available assigneespost
    • Enumerationsget
  • Domain Abuse
    • Detailed Domain Abuse alert datapost
    • Bulk Domain Abuse alert lookuppost
    • Screenshot related to Domain Abuse alertget
  • Malicious Sites
    • Playbook Alerts: Malicious Sites Detailpost
    • Playbook Alerts: Malicious Sites Bulkpost
    • Playbook Alerts: Malicious Sites Screenshotget
    • Playbook Alerts: Malicious Sites Createpost
  • Vulnerability
    • Detailed Vulnerability alert datapost
    • Bulk Vulnerability alert lookuppost
  • Data Leakage on Code Repository
    • Detailed Code Repository Data Leakage alert datapost
    • Bulk Code Repository Data Leakage alert lookuppost
  • Third Party Risk
    • Third Party Risk alert datapost
    • Bulk Third Party Risk alert lookuppost
  • Identity Novel Exposures
    • Detailed Identity Novel Exposures alert datapost
    • Bulk Identity Novel Exposures alerts lookuppost
  • Geopolitics Facility
    • Bulk Geopolitics Facility alerts lookuppost
    • Geopolitics Facility alert datapost
    • Image content by image idget
  • Malware Intelligence
    • Malware Report alert notification data.post
    • Bulk Malware Report alert lookuppost
  • Payment Card Fraud
    • Compromised Bank Checks alert notification data.post
    • Bulk Compromised Bank Checks alert lookuppost
    • Check image by alert idget
  • Dark Web Brand
    • Playbook Alerts: Dark Web Brand Detailpost
    • Playbook Alerts: Dark Web Brand Bulkpost
  • Social Media Impersonation
    • Playbook Alerts: Social Media Impersonation Detailpost
    • Playbook Alerts: Social Media Impersonation Bulkpost
  • Cases
    • Build a Case around a Reference Alert, or a Signal Alertpost
    • Deletes one Casedel
    • Deletes specified Casesdel
    • Lookup of Cases using Case IDspost
    • Lookup a Case using its IDget
    • Searches for any Case matching the criteriapost
    • Update Assignee, Status, Priority, Title or Description of a Caseput
    • Retrieve all eligible assignees for a Casepost

Analyst Notes

  • Configuration
    • Analyst Notes: Available Topics
    • Analyst Notes: Note Attributes
    • Analyst Notes: Serialization Options
  • Search & Lookup
    • Analyst Notes: Searchpost
    • Analyst Notes: Lookuppost
    • Analyst Notes: Attachmentget
    • Analyst Notes: Exportget
  • Publishing
    • Analyst Notes: Draftpost
    • Analyst Notes: Previewpost
    • Analyst Notes: Publishpost
    • Analyst Notes: Deletedel

Attack Surface Intelligence

  • Project
    • ASI Projects: Listget
  • Assets
    • ASI Assets: Searchpost
    • ASI Assets: Findget
    • ASI Assets: Readget
    • ASI Assets: List Exposuresget
    • ASI Assets: Get Filtersget
    • ASI Assets: Apply Tagput
    • ASI Assets: Remove Tagdel
    • ASI Assets: Bulk Add/Remove Tagspost
    • ASI Assets: Get Filtered Filterspost
  • Tagging
    • ASI Tagging: Get Tagsget
    • ASI Tagging: Get Task Statusget
    • ASI Tagging: Bulk Tag Assetspost
    • ASI Tagging: Add Tagpost
  • Exposures
    • ASI Exposures: Listget
    • ASI Exposures: Get Assetsget
  • Rules
    • ASI Rules: Get Static Assetsget
    • ASI Rules: Add Static Assetspost

Autonomous Threat Operations

  • Intelligence Sources
    • Get Sourcesget
    • Create Sourcepost
    • Get Sourceget
    • Update Sourceput
    • Publish Reportspost
  • Threat Hunting
    • Get Pending Jobsget
    • Get Job Indicatorspost
    • Get Job Detection Rulespost
    • Update Job Statuspost
    • Query Profilespost
  • Threat Detection
    • Query Profilespost
    • Get Profile Indicatorspost
    • Get Profile Detection Rulespost
  • Threat Prevention
    • Query Profilespost
    • Get Profile Indicatorspost
    • Get Profile Detection Rulespost

Collective Insights

  • Collective Insights: Overview
  • Detections
    • Submit detected IOCs to the Collective Insightspost
  • Search
    • Search Collective Insights eventspost
  • Exclusions
    • Create an exclusion list itempost
    • List exclusion list items for an organizationget
    • List audit log records for an organization's exclusion listget
    • Delete an exclusion list itemdel
    • Update the comment on an exclusion list itemput

Detection Rules

  • Search & Associations
    • Search Detection Rulespost
    • Associated Entitiesget
    • Associated Entity Typesget

Enrichment and Risk Lists

  • Enrichment: Field Attributes
  • Company
    • Search for Company entities based on a filterget
    • Lookup a Company entity by idget
    • Lookup Company by domainget
    • List Company risk rules.get
  • Domain
    • Search for Domain entities based on a filterget
    • Lookup a Domain entity by idget
    • List Domain risk rulesget
    • Fetch Domain risk listget
    • Stat a domain risk listhead
    • Lookup a Domain entity by id by querying an Intelligence Card extensionget
    • Fetch Domain risk list demo eventsget
  • Hash
    • Search for Hash entities based on a filterget
    • Lookup a Hash entity by idget
    • List Hash risk rulesget
    • Fetch Hash risk listget
    • Stat a hash risk listhead
    • Lookup a Hash entity by id by querying an Intelligence Card extensionget
    • Fetch Hash risk list demo eventsget
  • IP
    • Search for IP Address entities based on a filterget
    • Lookup a IP Address entity by idget
    • List IP Address risk rulesget
    • Fetch IP Address risk listget
    • Stat a IP Address risk listhead
    • Lookup a IP Address entity by id by querying an Intelligence Card extensionget
    • Fetch IP Address risk list demo eventsget
  • Malware
    • Search for Malware entities based on a filterget
    • Lookup a Malware entity by idget
    • Lookup a Malware entity by id by querying an Intelligence Card extensionget
  • URL
    • Search for URL entities based on a filterget
    • Lookup a URL entity by idget
    • List URL risk rulesget
    • Fetch URL risk listget
    • Stat a URL risk listhead
    • Lookup a URL entity by id by querying an Intelligence Card extensionget
    • Fetch URL risk list demo eventsget
  • Vulnerability
    • Search for Vulnerability entities based on a filterget
    • Lookup a Vulnerability entity by idget
    • List Vulnerability risk rulesget
    • Fetch Vulnerability risk listget
    • Stat a Vulnerability risk listhead
    • Lookup a Vulnerability entity by id by querying an Intelligence Card extensionget
    • Fetch Vulnerability risk list demo eventsget

Entity Match

  • Matching & Lookup
    • Matchpost
    • Lookupget
    • Available Entity Types

Fusion

  • File Operations
    • Fetch a feed fileget
    • Upload a feed filepost
    • Delete a feed filedel
  • Directory & Metadata
    • Fetch the content of a directoryget
    • Stat a feed filehead

Identity Intelligence

  • Detections
    • Detectionspost
  • Credentials
    • Searchpost
    • Lookuppost
    • Lookup passwords for exposurepost
    • Hostname Lookuppost
    • IP Lookuppost
    • Incident Reportpost
    • Dump Metadata Searchpost

Links

  • Links
    • Search for linkspost
  • Metadata
    • Technical analysis event typesget
    • Target entity typesget
    • Link sectionsget

Lists

  • Lists: Supported Entities
  • List Management
    • /list/createpost
    • /list/searchpost
    • /list/{listId}/infoget
    • /list/{listId}/statusget
  • Entity Operations
    • /list/{listId}/entitiesget
    • /list/{listId}/entity/addpost
    • /list/{listId}/entity/removepost
    • /list/{listId}/textEntriesget
  • Third Parties Watch List Tags
    • /list/{listId}/entitiesWithTagsget
    • /list/{listId}/entity/tagspost
    • Lists: Available Tags

Malware Intelligence

  • Queries and Reporting
    • Query Malware Intelligence data with query languagepost
    • Query Malware Intelligence data with natural languagepost
    • Query Malware Intelligence data with lists of entitiespost
    • Fetch sandbox reports for a given sha256 hash and querypost
  • Auto YARA
    • Create an Auto YARA jobpost
    • Get all jobs created by userget
    • Edit an Auto YARA jobpost
    • Get result of a jobget
    • Delete a Jobdel
    • Retry a Jobpost
  • Auto Sigma
    • Create a Auto Sigma jobpost
    • Get all jobs created by userpost
    • Get result of a jobget
    • Delete a Jobdel
    • Update a Sigma Rulepost
    • Retry a Jobpost

Payment Fraud Intelligence

  • Data Retrieval
    • Get resulted file for the taskpost
  • Images
    • Create task to prepare bank account images for download.put
    • Create task to prepare checks images for download.put
  • Scanning Queue
    • Adds new domains to the customer specific scanning queuepost
    • Empties the customer specific scanning queuepost
  • Bulk Data Requests
    • Generate and run new a pipeline from bank account preset inputput
    • Generate and run new a pipeline from full card preset inputput
    • Generate and run new a pipeline from partial card inputput
    • Generate and run new a pipeline from partial card sold inputput
    • Generate and run new a pipeline from bank check preset inputput
    • Generate and run new a pipeline from CPP preset inputput
    • Generate and run new a pipeline from magecart domain inputput
    • Generate and run new a pipeline from magecart merchant inputput
    • Generate and run new a pipeline from magescanner scans inputput
    • Generate and run new a pipeline from checker preset inputput
  • Task Management
    • Get tasks in queueget
    • Get task statusdel
    • Get task statusget

Risk

  • Company Risk Rules
    • Get a single active risk rule with enriched evidencepost
  • Risk History
    • Search for risk historypost

Sandbox

  • Environment
    • List geolocationsget
    • List resourcesget
  • Profiles
    • List profilesget
    • Create profilepost
    • Get profileget
    • Update profileput
    • Delete profiledel
  • Submissions
    • List samplesget
    • Submit a samplepost
    • Get sample detailsget
    • Search samplesget
    • Delete a sampledel
    • Set analysis profilepost
  • Streaming
    • Stream all sample eventsget
    • Stream sample eventsget
  • Reports
    • Get static analysis reportget
    • Get dynamic analysis reportget
    • Get overview reportget
    • Get sample summaryget
    • Get URL scan reportget
    • Get URL scan screenshotget
  • Downloads
    • Download original sampleget
    • Download sample archive (TAR)get
    • Download sample archive (ZIP)get
  • Task Artifacts
    • Download task fileget
    • Get behavioral logsget
    • Download PCAPget
    • Download PCAPNGget
  • YARA Rules
    • List YARA rulesget
    • Create YARA rulepost
    • Get YARA ruleget
    • Update YARA ruleput
    • Delete YARA ruledel

SOAR

  • Enrichment & Triage
    • Fetch risk information for a set of indicatorspost
    • Lookup all available risk contextsget
    • Triage multiple IOC entitiespost

STIX TAXII Feeds

  • STIX TAXII: Overview
    • STIX TAXII: 1.x Service
    • STIX TAXII: 2.1 Service
    • STIX TAXII: Collections

Takedowns

  • Takedown API

Threat Maps

  • All Maps
    • Available Threat Mapsget
  • Actors Threat Map
    • Threat Actor Threat Mappost
    • Threat Actor Threat Map for Organizationpost
    • Threat Actor Searchpost
    • Threat Actor Categoriesget
  • Malware Threat Map
    • Malware Threat Mappost
    • Malware Threat Map for Organizationpost
    • Malware Categoriesget

RiskRecon V0

  • IndustryTrends
    • Gets Industry trends data given a TOE idget
  • Portfolio
    • Portfolio member data including company description and domain ratings by security domain. If you are reading this and were filtering by analysis_id, please switch over to TOE_ID at your earliest convenienceget

RiskRecon CPE V0

  • CPE
    • query service by product and version, language and security_criteria using the query paramsget
    • query threat_intel service by ip or host_name using the query paramsget
    • query vulnerabilities by product and version using the query paramget
    • query language and security_criteria using the query paramsget
    • lookup product association with given cvesget

RiskRecon V1

  • Action Plans
    • This resource returns action plan configurations both automated and manual for a given TOE.get
    • This resource sends action plan email to recipients of a TOE.post
    • This resource returns a list of finding details from an action plan of a TOE.get
    • This resource tracks and reports a vendors progress in addressing action plan issues.get
    • This resource returns a vendor's action plan issue summary.get
    • This API returns the count of current action plan issues per their severity and priority.get
    • This API returns the vendor status summary counts of a given action plan.get
  • Alerts
    • This resource returns Alerting Issues from new scans in their portfolio based on the users alert settings.get
    • This resource returns any rating/score changes from new scans in the users portfolio based on the users alert settings.get
  • Analyses
    • :: Legacy Route Please use getToeRatings :: This resource returns the most recent `Analysis` object by the TOE identifier. Trend data is only included if `include_trend` query param is added.get
    • :: Legacy Route Please use getToeRatings :: This resource returns a collection of historical `Analysis` objects by the TOE identifier.get
  • Compliance
    • This resource returns an list of custom and industry standards.get
    • This resource returns risk standard controls associated with a TOE id and a particular custom or industry standard.get
  • Data Loss Events
    • This resource returns a collection of `BreachEvent` objects.get
    • :: Legacy Route :: This resource returns a collection of `DataLossEvent` objects.get
  • Display Name
    • This resource returns a mapping of security_criteria labels and their current display names in the RiskRecon portal.get
    • This resource returns a mapping of security_domain labels and their current display names in the RiskRecon portal.get
  • Findings
    • This resource returns a list of findings for latest analysis for a given TOE.get
    • :: Legacy Route :: This resource returns a list of findings for latest analysis for a given TOE.get
  • Hosts
    • This resource returns a list of Hosts for latest analysis for a given TOE.get
  • Integration Routes
    • The Integration Routes API provides a list of URLs for the security domains within the Security Profile section of the RiskRecon Portal.get
    • The Integration Routes Details API provides a list of URLs for the detailed views within each security domain in the Security Profile and its corresponding risk_dimensions section of the RiskRecon Portal.get
  • Portfolio
    • This endpoint is for requesting to add new TOEs (targets of evaluation) to your portfolio.post
    • This endpoint adds and updates subscription licenses for a TOE.post
    • This resource gets the customer's risk relationship folders names and slugs.get
    • This resource returns the default subscription_level for bulk toe requests for your customer.get
    • This resource sets the default subscription_level for bulk toe requests for your customer.put
  • Subsidiaries
    • This route returns a collection of `Subsidiary` objects associated with a toe.get
  • Target Of Evaluation TOE
    • This resource returns a collection of `TOE` objects mapped to a customer.get
    • This resource gets a `TOE` object by its identifier.get
    • This endpoint adds an existing TOE to the users portfolio.post
    • This endpoint allows a user to update the internal_ids and/or internal_name of an existing `TOE` by its identifier.put
    • This endpoint deletes an existing TOE to the users portfolio.del
    • This resource returns a collection of `TOE` objects mapped to a customer.get
    • This endpoint allows the user to search for a TOE by a valid domain or hostname.get
    • This endpoint allows the user to search for Company name, TOE ID by a valid CVE.get
    • Get the current or historical overall, domain and criteria ratings for a given TOE and a given risk dimension.get
    • This endpoint moves an existing TOE from one risk relationship folder to anotherput
  • Users
    • The User route is used to get all the user data for one’s organization.get
  • TOE Reports
    • This resource allows the ordering and downloading of toe reportspost
    • This resource returns the list of active report request.get
    • This resource returns the PDF report.get
  • Reports
    • Get portfolio ratings reportget
  • Privacy
    • This resource returns a collection of `EnforcementAction` objects.get

RiskRecon V2

  • Finding
    • Streaming Newline delimited JSON response containing findings for latest analysis for a given TOE, security domain and security criteria. Swagger didn't have a way of showing this so please don't let the schema of mislead you with the array of findingsget
    • Streaming Newline delimited JSON response containing findings for latest analysis for a given TOE and security domain. Swagger didn't have a way of showing this so please don't let the schema of mislead you with the array of findingsget
    • Retrieve finding given toe id and finding idget
    • Streaming Newline delimited JSON response containing findings for latest analysis for a given TOE. Swagger didn't have a way of showing this so please don't let the schema of mislead you with the array of findingsget

Search & Metadata

Updated 5 days ago


Recorded Future API Overview
Did this page help you?

Updated 5 days ago


Recorded Future API Overview
Did this page help you?