Lookup a Malware entity by id

Get full malware enrichment including classification, MITRE ATT&CK mappings, and threat actor associations.

What this endpoint does

Retrieves enrichment data for a specific malware family or tool (e.g., AsyncRAT, Cobalt Strike, Emotet) by its Recorded Future entity ID. Malware IDs are opaque alphanumeric strings — obtain them via Malware: Search using a freetext query. Unlike IOC entity types, malware entities do not have risk scores — the risk field returns no data. Use categories for classification labels (e.g., "Remote Access Trojan"), aiInsights for analysis, links for MITRE ATT&CK mappings and actor associations, and intelCard for the portal URL. For third-party provider enrichment, use Malware: Lookup Extension.

Response data

Returns the enrichment sections you requested for the malware family — classification categories, analyst insights, technique/actor relationships, or Intel Card links. Single-entity lookup, no pagination.

Path Params
string
required

Malware entity id

Query Params
string

The enrichment fields requested for the entities returned. Several fields can be given as a comma separated string.

See https://docs.recordedfuture.com/reference/enrichment-field-attributes for a list of values.

enum

Annotates the response with additional metadata explaining the response data elements.

Allowed:
boolean

Enable or disable entity tags in text fragments

string
deprecated
Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json