Get third-party enrichment for a malware entity from Intelligence Card extensions.
What this endpoint does
Retrieves malware enrichment data from a specific third-party intelligence provider integrated into the Recorded Future platform. Requires pre-configured provider credentials — unconfigured providers return 401. Obtain malware entity IDs via Malware: Search or Malware: Lookup.
The extension path parameter must be one of these exact lowercase strings (the prose description uses different capitalization — use these values):
reversinglabs— malware classification and sample analysismandiant— threat actor associations and campaign intelligencexforce— IBM X-Force threat intelligencebitsight— BitSight security ratingsfacebookte— Facebook Threat Exchangehunter_malware— Hunter malware intelligence
Response data
Returns provider-specific enrichment data — schema varies by provider. Each returns a different intelligence structure depending on their specialty. Returns 401 when provider credentials are not configured for your organization.
