Lookup a Malware entity by id by querying an Intelligence Card extension

Get third-party enrichment for a malware entity from Intelligence Card extensions.

What this endpoint does

Retrieves malware enrichment data from a specific third-party intelligence provider integrated into the Recorded Future platform. Requires pre-configured provider credentials — unconfigured providers return 401. Obtain malware entity IDs via Malware: Search or Malware: Lookup.

The extension path parameter must be one of these exact lowercase strings (the prose description uses different capitalization — use these values):

  • reversinglabs — malware classification and sample analysis
  • mandiant — threat actor associations and campaign intelligence
  • xforce — IBM X-Force threat intelligence
  • bitsight — BitSight security ratings
  • facebookte — Facebook Threat Exchange
  • hunter_malware — Hunter malware intelligence

Response data

Returns provider-specific enrichment data — schema varies by provider. Each returns a different intelligence structure depending on their specialty. Returns 401 when provider credentials are not configured for your organization.

Path Params
string
required

Malware entity id

enum
required

Which extension to call

Allowed:
Query Params
enum

Annotates the response with additional metadata explaining the response data elements.

Allowed:
Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json