Get third-party enrichment for a URL from extensions like VirusTotal, Kaspersky, or Mandiant.
What this endpoint does
This endpoint retrieves enrichment data for a specific URL from a third-party Intelligence Card extension integrated into the Recorded Future platform. Available extensions for URL entities include VirusTotal, Kaspersky, Mandiant, InQuest, and others, with 12 extensions total. Most extensions require that your organization has pre-configured credentials for the corresponding third-party service within the Recorded Future platform. The report_website and inquest extensions work without additional configuration — report_website returns links for reporting the URL to abuse and takedown services, while inquest returns aggregated OSINT reputation data. The URL entity ID must be URL-encoded in the path (e.g., url:http%3A%2F%2Fexample.com%2Fpath); use the URL: Search endpoint to find URL entity IDs.
Response data
The response contains a data object whose structure varies entirely depending on which extension is queried, since each provider returns different intelligence. For example, the report_website extension returns categorized links for reporting the URL to services like Symantec, PhishTank, and Google Safe Browsing, as well as takedown request links for Recorded Future and Phishfort. The inquest extension returns an overview with hit counts across InQuest Labs' reputation database (Rep-DB), deep file inspection results (DFI), and social media intelligence database (IOC-DB). An optional metadata object provides explanatory annotations when requested.
