List URL risk rules

Get the catalog of ~40 URL risk rules with criticality levels, entity counts, and MITRE ATT&CK codes.

What this endpoint does

This endpoint returns the complete set of risk rules used to evaluate URL risk scores. The primary use for this reference data is to obtain valid risk rule names for the riskRule filter in the URL: Search endpoint and the list filter in the URL Risk List download endpoint. There are currently 40 URL risk rules, heavily focused on phishing (detected and suspected techniques), malware distribution, C2 communication, botnet activity, and fraudulent content. This endpoint requires no parameters — it returns all rules in a single response.

Response data

Each risk rule in the response includes its API name (used as a filter value in other endpoints), a human-readable description, a criticality level (Unusual, Suspicious, Malicious, or Very Malicious), the current count of URLs that trigger that rule, and any associated MITRE ATT&CK technique or tactic codes. The entity counts range from zero to over 160 million depending on how broad or specific the rule is — phishing-related rules dominate with the largest counts, reflecting that phishing URLs are the most prevalent URL-based threat in the Recorded Future dataset.

Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json