List Vulnerability risk rules

Get the catalog of vulnerability risk rules with criticality levels, entity counts, and exploitation-focused MITRE ATT&CK codes.

What this endpoint does

Returns the complete set of risk rules used to calculate risk scores for vulnerability entities. It is a reference endpoint with no parameters — call it once to discover all available rule names. The rule name values returned here are the exact filter keys used in the Vulnerability: Search endpoint's riskRule parameter and the Vulnerability: Download Risk List endpoint's list parameter. Rules span several categories including vendor and NIST severity ratings, active exploitation signals (including ransomware and exploit kit linkages), proof-of-concept availability (verified and unverified), Insikt Group reporting, scanner/penetration testing tool uptake, and pre-disclosure signals for CVEs awaiting CVSS scores.

Response data

Returns the full catalog of vulnerability risk rules — effectively the scoring rubric that Recorded Future applies to every CVE. Each rule represents a specific intelligence signal (active malware exploitation, ransomware linkage, PoC availability, NIST severity, etc.) with its own criticality weighting. The count on each rule tells you how many CVEs currently trigger it, which is useful for understanding signal prevalence — a rule with 500 hits is more selective than one with 60,000. Rules also carry MITRE ATT&CK tactic and technique mappings where applicable, letting you align vulnerability prioritization with your threat model. Use the machine-readable name values as filter keys in Vulnerability: Search and Vulnerability: Download Risk List.

Response

Language
Credentials
Header
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json