Recorded Future

Download 1
Last updated Jan 20, 2026

rf-enrich-hash

Query threat information for a single file hash using Recorded Future API.

Syntax

rf-enrich-hash [profile=PROFILE] value=VALUE
profile=PROFILE
Optional. Recorded Future connect profile code
value=VALUE
Required. File hash to enrich (MD5, SHA1, SHA256)

Output Fields

FieldTypeNameDescription
entityStringEntityFile hash
entity_typeStringEntity Typee.g. Hash
risk_scoreIntegerRisk ScoreOverall risk score (0-99)
risk_levelIntegerRisk LevelOverall risk level (1-4)
c2_scoreIntegerC2 ScoreC2 context score
phishing_scoreIntegerPhishing ScorePhishing context score
public_scoreIntegerPublic ScorePublic threat score
public_ruleStringPublic Rulee.g. Linked to Malware
evidencesListEvidencesEvidence list with keys: signature, rule, level, count, description, mitigation, sightings, timestamp