Recorded Future

Download 1
Last updated Jan 20, 2026

rf-enrich-ip

Query threat information for a single IP address using Recorded Future API.

Syntax

rf-enrich-ip [profile=PROFILE] value=VALUE
profile=PROFILE
Optional. Recorded Future connect profile code
value=VALUE
Required. IP address to enrich

Output Fields

FieldTypeNameDescription
entityStringEntityIP address
entity_typeStringEntity Typee.g. IpAddress
risk_scoreIntegerRisk ScoreOverall risk score (0-99)
risk_levelIntegerRisk LevelOverall risk level (1-4)
c2_scoreIntegerC2 ScoreC2 context score
phishing_scoreIntegerPhishing ScorePhishing context score
public_scoreIntegerPublic ScorePublic threat score
public_ruleStringPublic Rulee.g. Recent Phishing Host
evidencesListEvidencesEvidence list with keys: signature, rule, level, count, description, mitigation, sightings, timestamp