---
title: "Fetch Hash risk list"
method: GET
path: "/hash/risklist"
tags: ["Hash"]
---

# Fetch Hash risk list

`GET /hash/risklist`

Download file hashes filtered by risk rule in CSV/Splunk or STIX format for SIEM and EDR integration.

## Query parameters

- `format` 'csv/splunk' | 'xml/stix/1.1.1' | 'xml/stix/1.2' | 'application/stix+json;version=2.1'
- `gzip` boolean
- `list` 'analystNote' | 'default' | 'dhsAis' | 'historicalThreatListMembership' | 'large' | 'linkedToCyberAttack' | 'linkedToMalware' | 'linkedToVector' | 'linkedToVuln' | 'malwareSsl' | 'malwareTestingDetonation' | 'noKnownRisk' | 'observedMalwareTesting' | 'observedTelemetry' | 'positiveMalwareVerdict' | 'recentActiveMalware' | 'relatedNote' | 'rfTrending' | 'suspiciousBehaviorDetected' | 'threatResearcher'

## Response `200`

Result of operation

---

[API](https://skmtc.net/recordedfuture/apis/alert-api.md) · [All operations](https://skmtc.net/recordedfuture/apis/alert-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/recordedfuture/alert-api/revisions/c8c2f68d8b60/schema)
