Documentation: https://recordedfuture-professionalservices.github.io/psengine/
Github: https://github.com/RecordedFuture-ProfessionalServices/psengine
PyPi: https://pypi.org/project/psengine/
PSEngine is a simple, yet elegant, library for rapid development of integrations with Recorded Future.
PSEngine allows you to interact with the Recorded Future API extremely easily. There’s no need to manually build the URLs and query parameters, just use the modules dedicated to individual API endpoints.
PSEngine is a Python package solely built and maintained by the Recorded Future Cyber Security Engineering team powering a number of high profile integrations, such as: PS Banshee; Recorded Future Alerts for QRadar; Anomali ThreatStream: Alerts and Analyst Notes integrations; Google SecOps and many more.
Installation
PSEngine is a Python package that can be installed using pip. To install PSengine, run the following command:
pip install psengine
PSEngine officially supports Python >= 3.10, < 3.15.
Supported Features & Best Practices
PSEngine is ready for the demands of building robust and reliable integrations.
It can easily interact with the following Recorded Future datasets:
- Analyst Notes
- Attack Surface Intelligence
- Collective Insights
- Classic & Playbook Alerts
- Detection Rules
- Fusion File management
- Identity Exposures management
- List management
- Malware Intelligence (including Auto Yara and Auto Sigma)
- Malware Sandbox reports download
- On demand IOC enrichment
- Risklists
- Risk History
- Sandbox Detonation of files and URLs
- STIX conversion
And facilitate the development with features like:
- Built-in logging
- Easy configuration management
- Markdown creation from certain data types
- Proxy support
Previous versions and version documentation
PSEngine has been made public from our internal version 2.0.4. Previous versions, including version 1, are not publicly available.
The documentation arrived at version 2.1.1. Older versions are not explicitly documented and changes can be found in the Release History section.
Release files for psengine 2.10.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| psengine-2.10.1.tar.gz | 180.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| psengine-2.10.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 503.8 kB
Release files / psengine-2.10.1.tar.gz
| Download URL | psengine-2.10.1.tar.gz |
|---|---|
| Size | 180.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
da3105318c551b345a2b9c2799cec281952f9861165a187f58d47d0ca654b278
|
|
BLAKE2b-256 checksum How to use checksums |
bbc60336e6659eda0f45d90d2fba60b3e15e31cf596a371ede2ee73edba62118
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.
Transparency logRelease files / psengine-2.10.1-py3-none-any.whl
| Download URL | psengine-2.10.1-py3-none-any.whl |
|---|---|
| Size | 323.8 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c0db598ed7f237f0f41e415a497cb3c3fc414b7b4c26ddc4be7fec001ed40120
|
|
BLAKE2b-256 checksum How to use checksums |
30439ca30ad5479d6eb75536f0000e83a444e29b703f847eb1d81588a2e7bbde
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 14, 2026.
Transparency log