Recorded Future v2
Unique threat intel technology that automatically serves up relevant insights in real time.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- RecordedFuture
Configuration parameters
- server_url — Server URL (e.g., https://api.recordedfuture.com/gw/xsoar/) (required)
- token — API Token
- token_credential —
- file_threshold_suspicious — File Suspicious Threshold
- file_threshold — File Malicious Threshold
- cve_threshold_suspicious — CVE Suspicious Threshold
- cve_threshold — CVE Malicious Threshold
- ip_threshold_suspicious — IP Suspicious Threshold
- ip_threshold — IP Malicious Threshold
- domain_threshold_suspicious — Domain Suspicious Threshold
- domain_threshold — Domain Malicious Threshold
- url_threshold_suspicious — URL Suspicious Threshold
- url_threshold — URL Malicious Threshold
- vulnerability_threshold — Vulnerability Threshold
- collective_insights — Collective Insights (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- rule_names — Rule names to fetch alerts by
- fetch_statuses — Alert Statuses to include in the fetch
- update_status — Update alert status on fetch.
- first_fetch — First fetch time
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- integrationReliability — Source Reliability
- feedExpirationPolicy —
- feedExpirationInterval — Incidents Fetch Interval
- incidentFetchInterval — Incidents Fetch Interval
Commands (18)
- cve — Gets a quick indicator of the risk associated with a CVE.
- domain — Gets a quick indicator of the risk associated with a domain.
- file — Gets a quick indicator of the risk associated with a file.
- ip — Gets a quick indicator of the risk associated with an IP address.
- recordedfuture-alert-rules — Search for alert rule IDs. Deprecated: use rf-alerts from "Recorded Future Alerts" integration in "Recorded Future" pack instead.
- recordedfuture-alert-set-note — Set a note for the alert in Recorded Future. Deprecated: use rf-alert-update from "Recorded Future Alerts" integration in "Recorded Future" pack instead.
- recordedfuture-alert-set-status — Set alert into predefined status. Deprecated: use rf-alert-update from "Recorded Future Alerts" integration in "Recorded Future" pack instead.
- recordedfuture-alerts — Gets details on alerts configured and generated by Recorded Future by alert rule ID and/or time range. Deprecated: use rf-alerts from "Recorded Future Alerts" integration in "Recorded Future" pack instead.
- recordedfuture-collective-insight — Post detection to collective insight.
- recordedfuture-detection-rules — Search detection rules.
- recordedfuture-intelligence — Get threat intelligence for an IP, Domain, CVE, URL, File or Malware.
- recordedfuture-links — Get Insikt Group Research Links for an IP, Domain, CVE, URL, File, or Malware.
- recordedfuture-malware-search — Search for a malware by specified filters.
- recordedfuture-single-alert — Get detailed information from vulnerability, typosquat and credential alerts. Deprecated in favor of "Recorded Future Alerts" integration in "Recorded Future" pack.
- recordedfuture-threat-assessment — Get an indicator of the risk based on context.
- recordedfuture-threat-links — Search links.
- recordedfuture-threat-map — Get threat actors map.
- url — Gets a quick indicator of the risk associated with a URL.