RecordedFutureAlerts
Fetch and triage alerts from Recorded Future.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- RecordedFutureV3
Configuration parameters
- isFetch — Fetch incidents
- incidentType — Incident type
- url — Your server URL (required)
- credentials — (required)
- integrationReliability — Source Reliability
- incidentFetchInterval — Incidents fetch interval
- max_fetch — Maximum number of incidents per fetch
- first_fetch — First fetch time
- classic_alerts_enabled — Enable Classic Alerts
- classic_alert_rule_names — Classic Alerts: Rule names to fetch
- classic_alert_statuses — Classic Alerts: Statuses to fetch (required)
- playbook_alerts_enabled — Enable Playbook Alerts
- playbook_alert_priority — Playbook Alerts: Priority to fetch
- playbook_alert_categories — Playbook Alerts: Categories to fetch
- playbook_alert_statuses — Playbook Alerts: Statuses to fetch (required)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (5)
- rf-alert-images — Fetch alert images.
- rf-alert-lookup — Look up a single Recorded Future alert by ID. Supports both Classic Alerts and Playbook Alerts. Returns full alert data including rule details, entities, AI insights, and Playbook Alert panel data.
- rf-alert-rules — Search for alert rule IDs.
- rf-alert-update — Update an alert in the Recorded Future platform.
- rf-alerts — List Classic or Playbook alerts.