Recorded Future
Deprecated. Use Recorded Future v2 from RecordedFuture pack instead. Unique threat intel technology that automatically serves up relevant insights in real time.
- Category
- Data Enrichment & Threat Intelligence
- Pack
- Recorded_Future
Configuration parameters
- server — Server URL (e.g., https://api.recordedfuture.com) (required)
- token — API Token (required)
- suspicious_threshold — Suspicious Threshold. Minimum risk score to consider an indicator suspicious.
- file_threshold — File Threshold. Minimum risk score from Recorded Future to consider the file malicious.
- ip_threshold — IP Threshold. Minimum risk score from RF to consider the IP malicious.
- domain_threshold — Domain Threshold. Minimum risk score from Recorded Future to consider the domain malicious.
- url_threshold — URL Threshold. Minimum risk score from Recorded Future to consider the URL malicious.
- cve_threshold — Vulnerability Threshold. Minimum risk score from Recorded Future to consider the vulnerability critical.
- unsecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
- isFetch — Fetch incidents
- rule_names — Rule names to fetch alerts by, separated by semicolon. If empty, all alerts will be fetched
- triggered — First fetch time (<number> <time unit>, e.g., 12 hours, 7 days, 3 months, 1 year)
- incidentType — Incident type
Commands (22)
- domain — Returns threat intelligence information for a domain or DNS in Recorded Future.
- file — Returns threat intelligence information for a file in Recorded Future.
- ip — Returns threat intelligence information for an IP address in Recorded Future.
- recorded-future-get-alert-rules — Gets Recorded Future alert rules.
- recorded-future-get-alerts — Gets alerts from Recorded Future.
- recorded-future-get-domain-risklist — Gets the domain risk list as a CSV file from Recorded Future.
- recorded-future-get-domain-riskrules — Gets the risk rules for domain data.
- recorded-future-get-hash-risklist — Gets the hash risk list from Recorded Future.
- recorded-future-get-hash-riskrules — Gets the risk rules for hash data.
- recorded-future-get-ip-risklist — Gets the IP risk list as a CSV file from Recorded Future.
- recorded-future-get-ip-riskrules — Gets the risk rules for IP data.
- recorded-future-get-related-entities — Returns threat intelligence context for an indicator in Recorded Future.
- recorded-future-get-threats-domain — Returns domain threats from Recorded Future
- recorded-future-get-threats-hash — Returns hash threats from Recorded Future
- recorded-future-get-threats-ip — Returns IP threats from Recorded Future
- recorded-future-get-threats-url — Returns URL threats from Recorded Future
- recorded-future-get-threats-vulnerabilities — Returns vulnerability threats from Recorded Future.
- recorded-future-get-url-risklist — Gets the URL risk list as a CSV file from Recorded Future.
- recorded-future-get-url-riskrules — Gets the risk rules for URL data.
- recorded-future-get-vulnerability-risklist — Gets the vulnerability (CVE) risk list from Recorded Future.
- recorded-future-get-vulnerability-riskrules — Gets the risk rules for vulnerability data.
- url — Returns threat intelligence information for a URL in Recorded Future.