Recorded Future Identity (v2.0.13)

Recorded Future App for Identity

Author
Recorded Future
Support
partner
URL
https://www.recordedfuture.com/integrations/
Categories
Data Enrichment & Threat Intelligence

Incident fields (10)

Integrations (1)

Layouts (2)

Playbooks (6)

README

Recorded Future Identity Pack

Overview

The Recorded Future Identity Pack for Cortex XSOAR enhances threat intelligence capabilities focused on identity-related
exposures. Integrating Recorded Future’s data, this pack automates the detection, investigation, and response to
identity threats. It includes playbooks, incident types, layouts, and classifiers to streamline identity threat
management and response workflows.

Primary Use Case

Designed for security teams managing identity-related threats, this pack helps detect compromised credentials in real
time and automatically respond to these threats. For example, when an identity exposure alert is triggered, the
integration fetches detailed information about the exposure, allowing security analysts to assess the severity and take
appropriate actions, such as enforcing password resets or disabling compromised accounts.

Getting Started

  1. Install the Pack:
    • From the Cortex XSOAR Marketplace, search for and install the Recorded Future Identity Pack.
  2. Configure the Integration:
    • Follow the setup instructions to configure the Recorded Future Identity integration.
  3. Run Initial Searches:
    • Use the recordedfuture-identity-search command to search for identity-related data.
    • Use the recordedfuture-identity-lookup command to look up detailed information about specific identities.
  4. Set Up Automated Responses:
    • Configure playbooks and automation to respond to identity exposure alerts. Use the Recorded Future - Identity
      Exposure
      playbook as a template for handling alerts.

Setup Instructions

To set up the Recorded Future Identity integration in Cortex XSOAR, follow these steps:

  1. Navigate to Integrations:
    • Go to Settings > Integrations > Instances.
  2. Search for Recorded Future Identity:
    • In the search bar, type Recorded Future Identity.
  3. Add a New Instance:
    • Click Add instance to create and configure a new integration instance.
  4. Configure the Integration:
    • Enter the required parameters such as Server URL and API Token.
    • Adjust optional settings like proxy usage and incident fetching as needed.
  5. Test the Configuration:
    • Click Test to ensure the settings are correct and that the connection to Recorded Future is successful.
  6. Setup Pre-Process Rule:
    • The configuration of the preprocessing rule is optional, but highly recommended.

For detailed configuration instructions, refer to the Recorded Future Identity Integration Documentation.

Contents of the Pack

Integration

Commands

Classifiers

Incident Types

Incident Fields

Layouts

Playbooks

Deprecated Components

Dependencies

This pack depends on the following content packs: