Recorded Future Intelligence (v1.9.1)

Recorded Future App, this pack is previously known as 'RecordedFuture v2'

Author
Recorded Future
Support
partner
URL
https://www.recordedfuture.com/support/demisto-integration/
Default data source
RecordedFutureEventCollector
Categories
Data Enrichment & Threat Intelligence

Incident fields (10)

Indicator fields (2)

Integrations (4)

Layouts (5)

Modeling rules (1)

Playbooks (23)

README

“Recorded Future Intelligence” Pack Documentation

Integrations

Recorded Future v2

Access Recorded Future data to enrich IPs, domains, URLs, CVEs, Files, and Malwares and assess
threats in regards to a specific context.

Deprecated functionality: you should no longer use this integration to fetch incidents, but instead the Recorded Future Alerts integration from Recorded Future pack.

Available Actions

Relevant Playbooks


All the playbooks are meant to be used as sub-playbooks to get reputation, intelligence or assess the threat level in
regards to a context.

Relevant Classifiers

Classifier and Incoming Mapper allows you to classify and map fetched incident onto Recorded Future Incident Types.

Relevant Incident Types

Relevant Layouts


Recorded Future - Playbook Alerts (deprecated)

Fetch & triage Recorded Future Playbook Alerts

Deprecated: Use the Recorded Future Alerts integration from Recorded Future pack instead.

Available Actions

Relevant Playbooks

The template playbooks included help you save time and keep your incidents in sync. They also aid with automating repetitive tasks associated with playbook alerts. Template playbooks should be used as launching points to build playbooks for specific use cases supported by Recorded Future. Certain playbook steps in a template playbook need to be configured to function.

Relevant Classifiers

Classifier and Incoming Mapper allows you to classify and map fetched incident onto Recorded Future Incident Types.

Relevant Incident Types

Relevant Layouts


Recorded Future - Lists

Search and manage watchlists and lists in Recorded Future

Available Actions


Dashboards and indicators


Includes a dashboard that details various metrics related to indicators that was generated from Recorded Future data and
incidents that was created from Recorded Future data.

There are two indicator fields added to record which risk rules indicators have triggered as well as whether an
indicator is a malware, c2, or phishing when it has gone through the playbook for threat assessment.