Recorded Future (v1.0.6)

New Recorded Future content. Currently contains only alert functionality - for enrichment etc, refer to the 'Recorded Future Intelligence' pack.

Author
Recorded Future
Support
partner
URL
https://support.recordedfuture.com/
Categories
Data Enrichment & Threat Intelligence, Analytics & SIEM

Incident fields (18)

Integrations (1)

Layouts (5)

README

Recorded Future - Pack Documentation

Recorded Future delivers real-time threat intelligence that helps security teams detect, prioritise, and respond to
threats faster.
The Recorded Future pack focuses on alert-handling and brings both Recorded Future Classic Alerts and
Recorded Future Playbook Alerts straight into Cortex XSOAR so you can triage, investigate, and close alerts without
ever leaving the SOC console.

Heads-up: This pack replaces the alert-centric capabilities that previously lived in the Recorded Future
Intelligence
pack - namely the Recorded Future v2 and Recorded Future - Playbook Alerts integrations.

See Guide: Migrating from Recorded Future Intelligence pack for more details.


What does this pack include?


Key capabilities


Integrations

Recorded Future Alerts

Fetch & triage Recorded Future Classic and Playbook alerts.

Available commands

Command Description
rf-alerts Search / list Classic or Playbook alerts.
rf-alert-update Update alert status, assignee, comment/note, or reopen strategy.
rf-alert-rules Search for alert rule IDs by (partial) rule name.
rf-alert-images Retrieve the latest screenshots for an alert and attach them to the incident.
rf-alert-lookup Look up a single Recorded Future alert by ID.

Full parameter, example, and context details are available in
the integration README.


Relevant Classifiers


Relevant Incident Types


Relevant Layouts


Example use cases

These are only a few examples - the integration supports any Classic or Playbook alert configured in your Recorded
Future workspace.


Additional resources


© Recorded Future. All rights reserved.