Recorded Future Hash Intelligence

Updated 5 months ago by Elvis Hovor

This document describes how to set up and use Recorded Future Hash Intelligence with TruSTAR Station.

With billions of indexed facts, and more added every day, Recorded Future’s Threat Intelligence Machine makes use of machine learning and natural language processing (NLP), to continuously analyze threat data from a massive range of sources.

  • Source Type: Premium Intel
  • Update Type: Feed-based
  • Update Frequency: 4 hours
  • Time to Install: 10 minutes

Data Types

The integration pulls the following information from Recorded Future Hash Intelligence:

  • MD5
  • SHA1
  • SHA256

Requirements

  • A subscription to Recorded Future Premium
  • Recorded Future API Key
  • A daily quota of 60 Recorded Future credits. Each list update requires 5 credits, for a total of 60 credits per day (12 list updates per day).
TruSTAR Admin rights are required to activate this Premium Intel feed.

Getting Started

  1. Log into TruSTAR Station.
  2. Click the Marketplace icon on the left side icon list.
  3. Choose Premium Intel.
  4. Click Subscribe on the Recorded Future Hash Intelligence box.
  5. Enter your Recorded Future API key and click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

Report Mapping

The Recorded Future Hash Intelligence contains hash data scored at 90 and above (on a scale of 0-100) by Recorded Future’s internal team.

Field 

Explanation

Example

Report Title

<IOC type> <IOC value>

SHA256 XXXXXXXXXXXXXXXXX

SHA1 XXXXXXXXXXXXX

MD5 XXXXXXXXXX

External ID

Encoded value of <IOC type> <IOC value>

Report Body

Full json response

Time Begun

FirstSeen ​field of response

2019-04-27T12:46:51.000Z

Tags

​criticalityLabel and score ​field of response if available. criticalityLabel of None and score value = 0 are ignored.

criticality​Label​: unspecified Score: 5

Deeplink

​IntelCard ​field value of response, if available

https://app.recordedfuture.com/live/sc/entity/XXXXX

Client Type

PYTHON SDK

Client Meta Tag

trustash

FAQ

Use THIS LINK to access a PDF file explaining the Recorded Future API and THIS LINK to explore their API.

Use THIS LINK to access documentation for the TruSTAR API. 

Known Issues

No reported issues.

Please reach out to support@trustar.co if you have issues with this integration.


How Did We Do?