Recorded Future IP Intelligence

Updated 1 month ago by TruSTAR

This document explains how to set up the Recorded Future IP Intelligence premium intelligence source in the TruSTAR platform.

With billions of indexed facts, and more added every day, Recorded Future’s Threat Intelligence Machine makes use of machine learning and natural language processing (NLP), to continuously analyze threat data from a massive range of sources. Recorded Future IP Intelligence contains IP addresses scored at 90 and above (on a scale of 0-100) by Recorded Future’s internal team.

  • Source Type: Premium Intel
  • Update Type: Feed-based
  • Update Frequency: 2 hours
  • Parser: Yes
  • Time to Install: 10 minutes

Observables Supported

Requirements

  • A subscription to Recorded Future Premium
  • Recorded Future API Key
  • A daily quota of 60 Recorded Future credits. Each list update requires 5 credits, for a total of 60 credits per day (12 list updates per day).
    TruSTAR Admin rights are required to activate this Premium Intelligence feed.

Getting Started

  1. Log into the TruSTAR Web App.
  2. Click the Marketplace icon on the left side icon list.
  3. Choose Premium Intel.
  4. Click Subscribe on the Recorded Future IP Intelligence box.
  5. Enter your Recorded Future API key and click Save Credentials & Request Subscription.

TruSTAR will validate the integration within 48 hours and send an email when the integration has been enabled.

TruSTAR Report Mapping

The information retrieved from this intelligence source is stored in the Recorded Future IP Intelligence Enclave using this format.

Field 

Explanation

Report Title

IP <Observable Value>

External ID

Encoded value of (IP<Observable Value>)

Report Body

Full JSON response

Time Begun

FirstSeen ​field of response

Example: 2021-04-27T12:46:51.000Z

Tags

​criticalityLabel and score ​field of response if available. criticalityLabel of None and score value = 0 are ignored.

Example: criticality​Label​: unspecified Score: 5

Deeplink

​IntelCard ​field value of response, if available

Example: https://app.recordedfuture.com/live/sc/entity/XXXXX

Client Type

PYTHON SDK

Client Meta Tag

trustash

Resources

Link to a PDF File explaining the Recorded Future API

Link to the Recorded Future API documentation

Link to TruSTAR API documentation

Known Issues

No reported issues.

Please reach out to support@trustar.co if you have issues with this integration.


How Did We Do?