Enriching Data with Recorded Future
The Recorded Future enrichment provides enrichment data on domain, hash, IP address, and URL observables on observable details pages. It enables you to leverage Recorded Future data from ThreatStream, without leaving the platform. Enrichment data is displayed on the Recorded Future tab in the Enrichments section on hash observable details pages.
In addition to links to Intelligence Cards on the Recorded Future platform, the enrichment provides the following data from Recorded Future:
- Context (Domain, IP Address, and Hash observables only)
- First References (Domain, IP Address, and Hash observables only)
- Insikt Group Research
- Triggered Risk Rules
- In Threat List (Domain, IP Address, and Hash observables only)
- Reference Count (Domain, IP Address, and Hash observables only)
- Recent References (Domain, IP Address, and Hash observables only)
- Risk Scores
You must obtain the API Key from your Recorded Future account to activate the Recorded Future enrichment.
Before activating the Recorder Future enrichment, obtain a Recorded Future API Key from your Recorded Future account.
To activate the Recorded Future enrichment:
-
Navigate to ThreatStream > APP STORE > APP Store.
- Click Get Access on the Recorded Future tile.
- Click I have credentials on the wizard page that opens.
- On the next wizard page, click Credentials and enter your Recorded Future API Key.
- Click Activate.
The Recorded Future enrichment is now active.