icon/x Created with Sketch.

Splunk Cookie Policy

We use our own and third-party cookies to provide you with a great online experience. We also use these cookies to improve our products and services, support our marketing campaigns, and advertise to you on our website and other websites. Some cookies may continue to collect information after you have left our website. Learn more (including how to update your settings) here.
Accept Cookie Policy

We are working on something new...

A Fresh New Splunkbase
We are designing a New Splunkbase to improve search and discoverability of apps. Check out our new and improved features like Categories and Collections. New Splunkbase is currently in preview mode, as it is under active development. We welcome you to navigate New Splunkbase and give us feedback.

Accept License Agreements

This app is provided by a third party and your right to use the app is in accordance with the license provided by that third-party licensor. Splunk is not responsible for any third-party apps and does not provide any warranty or support. If you have any questions, complaints or claims with respect to this app, please contact the licensor directly.

Thank You

Downloading Recorded Future For Splunk SOAR
SHA256 checksum (recorded-future-for-splunk-soar_443.tgz) ad380e6a6e68a6c374be1dedb0ee568ba37ce251c693a2714e9531d5749ccb7c SHA256 checksum (recorded-future-for-splunk-soar_442.tgz) ec9518c1f3904686d5b4a4692134da8b489ac8902bbd99ecff9847dc4d81321b SHA256 checksum (recorded-future-for-splunk-soar_432.tgz) 09b907062e4ac68c7fea7ec87a4808f21a990c218c2a8479823ef6603ecae14b SHA256 checksum (recorded-future-for-splunk-soar_431.tgz) a574af503ef60bf87d7ad250da5645e404a21626f1037534c811fe5f95493f1e SHA256 checksum (recorded-future-for-splunk-soar_430.tgz) 2c21af6651477221bbfbc9b8a9d4593642301c5ec17fc941f12a0c4151bf21dd SHA256 checksum (recorded-future-for-splunk-soar_420.tgz) e88b8e0b05ef9c831756642d9278883aab2a9e888f02720de7e9b66bc64537ba SHA256 checksum (recorded-future-for-splunk-soar_410.tgz) 8b030afdd0d1f1611eb97041d1a9d9c6ec1fc3a9fd1718a8f6b93785a5b39625 SHA256 checksum (recorded-future-for-splunk-soar_400.tgz) 29c86fe7617dfa09d6c43de47cc7f08cf20193cb9493bef50449fbc9fdaa2e95 SHA256 checksum (recorded-future-for-splunk-soar_310.tgz) b887d2ad31b5302da3e77e386d066728dcf7223a2adbf13b15c3a8e1abb4496a SHA256 checksum (recorded-future-for-splunk-soar_300.tgz) 1b9db2a165966ba44195cc31292ef93cf6232507c09210643a81d87e837397b0

Flag As Inappropriate

soar

Recorded Future For Splunk SOAR

Splunk SOAR Cloud
Overview
Details
Enhance your security posture with Recorded Future for Splunk SOAR.
Key Capabilities:
•Swift Threat Assessments: Access Recorded Future's extensive IOC data for swift and accurate assessments

Supported Actions Version 4.4.3

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • links search: Search for links data
  • detection rule search: Search for detection rule
  • threat actor intelligence: Get threat actor intelligence
  • threat map: Get threat map
  • collective insights submit: Enables contribute data, `collective insights`, into the Recorded Future Intelligence Cloud
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.4.2

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • links search: Search for links data
  • detection rule search: Search for detection rule
  • threat actor intelligence: Get threat actor intelligence
  • threat map: Get threat map
  • collective insights submit: Enables contribute data, `collective insights`, into the Recorded Future Intelligence Cloud
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.3.2

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • links search: Search for links data
  • detection rule search: Search for detection rule
  • threat actor intelligence: Get threat actor intelligence
  • threat map: Get threat map
  • collective insights submit: Enables contribute data, `collective insights`, into the Recorded Future Intelligence Cloud
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.3.1

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • links search: Search for links data
  • detection rule search: Search for detection rule
  • threat actor intelligence: Get threat actor intelligence
  • threat map: Get threat map
  • collective insights submit: Enables contribute data, `collective insights`, into the Recorded Future Intelligence Cloud
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.3.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • links search: Search for links data
  • detection rule search: Search for detection rule
  • threat actor intelligence: Get threat actor intelligence
  • threat map: Get threat map
  • collective insights submit: Enables contribute data, `collective insights`, into the Recorded Future Intelligence Cloud
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.2.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • list search: Find lists based on a query
  • create list: Create new list
  • list add entity: Add new entity to list
  • list remove entity: Remove entity from list
  • list details: Get list details
  • list status: Get list status info
  • list entities: Get list entities
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • playbook alerts search: Search Playbook alerts
  • playbook alert update: Update Playbook alert
  • playbook alert details: Get Playbook alert details
  • entity search: Find entities based on a query
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.1.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 4.0.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert update: Update status and/or notes for the alert specified with alert_id
  • alert search: Get details on alerts configured and generated by Recorded Future by alert rule ID and time range
  • alert lookup: Get details on an alert
  • alert rule search: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment
  • on poll: Ingest alerts from Recorded Future

Supported Actions Version 3.1.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert data lookup: Get details on alerts configured and generated by Recorded Future by alert rule ID and/or time range
  • alert rule lookup: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk for a collection of entities based on context
  • list contexts: Get a list of possible contexts to use in threat assessment

Supported Actions Version 3.0.0

  • test connectivity: Validate the asset configuration for connectivity
  • alert data lookup: Get details on alerts configured and generated by Recorded Future by alert rule ID and/or time range
  • alert rule lookup: Search for alert rule IDs by name
  • url intelligence: Get threat intelligence for a URL
  • url reputation: Get a quick indicator of the risk associated with a URL
  • vulnerability intelligence: Get threat intelligence for a vulnerability
  • vulnerability reputation: Get a quick indicator of the risk associated with a vulnerability
  • file intelligence: Get threat intelligence for a file identified by its hash
  • file reputation: Get a quick indicator of the risk associated with a file identified by its hash
  • domain intelligence: Get threat intelligence for a domain
  • domain reputation: Get a quick indicator of the risk associated with a domain
  • ip intelligence: Get threat intelligence for an IP address
  • ip reputation: Get a quick indicator of the risk associated with an IP address
  • threat assessment: Get an indicator of the risk based on context
  • list contexts: Get a list of possible contexts to use in threat triage

This app implements investigative actions to perform lookups for quick reputation information, contextual threat intelligence and external threat alerts.

Recorded Future App for Splunk SOAR allows clients to work smarter, respond faster, and strengthen their defenses through automation and orchestration. The Recorded Future App provides a number of actions that enable the creation of Playbooks to do automated enrichment, correlation, threat hunting, and alert handling.

Access playbook templates created by Recorded Future automation experts to embed intelligence in your new and existing security workflows: https://support.recordedfuture.com/hc/en-us/articles/12294483605523-Splunk-SOAR-Template-Playbooks-Library

Release Notes

Version 4.4.3
Dec. 4, 2024
  • Remove usage of md5 to be compatible with FIPS
Version 4.4.2
July 10, 2024
  • Changes to polling of alerts; now requires a comma seperated list to pull in alerts
  • Fixing logic issue blocking the polling of alerts
  • Fixing issues with hardcoded path for Cloud
Version 4.3.2
April 18, 2024
  • Improved visibility of support documents
  • Renaming of app headers
  • Fixing issues with hardcoded path for Cloud
  • Improved format for Intelligence Command Widgets
  • Added status config options for fetching standard and playbook alerts
Version 4.3.1
Oct. 3, 2023
  • Increase timeout setting for RecordedFuture HTTP client
Version 4.3.0
Sept. 20, 2023
  • Added new actions:
    • links search - find links data in Recorded Future dataset.
    • detection rule search - download detection rules (yara, sigma, snort) into the system for provided entity.
    • threat actor intelligence - get intelligence data for threat actor.
    • threat map - get a threat map from Recorded Future.
  • Change the way Playbook alerts are polled from Recorded future into the Splunk SOAR. On the first poll the creation date is used to poll the alerts and all the next poll the alert that were updated during the time period from last poll to current poll.
  • Now the intelligence commands will not fail with error NotFound but will successfully finish with the message that Recorded future does not have data for that entity.
  • Added a code_repo_leakage type of playbook alerts.
  • Recorded Future AI Insights added to Intelligence and Alert Lookup results.
Version 4.2.0
March 27, 2023
  • Added new actions:
    • create list
    • list search
    • list details
    • list add entity
    • list remove entity
    • list entities
    • list status
    • playbook alerts search
    • playbook alert details
    • playbook alert update
  • Added new configs to ingest settings
Version 4.1.0
Jan. 11, 2023
  • Fixed the bug when scheduled pulling for events was not working.
  • Change the name of the app from "Recorded Future" to "Recorded Future For Splunk SOAR"
Version 4.0.0
Aug. 26, 2022
  • Added two new actions: alert_lookup and alert_update
  • On_poll functionality to download alerts
  • alert_rule_lookup renamed to alert_rule_search to better describe the action
  • alert_data_lookup renamed to alert_search to better describe the action
  • Improved tagging of entities in alert widgets to find the related actions
Version 3.1.0
April 5, 2022
  • Added MITRE ATT@Ck codes to the entity information
  • Added links information to intelligence lookups
  • Improved presentation of Fixed table output views
  • API call response tailored to the app
Version 3.0.0
Sept. 21, 2021

Recorded Future Release Notes - Published by Recorded Future June 24, 2020

Version 3.0.0 - Released June 24, 2020

  • Compatibility changes for Python 3 support
  • Added 2 new actions
  • threat assessment
  • list contexts

  • Fixed table output views

  • Handled exceptions for Unicode character issues

Subscribe Share

Are you a developer?

As a Splunkbase app developer, you will have access to all Splunk development resources and receive a 10GB license to build an app that will help solve use cases for customers all over the world. Splunkbase has 1000+ apps from Splunk, our partners and our community. Find an app for most any data source and user need, or simply create your own with help from our developer portal.

Follow Us:
Splunk, Splunk>,Turn Data Into Doing, Data-to-Everything, and D2E are trademarks or registered trademarks of Splunk LLC in the United States and other countries. All other brand names,product names,or trademarks belong to their respective owners.