Recorded Future with Investigation Insights
The Investigation Insights – Recorded Future integration searches Recorded Future’s vast intelligence system for information pertaining to indicators such as IPs, hashes, cves domains and urls. Enabling analysts to get a complete picture of how an indicator might affect their systems. In addition to threat intelligence, analysts can also search notes and sightings in the Recorded Future platform.
Indicator Overview
Summary Tags: When searching indicators in Recorded Future analysts can quickly understand the criticality of the indicator, the rules that determined its criticality and the risk score assigned to it.
Criticality Overview: When drilling into the details of the indicator analysts can get a better understanding of the risk score and the criticality of the indicator.
Indicator Information: When drilled in the analysts can also get more in-depth information on the indicator. In this CVE example analysts can quickly understand what the CVE is, its criticality and impact and how exploitable it is. The indicator information will change based on the indicator type that was searched, for example a hash will return different information than the CVE shown.
Risk Evidence: Analysts can also quickly go through all of the evidence that determined the risk score in Recorded Future.
Notes: When drilled into an indicator for Recorded Future an analyst can also see any user driven notes that were added about the indicator to see more information on how the community and their team are enriching the indicators.
Sightings: When drilled into the details on an indicator the analysts can also click on the sightings tab to where the indicator has been sighted on the internet.