Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Recorded Future

ASecurity

Expert agent for Recorded Future Intelligence Cloud. Covers Collective Insights AI/NLP analysis, Intelligence Cards, risk scoring, Identity Intelligence, Vulnerability Intelligence, Brand Intelligence, SIEM/SOAR integration, and the RF browser extension. WHEN: \"Recorded Future\", \"RF\", \"Intelligence Card\", \"Collective Insights\", \"risk score\", \"RF Portal\", \"Recorded Future API\", \"RF Intelligence\", \"Mastercard threat intel\".

4 stars
0 votes
0 copies
0 views
Added 9/24/2026
securityrustgonodeazuregitapisecurity

Works with

cliapi

Security Analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned 9/24/2026

$npx -y skills add chrishuffman5/domain-expert --skill recorded-future --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Recorded Future?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Recorded Future
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/chrishuffman5-recorded-future/badge)](https://www.skillsdirectory.com/skills/chrishuffman5-recorded-future)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: recorded-future
description: "Expert agent for Recorded Future Intelligence Cloud. Covers Collective Insights AI/NLP analysis, Intelligence Cards, risk scoring, Identity Intelligence, Vulnerability Intelligence, Brand Intelligence, SIEM/SOAR integration, and the RF browser extension. WHEN: \"Recorded Future\", \"RF\", \"Intelligence Card\", \"Collective Insights\", \"risk score\", \"RF Portal\", \"Recorded Future API\", \"RF Intelligence\", \"Mastercard threat intel\"."
license: MIT
---

# Recorded Future

This skill covers Recorded Future's Intelligence Cloud platform. It has deep expertise in Recorded Future's data collection, AI/NLP analysis, intelligence modules, and integration capabilities.

**Context:** Recorded Future was acquired by Mastercard in 2024. The platform continues to operate independently under the Recorded Future brand, now with additional financial sector context and payment intelligence capabilities.

## How to Approach Tasks

1. **Classify the request type:**
   - **Intelligence enrichment** -- Apply Intelligence Card knowledge (IPs, domains, hashes, vulnerabilities)
   - **Module-specific** -- Route to the appropriate RF module context
   - **Integration** -- Apply SIEM/SOAR/API integration guidance
   - **Workflow** -- Apply operational SOC workflow for RF usage

2. **Identify the RF module** -- SecOps, Vulnerability, Brand, Identity, Geopolitical, Third-Party, or Fraud Intelligence?

3. **Load context** -- Read `references/architecture.md` for platform internals.

## Platform Overview

Recorded Future collects and analyzes data from 1 million+ sources across the open, deep, and dark web, processing data continuously to produce contextualized intelligence.

**Core value proposition:** Replace manual OSINT research with automated, AI-enriched intelligence that surfaces context when and where analysts need it.

## Data Collection

### Source Categories

**Open web:**
- Security blogs and research publications
- Government advisories (CISA, NCSC, ENISA, etc.)
- CVE/NVD/vendor security advisories
- Social media (Twitter/X, LinkedIn, Telegram)
- Paste sites (Pastebin, etc.)
- Code repositories (GitHub -- public repos with leaked credentials, malware samples)
- News media

**Deep web:**
- Closed forums (invite-only hacker communities)
- Messaging platforms (Telegram channels, Discord servers)
- Dark web marketplaces (credential markets, exploit sales)
- Paste sites with obfuscated access
- Private IRC channels

**Technical sources:**
- DNS passive records (passive DNS)
- WHOIS and registration data
- Certificate transparency logs (new domain/cert issuance)
- IP geolocation and ASN data
- Malware analysis (sandboxing, VirusTotal integration)
- Shodan/Censys-equivalent scanning

### AI/NLP Processing

Recorded Future uses NLP to:
- Extract entities (IP addresses, domains, hashes, CVEs, threat actor names, organization names)
- Classify sentiment and context (positive discussion vs. threat discussion)
- Link entities across disparate sources (same malware family mentioned in different reports)
- Identify event type (breach, exploit, sale, vulnerability disclosure, etc.)
- Translate content from multiple languages (Russian, Chinese, Arabic, etc.)

**Collective Insights:**
Anonymized telemetry from Recorded Future customers contributes to collective intelligence:
- Which IPs/domains have been observed making malicious connections (without sharing what was targeted)
- Which malware families are active in customer environments
- This improves accuracy of risk scores beyond what open-source data alone provides

## Intelligence Cards

The Intelligence Card is the core UI element in Recorded Future -- a contextual brief for any entity (IP, domain, hash, vulnerability, threat actor, company).

### IP Intelligence Card

For any IPv4/IPv6 address:
- **Risk Score**: 0-99 (based on observed malicious activity, current status)
- **Risk Rules**: Specific rules that triggered the score (e.g., "C2 for LockBit malware", "Recently active scanning source")
- **Linked malware**: Malware families this IP has been associated with
- **Sightings**: Times this IP appeared in threat reports or security data
- **Related domains**: Domains that have resolved to this IP (passive DNS)
- **Geolocation / ASN**: Physical location and network owner
- **Timeline**: Activity history (when was this IP first/last seen as malicious)

### Domain Intelligence Card

- Risk score with risk rules
- DNS history (all resolved IPs over time)
- Related malware families
- Sightings in threat reports
- WHOIS history (registration changes -- sudden registrar change is a risk signal)
- Certificate information
- Related indicators (URLs hosted, email addresses from same domain)

### File Hash Intelligence Card

For MD5/SHA-1/SHA-256 hashes:
- Risk score
- Malware family classification (identified by sandbox analysis, AV vendor data)
- First seen / last seen dates
- Sightings across reports
- Related indicators (C2 IPs/domains contacted by this malware)
- Sandbox analysis summaries (behavior: process creation, network activity, file modification)
- VirusTotal detection count and results

### Vulnerability Intelligence Card

For CVE identifiers:
- **Risk Score**: Based on exploitation activity (active exploitation >> theoretical risk)
- **CVSS Score**: Standard severity score
- **Exploitation evidence**: Is there a public PoC? Is it being actively exploited in the wild?
- **Exploitation timeline**: When was PoC published, when was first exploitation observed
- **Affected products**: Software/version list
- **Related threat actors**: Which APT groups or criminal actors have used this CVE
- **Patch status**: Is a patch available?
- **Linked malware**: Malware families that use this vulnerability

**Key differentiator:** CVSS score ≠ exploitation risk. A high-CVSS vulnerability with no public exploit has lower remediation priority than a medium-CVSS vulnerability actively exploited by ransomware. RF's risk score incorporates exploitation evidence.

## Intelligence Modules

### SecOps Intelligence

The core SOC analyst module:
- Real-time alerting on IOCs, threat actor activity, and technology risks
- Analyst notes and context on alert items
- SOC dashboard with prioritized alert queue
- Incident response context (relevant intelligence when responding to an alert)
- Integration: SIEM alerts enriched with RF context

**Primary workflows:**
1. Alert triage: SIEM alert → RF lookup → enrichment context → triage decision
2. Threat investigation: Pivot from known IOC → related infrastructure → actor identification
3. Proactive monitoring: Alert rules for keywords (company name, executive names, sector terms)

### Vulnerability Intelligence

Prioritized patch management intelligence:
- Which CVEs in your environment have active exploitation evidence in the wild?
- Trending vulnerabilities (CVEs being actively discussed/exploited this week)
- Patch timeline guidance (how long until unpatched CVE is exploited at scale?)
- Integration with vulnerability scanners (Tenable, Qualys, Rapid7) to cross-reference your scan results with RF exploitation data

**Workflow:**
1. Vulnerability scanner produces list of CVEs
2. RF Vulnerability Intelligence enriches each CVE with exploitation risk score
3. Prioritize remediation by exploitation risk, not just CVSS

### Identity Intelligence

Monitors for compromised credentials related to your organization:
- Employee credentials in data breach compilations (Combo Lists, dark web markets)
- Exposed credentials in paste sites
- Corporate email domain monitoring
- Third-party (supply chain) credential exposure
- Integration with AD/Azure AD for alert-on-compromise workflow

**Alert types:**
- Employee email + password in breach dump
- Employee email found in paste site
- Employee credentials in dark web market listing
- Third-party partner credential exposure (if partner manages access to your systems)

### Brand Intelligence

Protects against brand abuse, typosquatting, and impersonation:
- Newly registered domains that typosquat your brand (rf-example.com, example-support.com)
- Social media impersonation accounts
- Fake mobile apps (unofficial app stores)
- Phishing kit detections referencing your brand
- Look-alike domain monitoring (visual similarity + edit distance analysis)

### Geopolitical Intelligence

Strategic intelligence for business and security risk planning:
- Country-level risk ratings and trend analysis
- Geopolitical events that create cyber risk (sanctions, conflict, election instability)
- Relevant for organizations with operations in multiple countries
- Feeds strategic intelligence products and executive briefings

### Third-Party Intelligence

Monitors your vendor and supply chain ecosystem for threats:
- Breaches or data leaks at third parties with your data
- Dark web mentions of your vendors being targeted
- Credential theft at vendors that access your systems
- Rated per vendor: How many risk indicators does each third party have?

## Risk Scoring (0-99)

### Score Ranges

| Score | Level | Recommended Action |
|---|---|---|
| 0-24 | Unknown / No evidence | No action required |
| 25-64 | Unusual | Monitor; investigate if in context of active incident |
| 65-89 | Malicious | Block/investigate; active threat |
| 90-99 | Very Malicious | Immediate block; confirmed malicious actor |

### Risk Rules

RF calculates scores from risk rules. Key rules:

**IP risk rules:**
- `C2 for Active Malware`: IP confirmed as command and control for active malware
- `Recently active threat actor infrastructure`: IP used by known threat actor in last 30 days
- `Open proxy / Tor exit node`: Anonymizing infrastructure (high false positive risk for blocking)
- `Scanning source`: IP conducting scanning activity
- `Brute force source`: IP conducting credential brute force

**Domain risk rules:**
- `Malware C2`: Domain used for C2
- `Recently registered`: Domain registered in last 30 days (phishing predictor)
- `Parked domain serving malicious content`: Domain parked but serving malware
- `Lookalike domain for brand abuse`: Typosquat/impersonation

**Hash risk rules:**
- `Positive malware verdict`: AV vendors flag this hash
- `Malware family association`: Hash matches known malware family
- `Threat actor tool`: Hash is a tool used by known threat actor

## SIEM/SOAR Integration

### SIEM Integrations (Native Connectors)

- **Splunk**: Recorded Future App for Splunk (Splunkbase)
- **Microsoft Sentinel**: RF Threat Intelligence connector (TAXII-based)
- **IBM QRadar**: RF app on IBM Security App Exchange
- **Google SecOps / Chronicle**: RF-Chronicle integration via API
- **Elastic/OpenSearch**: RF indicator ingestion via API

### SOAR Integrations

- **Palo Alto XSOAR**: RF integration pack
- **Splunk SOAR**: RF enrichment actions
- **ServiceNow**: RF Security Operations integration
- **Tines**: RF HTTP action

### API Integration

**Base URL:** `https://api.recordedfuture.com/v2`

**Key endpoints:**

```
# IP enrichment
GET /ip/{ip_address}
Authorization: Token <API_KEY>

# Domain enrichment
GET /domain/{domain}

# File hash enrichment
GET /hash/{hash_value}

# Vulnerability enrichment
GET /vulnerability/{cve_id}

# Threat actor information
GET /entity/{entity_id}

# Alert list
GET /alert/search
```

**Bulk lookup (for SIEM enrichment):**
```
POST /ip/lookup
{
  "ips": ["1.2.3.4", "5.6.7.8", "9.10.11.12"]
}
```

**Response fields:**
- `risk.score`: 0-99 risk score
- `risk.rules`: List of risk rules that triggered
- `relatedEntities`: Related threat actors, malware, vulnerabilities
- `timestamps.firstSeen` / `timestamps.lastSeen`: Activity dates

### Browser Extension

The RF Browser Extension provides inline enrichment in any web-based security tool:
- Highlights IPs, domains, and hashes on any webpage
- Shows RF risk score on hover (no need to context-switch to RF portal)
- Supported browsers: Chrome, Firefox, Edge
- Works with: SIEM web UIs, ticketing systems, email clients, Google Docs

## Alert Configuration

### Alert Rules

Configure monitoring in RF portal under `Alerts > Alert Rules`:

**Alert types:**
- **Keyword alert**: Alert when company name, technology, or key term appears in new intelligence
- **Indicator alert**: Alert when a specific IP/domain/hash has elevated activity
- **Vulnerability alert**: Alert when new exploitation evidence emerges for CVEs in your asset inventory
- **Identity alert**: Alert on employee credential exposure

**Example keyword alert:**
- Keywords: `"example.com" OR "Example Corp" OR "ExampleCorp" OR "[key executive names]"`
- Sources: All sources (or narrow to: dark web, paste sites, technical sources)
- Notification: Email + SIEM webhook

### Alert Triage in SOC

Workflow for RF alerts in SOC:

1. Alert arrives (email, SIEM, Slack webhook)
2. Click RF alert link → RF portal shows full context
3. Assess: Is this actionable? Is the risk real for my environment?
4. If actionable: Create SOC ticket with RF context attached; proceed to investigation
5. If not actionable (false positive, out of scope): Dismiss; provide feedback to RF (improves model)

## Reference Files

- `references/architecture.md` -- Recorded Future Intelligence Cloud architecture, data collection pipeline, AI/NLP processing, Collective Insights mechanism, Intelligence Graph entity relationships, risk scoring algorithm, and integration architecture with SIEM/SOAR platforms.

Attribution

chrishuffman5chrishuffman5
View sourceSee grades on GitHubMore from chrishuffman5 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Springboot Security

Java Spring Boot 服务中关于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的 Spring Security 最佳实践。

2456590 votes

Security Review

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

2456590 votes

Paperclip Evals

Choose, inspect, validate, and report Paperclip Runner or Product E2E evaluations while preserving evidence, provenance, cost, and failure classification.

953190 votes

Paperclip Task Bridge

Create, comment on, update, and list Paperclip tasks from Hermes using scoped Paperclip API credentials.

953190 votes

Summarize Status

Write a short, colloquial summary for a Paperclip summary slot: open with the 1–3 specific, concrete actions the reader needs to take right now to unblock the work, then a brief plain-language status, streaming progress as it works.

953190 votes
View all in security →