Recorded Future Application

The RecordedFuture application enriches the incoming logs with the threat information fetched from Recorded Future. You can use the enriched data in dashboards, reports, and alerts to monitor and track threats.

The application fetches threat information of the following entities from Recorded Future:

  • IP Address

  • URL

  • Domain

  • Hash

  • Vulnerability

The application summarizes all the fetched and enriched data of the given entities in an Intelligence Card. You can drill forward from the search results to access the Intelligence Card.

Furthermore, the application adds RecordedFuture as a threat intelligence source in the Threat Intelligence application. You can also use the Threat Intelligence process command to further enrich logs with the latest threat information.

Using RecordedFuture in LogPoint

The following steps summarize the flow of using RecordedFuture in LogPoint:

  1. Install the Threat Intelligence application.

  2. Install the RecordedFuture application.

  3. Add RecordedFuture as a threat intelligence source in the Threat Intelligence Management panel or go to Settings >> Configuration >> Recorded Future.

  4. Select the RecordedFuture entity types to fetch the threat information and store it in LogPoint.

  5. Enable the Enable Drill Forward option.

  6. Map LogPoint fields to the RecordedFuture entity types to drill forward from the fields to the Intelligence Card.

  7. Apply an enrichment policy with the Threat Intelligence enrichment source.

  8. From the search results, drill forward and find the Intelligence Card for the mapped fields.


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support