Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization
Today, Recorded Future is announcing Automated Signature Creation, a new capability in Attack Surface Intelligence (ASI) to combat the speed of AI-generated exploits.
ASI continuously maps an organization’s external exposure, correlates newly surfaced vulnerabilities with real-world threat intelligence, and prioritizes response to enable defenders to remediate before adversaries can act.
This new function within ASI automatically creates signatures, pieces of detection logic that empowers the Recorded Future Platform to recognize a specific vulnerable or exposed condition across organization’s assets in real time.
With Automated Signature Creation now available, Recorded Future is helping to close the gap between AI-enabled threat discovery and enterprise defense.
Tackling the machine speed of exploitable vulnerabilities
It seems everything is moving quicker these days and the time to exploit a vulnerability is no different. A new generation of AI models is accelerating this challenge, demonstrating that they can automatically find zero-day vulnerabilities in major operating systems and web browsers — a skill that was previously exclusive to the most advanced government cyber units and research labs.
Back in 2020, we cited how Gartner confirmed that the time from discovery to exploitation dropped from 45 days to 15 days, between 2010 to 2020.
In our 2025 Malware and Vulnerability Trends report, we reported that weaponization occurred “within days of disclosure." Today, that window is measured in hours.
As a result, the status quo of traditional defenses and manual processes are no longer sufficient. Let’s look back at how we got here, from pre-existing detection methods to Recorded Future’s latest ASI enhancement to better defend against AI-accelerated vulnerabilities.
How we got here
In the past year, Recorded Future’s traditional approach of expert-authored signatures from the Insikt Group® was effective; they were high quality but moved at a human pace.
For example, in February 2025 we reported on the Trimble Cityworks: CVE-2025-0994, showcasing how manual signature creation worked. The Insikt Group built a Nuclei template (shared as a downloadable YAML file) specifically for CVE-2025-0994. This enabled defenders to test potentially vulnerable Trimble Cityworks instances prior to the patched version, serving as a detection and prioritization aid for helping teams figure out where to focus patching efforts first. This worked in conjunction with one of ASI’s core functions, scanning web infrastructure to identify internet-facing assets vulnerable to CVE-2025-0994.
Since that vulnerability disclosure a little over a year ago, we have ample evidence that the speed at which vulnerabilities are exploited has increased exponentially. Just recently, it was reported that OpenAI’s own agents went rogue and exploited a zero-day vulnerability in Artifactory, now infamously tied to the Hugging Face incident.
Incidents like this one, and the underlying vulnerabilities that facilitate them, are exactly why Recorded Future automated signature creation.
Now, in the face of an attack moving at machine speed, agentic processing generates production-ready detection signatures autonomously by turning a newly surfaced vulnerability into a deployable signature in as little as 31 minutes. As a result, the number of in-platform signatures produced has increased tenfold. Let’s take a closer look at how it works.
How automated signature creation works
So what does a signature in this context actually mean? Think of it like this: the signature is a piece of detection logic that says "go ask this asset this exact question; if the answer looks like this, it's vulnerable." It's the difference between "we found your assets" and "we found the ones a threat actor can potentially break into."
Automated signature creation works like a three-step early warning system. (See Figure 1)
- The platform keeps a constant view of what your organization exposes to the internet such as domain records, certificates, and ownership data.
- When a new vulnerability is flagged and matched against your scanned assets, it's checked against live threat activity rather than just a generic severity score. The system looks for evidence that threat actors are actually exploiting it, tying it to malware, ransomware or threat actor intent.
- When Recorded Future Intelligence determines a CVE is relevant for detection, the system automatically processes it to generate a detection signature or product fingerprint in as little as 31 minutes.
The policy angle
The compressed time to exploit has created new policies for federal agencies to follow. One such policy was issued by the Cybersecurity and Infrastructure Security Agency (CISA) on 10 June 2026. The new directive is designed to improve how federal agencies prioritize the mitigation of cyber vulnerabilities. The directive outlined four key criteria for prioritizing vulnerabilities:
- Asset Exposure
- Known Exploited Vulnerabilities (KEV) Status
- Exploit Automation
- Post-Exploitation Technical Impact
These criteria directly map to Recorded Future capabilities (see Table 1). In short, Automated Signature Creation operationalizes the risk-based prioritization CISA now mandates that some, and encourages all organizations to adopt.
Table 1: Mapping the CISA directive to Recorded Future capabilities
The impact is clear
Our automated signature processes have already processed over 1,600 CVEs and triggered 900,000+ ASI detection events across 46,000+ hosts, impacting more than 75% of ASI customer projects. In fact, during the week of 9-14 August 2026, automated signatures accounted for 19.8% of all critical-severity events and 25.5% of all high-severity events. (Source: Recorded Future R&D Teams)
As the speed of exploitation continues to outpace traditional, manual security processes, the necessity for a shift in defensive strategy has become clear. Automated signature creation represents more than just defensive efficiency — it's critical for defending against AI-accelerated threats. By enabling machine-speed response, Recorded Future is ensuring security teams can better prioritize the vulnerabilities that present the biggest risk to their organization.
Learn more about Recorded Future Attack Surface Intelligence or request a demo to see it in action.
Frequently asked questions
1. What is Automated Signature Creation?
It's a new capability inside Attack Surface Intelligence (ASI) that automatically generates detection signatures. This is the logic that tells the platform how to recognize a specific vulnerable or exposed condition on an organization's assets without waiting on manual, expert-authored work.
2. Who is this for and how do I enable it?
Automated Signature Creation is for Recorded Future ASI customers. It's a new function within the ASI product, applied automatically to your scanned assets.
3. How fast is it?
Signature creation takes 31 minutes or less, a 95% reduction in time required compared to previous analyst-driven signature creation. Once created, the signature loads into the ASI signature library and is ready for use. This means it typically takes less than one hour from when a newly surfaced vulnerability triggers the automated signature creation process until ASI has a deployable, scannable signature for that vulnerability.
4. How does it work?
Three steps: ASI continuously maps an organization's external exposure such as domains, certificates, ownership data, misconfigurations, vulnerabilities; Recorded Future Intelligence flags vulnerabilities that are relevant for detection with live threat intelligence; the system then generates a signature or product fingerprint automatically.
5. Does this replace Insikt Group's expert-authored signatures?
No. Insikt Group's manual signatures remain part of the approach; automation extends detection to machine speed for the volume traditional processes generally can't keep pace with.
6. What's the measurable impact so far?
Signature volume has increased tenfold since automation was introduced. Automated processes have processed 1,600+ CVEs, triggered 900,000+ ASI detection events across 46,000+ hosts, and touched more than 75% of ASI customer projects. In the week of August 9–14, 2026, automated signatures accounted for 19.8% of critical-severity events and 25.5% of high-severity events.
7. Why does this matter?
Automated Signature Creation helps close the gap between AI-enabled threat discovery and enterprise defense. Ultimately, giving security teams a way to respond at the same speed adversaries are now operating at, rather than relying solely on manual triage.
8. Where can I find more information?
More information can be found in the accompanying support article or contact us with any questions.