Image d’en-tête abstraite​​ 

Recorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations​​ 

Recorded Future MCP is now generally available, giving AI agents and LLM workflows direct access to Recorded Future's Intelligence Graph® and enabling precise, trustworthy, and cost-effective decision-making at machine speed and scale.​​ 

Today, Recorded Future announces the general availability of Recorded Future Model Context Protocol (MCP), connecting AI agents to Recorded Future intelligence. It helps security teams' agents to make faster, better, more trustworthy decisions.​​ 

Threat actors are extensively using AI to automate reconnaissance, develop complex exploits, and carry out frequent and effective attacks with minimal human input. Security teams are responding to this shift by moving more of their own work into agents and copilots, but an agent is inherently limited by the intelligence behind its decisions.​​ 

Ask an LLM the same question twice and it can give you two different answers. This makes agent-driven work unreliable and hard to audit, and it creates uncertainty and delays response times. Security teams need to be able to directly pull trusted intelligence into their agentic layer to help make the right calls, keep their businesses secure, and keep pace at machine speed and scale.​​ 

Recorded Future has been one of the most trusted intelligence providers behind human analyst decisions for over 15 years. Recorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.​​ 

What just launched​​ 

Recorded Future MCP gives agents direct, standardized, OAuth-authenticated access to Recorded Future intelligence. Customers connect once and get a full catalog of intelligence tools their agents can call directly, resulting in improved agent decision making.​​ 

Over 80 tools available​​ 

Recorded Future MCP includes access to more than 80 tools. These tools expose a broad set of capabilities from across the Recorded Future Platform, including threat actor profiles, Recorded Future Risk Scores, ransomware metadata, malware sandbox data, and dark web intelligence as native calls an agent can make directly. Customers can put the full catalog to work in the client software their teams already use, from Claude to ChatGPT.​​ 

Write-capable tools​​ 

Agents can now write to Watch Lists within Recorded Future, and they can author Platform Analyst Notes on specific threat actors. This helps close the loop between analysis and configuration so agents can act on what they find, not just surface it for a human to enter manually. This write access also helps agents keep a customer's own intelligence current, for example by automatically updating their tech stack Watch List on the Platform as new tools are adopted across the organization.​​ 

Figure 1: Recorded Future MCP can be accessed via the Integration Center, among other ways. It supports OAuth 2.0 via Client ID/Secret for integrations users, enabling persistent access for services and agents.​​ 

Integration Center tile​​ 

Setup is simple. MCP is accessible as a tile in the Integration Center alongside customers’ other integrations. For sustained agent access, customers can set up an integration user that’s authenticated via Client ID/Secret (OAuth 2.0). Portal user-based authentication (SSO or similar) continues to work as well.​​ 

Token-efficient operations​​ 

Recorded Future MCP is designed to help agents retrieve what they need in fewer calls. Agents can crawl the Intelligence Graph directly to find related entities and context rather than issuing repeated, narrow searches to piece together the same picture. That can keep cost and latency down as agentic workflows scale.​​ 

Figure 2: Vulnerability dashboard created using Recorded Future MCP and Attack Surface Intelligence.​​ 

How Recorded Future customers are using MCP​​ 

Over the past year, more than 100 of Recorded Future’s enterprise customers field-tested and helped evolve MCP through our pilot program. Their work revealed three common usage patterns:​​ 

1. Automated enrichment and detection engineering​​ 

Customers are replacing manual IOC and CVE lookups with bulk enrichment wired directly into their SIEM and SOAR logic, so alerts arrive already enriched with the latest intelligence instead of requiring a lookup for each indicator. That same access supports automated threat-actor profiling, TTP exploration, and malware analysis. An agent can now trace a path from an indicator to the actor and technique behind it in one pass.​​ 

Additionally, risk-scored detections can be consolidated into a single pane, speeding up triage and escalation decisions that could previously require checking several sources.​​ 

2. Executive and leadership-ready reporting​​ 

Teams are creating automated reports on their threat landscape and risk posture for leadership, turning what used to be a manual weekly assembly into a recurring briefing. Compliance-driven reports, such as high-risk CVE and ransomware-profile requirements, get generated with minimal manual effort. MCP access has helped analysts shift from intelligence collection and report writing to strategic analysis.​​ 

Figure 3: Example query using Recorded MCP to create an executive report of IOCs associated with the threat group Scattered Spider.​​ 

3. Incident response and threat hunting acceleration​​ 

New tooling no longer slows responders down mid-incident: MCP-driven triage and escalation sit right at the decision point, not in a separate tool. This can shorten the path from detection to action, with agents handling the early legwork of an incident so responders can spend time on the parts of the response that need a human call.​​ 

Those patterns are already showing up as concrete wins:​​ 

Where we’re going​​ 

Recorded Future AI, our in-platform AI assistant and workspace, is already live. Recorded Future MCP is the next step, extending that same intelligence to any agent or LLM a customer already runs. Agentic security works best as one program, not a patchwork of separate tools. Recorded Future MCP is the connective layer making that possible today.​​ 

We’ll announce the next phase of our AI journey soon, so make sure to watch this space.​​ 

Bien démarrer​​ 

If you're already a Recorded Future customer, Recorded Future MCP is available if your subscription includes unlimited integrations. Check out our Support Center or contact your Account Director if you need help getting started. If you're not yet a Recorded Future customer, request a demo to see it in action.​​ 

Questions fréquemment posées​​ 

What is Recorded Future MCP?​​ 

Recorded Future MCP is a gateway that gives AI agents and LLM workflows direct access to Recorded Future intelligence, so they can pull it in natively instead of relying on a manual lookup or a custom-built integration.​​ 

Which AI tools and agents work with Recorded Future MCP?​​ 

Recorded Future MCP works with Claude, ChatGPT Enterprise, Copilot, Cursor, Gemini CLI, and other OAuth-capable MCP clients.​​ 

How is this different from the Recorded Future API?​​ 

The API is built for standardized, repeatable processes. Recorded Future MCP is built for exploratory, complex intelligence questions that require reasoning, enrichment, and synthesis across multiple intelligence areas — the kind of work a structured API call isn't built to handle on its own. MCP extends the API, it doesn't replace it.​​ 

Do I need to build my own agent to use this?​​ 

No. Recorded Future MCP works with the agents and copilots you already run.​​ 

How much does it cost, or is it included in my plan?​​ 

Recorded Future MCP is included for customers whose subscriptions include unlimited integration users. Reach out to your account team for questions specific to your plan.​​ 

Is my data or query content visible to Recorded Future?​​ 

Recorded Future does not receive the prompts or conversation content from your LLM or agent.​​ 

When your agent uses the Recorded Future MCP server, we receive only the tool invocation and its parameters — for example, a request to enrich the IP address 1.2.3.4 — not the surrounding prompt, conversation history, or any other data from your environment.​​ 

Those tool invocations are handled as API requests: they are logged and retained for 14 days for security, abuse-prevention, and compliance purposes, then deleted or rendered unattributable.​​ 

Can agents write back to Recorded Future Platform, not just read?​​ 

Yes. Write-capable tools support writing to Watch Lists, for example.​​ 

What are the top use cases for Recorded Future MCP?​​ 

Customers are using it for automated enrichment and detection engineering, executive and leadership-ready report building, and incident response and threat hunting acceleration.​​ 

See the section “How Recorded Future customers are using MCP” above for specifics.​​ 

Does this work alongside other vendors' MCPs?​​ 

Yes. Customers can run Recorded Future MCP alongside other vendors' MCP servers.​​ 

Where can I learn more or get started?​​ 

Prospective customers can request a demo to see Recorded Future MCP in action.
Current customers can activate it directly in the Integration Center if their subscription includes unlimited integrations.​​ 

If your subscription doesn’t currently include unlimited integrations, reach out to your Recorded Future Account Director as you’re still eligible to access MCP through the end of 2026.​​ 

I can’t see an option to connect Recorded Future MCP in my LLM client software (e.g. Claude or ChatGPT). What are my next steps?​​ 

Talk to your organization's enterprise administrator about enabling access.​​