Recorded Future Launches MCP to Connect AI Agents with Threat Intelligence

Summary
Recorded Future’s MCP is generally available, giving AI agents OAuth-authenticated access to more than 80 threat-intelligence tools for security workflows including enrichment, detection engineering, threat hunting, and incident response.
Key points
- The service connects AI agents and LLM workflows to Recorded Future intelligence through a standardized MCP interface with OAuth authentication.
- More than 80 tools provide access to threat-actor profiles, risk scores, ransomware metadata, malware sandbox data, and dark web intelligence.
- Agents can write to Watch Lists and add Platform Analyst Notes, as well as retrieve intelligence.
- Customers report using MCP for bulk IOC and CVE enrichment, detection engineering, threat hunting, incident response, and automated reporting.
- Recorded Future says it receives tool invocations and parameters, but not prompts or conversation history; requests are logged and retained for 14 days.
Article Details
- Event Type
- General availability launch of a security intelligence integration
- Impact
- Recorded Future MCP gives eligible customers' AI agents OAuth-authenticated access to Recorded Future intelligence through more than 80 tools. It supports intelligence retrieval and writing to Watch Lists and Platform Analyst Notes. Pilot customers reported faster enrichment, reporting, and incident-response workflows.
Vendors
Products
Attack Surface IntelligenceFigure 2: Vulnerability dashboard created using Recorded Future MCP and Attack Surface Intelligence.ChatGPTRecorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.ChatGPT EnterpriseRecorded Future MCP works with Claude, ChatGPT Enterprise, Copilot, Cursor, Gemini CLI, and other OAuth-capable MCP clients.ClaudeRecorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.CopilotRecorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.CursorRecorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.Gemini CLIRecorded Future MCP extends that same role natively to agents, wherever they run, including Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.Recorded Future AIRecorded Future AI, our in-platform AI assistant and workspace, is already live.Recorded Future MCPRecorded Future MCP is now generally available, giving AI agents and LLM workflows direct access to Recorded Future's Intelligence Graph® and enabling precise, trustworthy, and cost-effective decision-making at machineRecorded Future PlatformThese tools expose a broad set of capabilities from across the Recorded Future Platform, including threat actor profiles, Recorded Future Risk Scores, ransomware metadata, malware sandbox data, and dark web intelligence
Industries
energy and utilitiesAn energy and utilities organization uses it to help cover ground that a leaner, always-on team would struggle to staff manually.financialA financial institution now bulk-enriches hundreds of IP addresses in a single prompt instead of one-by-one lookups.TechnologyA global technology company uses Recorded Future MCP for phishing analysis, credential leak investigation, and executive reporting, reducing research time.technology servicesA technology services company uses it to search for malware campaigns and variants, distill the biggest threats, and generate detection logic for its SIEM, cutting a multi-day research process down to minutes.