Recorded Future Vulnerability Enrichment

The integration with Archer & Recorded Future (RF) will allow customers the ability to automatically download a feed of cyber vulnerability enrichment data. The information in this data feed can be used to help identify trends and patterns in emerging and disclosed vulnerabilities as well as to drive proactive workflows for resolving known vulnerabilities in the customer’s enterprise. Combined with the asset criticality information in Archer, the intelligence gained from Recorded Future enables users to better prioritize vulnerability management activities.

Release history

Last updated: May 2018

Solution summary

Partner Integration Overview

Archer Solution

IT & Security Risk Management

Archer Use Case

IT Security Vulnerabilities Program

Archer Applications

Vulnerability

Uses Custom Application

No

Requires On-Demand license

No

Key features & benefits

  • Faster awareness of emerging threats that affect your key assets

  • Enrich the context around disclosed vulnerabilities

  • Better prioritize remediation with external intelligence

Partner product configuration

Before you begin 

This section provides instructions for configuring Recorded Future’s (RF) vulnerability enrichment data with the Archer Platform. This document is not intended to suggest optimum installations or configurations.

It is assumed that the reader has both working knowledge of all products involved, and the ability to perform the tasks outlined in this section. Administrators should have access to the product documentation for all products in order to install the required components.

Important: The integration described in this guide is being provided as a reference implementation for evaluation and testing purposes. It may or may not meet the needs and use cases for your organization. If additional customizations or enhancements are needed, it is recommended that customers contact Archer Help for assistance.

Two things are required before you begin configuration of this data feed.

  • A Recorded Future API token. provides information on how Recorded Future users can create and access their API tokens.

  • Access to the Recorded Future Fusion API product feature & a configured Fusion Flow providing a feed of vulnerability enrichment data. If you would like to customize the feed of vulnerability data you are receiving & have questions, please contact the Recorded Future Professional Services team for additional assistance.

Archer configuration

Sub-form configuration

Dashboard configuration

A number of custom reports can be configured to provide additional contextual information about specific or trending vulnerabilities using your own custom definitions. Provided below are some sample report configurations which use the Recorded Future Vulnerabilities enrichment data.

Certification environment

Date tested: May 2018

Product Name Version Information Operating System

Archer

6.3

Virtual Appliance

Recorded Future API

v2

N/A