Overview
Recorded Future's Agentic Processing pipeline automatically transforms incoming threat signals into production-ready detection signatures and enriched vulnerability intelligence—without requiring manual analyst intervention for every finding. This article describes how signatures are triggered, how they are produced, and how output is tracked through to delivery.
| ℹ | This process applies to vulnerability-based detection signatures generated through automated agentic workflows. Signatures for non-vulnerability use cases (e.g., threat actor TTPs, malware campaigns) follow a separate workflow. |
Input Streams
The agentic signature pipeline accepts inputs from three sources. Any qualifying signal from these streams can initiate the automated creation process.
| Input Stream | Description | Trigger Method |
|---|---|---|
| Recorded Future Threat Map | Continuous monitoring of the Intelligence Graph surfaces newly disclosed or actively exploited vulnerabilities. Signals are ingested in real time as threat landscape changes are detected. | Automated |
| Recorded Future Risk Lists | Vulnerability Risk Lists are evaluated on a continuous basis. When a CVE on the list crosses an auto-creation threshold, it enters the agentic pipeline automatically. | Automated |
| Manual Request | Internal teams (Detection Engineering, Insikt Group) or field-facing teams can submit a manual request for a specific CVE or exposure indicator. Manual requests bypass threshold requirements. | Manual |
Auto-Creation Thresholds
To ensure engineering resources focus on the highest-risk exposures, the agentic pipeline automatically processes signature creation for vulnerabilities that are both corroborated by active threat intelligence and have a Recorded Future risk score that exceeds the set threshold (described below). A vulnerability must meet all of the following criteria to enter the pipeline automatically.
| Condition | Criteria | Additional Details |
|---|---|---|
| Threat Intelligence Signal | Recorded Future's Intelligence Graph has linked the vulnerability to a tracked threat actor, or flagged it under one or more risk rules indicating real-world threat activity (exploited in the wild, associated with malware or ransomware, linked to recent or historical cyber-exploit activity, active exploit development, or a public proof of concept) — at or above the Recorded Future risk-score threshold for that rule. |
Risk Rules Ingested
|
| Coverage Gap | No existing signature already provides coverage | |
| Remotely Detectable | The vulnerability must be observable through unauthenticated scanning of a network-reachable service (e.g., an exposed HTTP/S or other network-facing service. | |
| Safe to Validate | Confirmable with a signature that does not disrupt or degrade the target system. |
| ⚠ | Vulnerabilities that do not meet all criteria or that cannot be validated through remote scanning will not enter the automated pipeline and can be submitted through a Manual Request process. |
When a vulnerability can’t be directly confirmed either safely or definitively, the pipeline will do its best to provide a means to surface potentially affected systems instead. For example, identifying an exposed administrative panel or providing technology detection. This may be surfaced in Explorer so teams can investigate and prioritize candidate systems even when definitive confirmation isn’t possible.
The thresholds are intentionally set to focus automated signature creation on vulnerabilities that combine high severity, confirmed threat activity, and remote detectability. These exposures present the greatest and most immediate risk to customers. This ensures the signatures delivered through the agentic pipeline represent genuine, high-priority exposures rather than a broad volume of findings that increases alert load without a corresponding increase in risk severity. As customers become familiar with the speed and cadence of automated delivery, Recorded Future plans to progressively expand the automated thresholds to cover a wider range of vulnerabilities.
Speed to Signature
Once a signal meets the threshold—or is submitted manually—it moves through a multi-stage agentic workflow. From signal detection to a complete, validated, production-ready signature, the agentic pipeline operates within the following average time:
|
<31 minutes |
End-to-End Signature Creation Time A fully enriched detection signature—including correlation, verification, and structured output—is produced in under 31 minutes from the time a qualifying signal is received. This compares to hours of manual research per signature, representing signature creation that is 40× faster, on average, than manual creation. |
Daily Review and Escalation Process
To ensure that no critical vulnerability goes unaddressed for an unacceptable length of time, Recorded Future Detection Engineering conducts a daily review of signature needs. During this review, analysts assess any vulnerability that the automated pipeline was unable to process to completion, prioritize cases based on severity and active exploitation indicators, and assign manual signature creation tasks accordingly. This process serves as a safety net for the agentic pipeline, ensuring that edge cases—such as CVEs with limited public data or novel exploitation techniques that require human judgment—are identified and acted upon within one business day of escalation.
Frequently Asked Questions
CAN I REQUEST A SIGNATURE FOR A VULNERABILITY WITH A RECORDED FUTURE RISK SCORE BELOW THE STATED THRESHOLDS ABOVE?
Yes. Vulnerabilities that do not meet the automated threshold can be submitted via the Manual Request process. Submit via Recorded Future Support. Manual requests are not subject to threshold restrictions.
HOW DO I KNOW WHEN A SIGNATURE FOR A SPECIFIC CVE IS COMPLETE?
Once a signature is available it will be visible in the ASI signature library.
WHAT HAPPENS IF THE PIPELINE CANNOT PRODUCE A VALIDATED SIGNATURE?
If automated validation fails or insufficient public data exists for a CVE, the signature request ticket is escalated to a human analyst. The analyst will complete the signature manually and it will be present in the ASI Signature Library.
ARE SIGNATURES CONTINUOUSLY UPDATED AFTER INITIAL CREATION?
Yes. The pipeline runs continuous refresh cycles so that intelligence remains accurate as new exploitation data, patches, and threat actor associations emerge.
ARE ASI SCANS RUN AUTOMATICALLY WHEN A NEW SIGNATURE IS CREATED?
No. The new signatures are incorporated into the next scheduled ASI scan cycle. On demand scans can be run for any asset and will include all signatures at the time of that on demand scan request.