ASI Agentic Signature Creation

Overview

Recorded Future's Agentic Processing pipeline automatically transforms incoming threat signals into production-ready detection signatures and enriched vulnerability intelligence—without requiring manual analyst intervention for every finding. This article describes how signatures are triggered, how they are produced, and how output is tracked through to delivery.

This process applies to vulnerability-based detection signatures generated through automated agentic workflows. Signatures for non-vulnerability use cases (e.g., threat actor TTPs, malware campaigns) follow a separate workflow.

Input Streams

The agentic signature pipeline accepts inputs from three sources. Any qualifying signal from these streams can initiate the automated creation process.

Input Stream Description Trigger Method
Recorded Future Threat Map Continuous monitoring of the Intelligence Graph surfaces newly disclosed or actively exploited vulnerabilities. Signals are ingested in real time as threat landscape changes are detected. Automated
Recorded Future Risk Lists Vulnerability Risk Lists are evaluated on a continuous basis. When a CVE on the list crosses an auto-creation threshold, it enters the agentic pipeline automatically. Automated
Manual Request Internal teams (Detection Engineering, Insikt Group) or field-facing teams can submit a manual request for a specific CVE or exposure indicator. Manual requests bypass threshold requirements. Manual

Auto-Creation Thresholds

To ensure engineering resources focus on the highest-risk exposures, the agentic pipeline automatically processes signature creation for vulnerabilities that are both corroborated by active threat intelligence and have a Recorded Future risk score that exceeds the set threshold (described below). A vulnerability must meet all of the following criteria to enter the pipeline automatically.

Condition Criteria Additional Details
Threat Intelligence Signal Recorded Future's Intelligence Graph has linked the vulnerability to a tracked threat actor, or flagged it under one or more risk rules indicating real-world threat activity (exploited in the wild, associated with malware or ransomware, linked to recent or historical cyber-exploit activity, active exploit development, or a public proof of concept) — at or above the Recorded Future risk-score threshold for that rule.

Risk Rules Ingested

Gated at Risk score ≥ 60:

malwareActivity, recentMalwareActivity, ransomwareExploit, recentRansomwareExploit, linkedToRecentCyberExploit, cyberSignalCritical,
cyberSignalHigh, cyberSignalMedium, recentAnalystNote, recentRelatedNote, linkedToRAT, linkedToRansomware,
recentLikelyExploitDevelopment

Gated at Risk score ≥ 70:


linkedToIntrusionMethod

Coverage Gap No existing signature already provides coverage  
Remotely Detectable The vulnerability must be observable through unauthenticated scanning of a network-reachable service (e.g., an exposed HTTP/S or other network-facing service.  
Safe to Validate Confirmable with a signature that does not disrupt or degrade the target system.  
Vulnerabilities that do not meet all criteria or that cannot be validated through remote scanning will not enter the automated pipeline and can be submitted through a Manual Request process.

When a vulnerability can’t be directly confirmed either safely or definitively, the pipeline will do its best to provide a means to surface potentially affected systems instead. For example, identifying an exposed administrative panel or providing technology detection. This may be surfaced in Explorer so teams can investigate and prioritize candidate systems even when definitive confirmation isn’t possible.

The thresholds are intentionally set to focus automated signature creation on vulnerabilities that combine high severity, confirmed threat activity, and remote detectability. These exposures present the greatest and most immediate risk to customers. This ensures the signatures delivered through the agentic pipeline represent genuine, high-priority exposures rather than a broad volume of findings that increases alert load without a corresponding increase in risk severity. As customers become familiar with the speed and cadence of automated delivery, Recorded Future plans to progressively expand the automated thresholds to cover a wider range of vulnerabilities.

Speed to Signature

Once a signal meets the threshold—or is submitted manually—it moves through a multi-stage agentic workflow. From signal detection to a complete, validated, production-ready signature, the agentic pipeline operates within the following average time:

<31

minutes

End-to-End Signature Creation Time

A fully enriched detection signature—including correlation, verification, and structured output—is produced in under 31 minutes from the time a qualifying signal is received. This compares to hours of manual research per signature, representing signature creation that is  40× faster, on average, than manual creation.

Daily Review and Escalation Process

To ensure that no critical vulnerability goes unaddressed for an unacceptable length of time, Recorded Future Detection Engineering conducts a daily review of signature needs. During this review, analysts assess any vulnerability that the automated pipeline was unable to process to completion, prioritize cases based on severity and active exploitation indicators, and assign manual signature creation tasks accordingly. This process serves as a safety net for the agentic pipeline, ensuring that edge cases—such as CVEs with limited public data or novel exploitation techniques that require human judgment—are identified and acted upon within one business day of escalation.

Frequently Asked Questions

CAN I REQUEST A SIGNATURE FOR A VULNERABILITY WITH A RECORDED FUTURE RISK SCORE BELOW THE STATED THRESHOLDS ABOVE?

Yes. Vulnerabilities that do not meet the automated threshold can be submitted via the Manual Request process. Submit via Recorded Future Support. Manual requests are not subject to threshold restrictions.

HOW DO I KNOW WHEN A SIGNATURE FOR A SPECIFIC CVE IS COMPLETE?

Once a signature is available it will be visible in the ASI signature library.

WHAT HAPPENS IF THE PIPELINE CANNOT PRODUCE A VALIDATED SIGNATURE?

If automated validation fails or insufficient public data exists for a CVE, the signature request ticket is escalated to a human analyst. The analyst will complete the signature manually and it will be present in the ASI Signature Library.

ARE SIGNATURES CONTINUOUSLY UPDATED AFTER INITIAL CREATION?

Yes. The pipeline runs continuous refresh cycles so that intelligence remains accurate as new exploitation data, patches, and threat actor associations emerge. 

ARE ASI SCANS RUN AUTOMATICALLY WHEN A NEW SIGNATURE IS CREATED?

No. The new signatures are incorporated into the next scheduled ASI scan cycle. On demand scans can be run for any asset and will include all signatures at the time of that on demand scan request. 

This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section