Recorded Future MCP: Available Tools

Recorded Future MCP is generally available from 28 September 2026.

This article lists every tool available through Recorded Future MCP at general availability, grouped by capability. For what Recorded Future MCP is, how to connect and which clients are supported, see Recorded Future MCP.

The Module required column states which Recorded Future module a tool needs. "Any module" means the tool is available with any Recorded Future intelligence module. Where several modules are listed, any one of them is enough.

You will only see the tools your entitlements cover — a tool you are not licensed for does not appear in your client at all. The parent article explains how entitlement gating works.

Tool names may appear in your client with a server prefix (for example rf-ai-mcp__), depending on how the client displays them.

Additional tools will continue to be added as part of our ongoing improvements to the service. They will be added to this article as they go live.

N.B: Some tools available to any module will only display content available to the specific entitlements available to you. For example, some Insikt Notes related to Fraud are available only to Fraud customers.

 

Entity research

Resolution tools turn names and free text into Recorded Future Master IDs, which is what most of the rest of the catalogue takes as input.

Tool What it does Module required
entity_lookup_resolve_entities_in_text Extracts the entities mentioned in a block of text and resolves them to Master IDs Any
entity_lookup_lookup_master_ids Resolves Master IDs into readable entity metadata Any
raw_api_find_entities_by_name Finds entities by name and type to resolve their Master IDs Any
intelligence_cards_get_intelligence_cards Returns Intelligence Cards summarising the key attributes of one or more entities Any 
links_get_links_for_entities Pivots from an entity to related IOCs, malware, CVEs, TTPs and other linked entities SecOps Intelligence, Threat Intelligence

Risk scoring

Tool What it does Module required
risk_get_risk_rules Lists the risk rules that apply to a supported entity type Any
risk_get_risk_score_history Returns risk score history for an entity across a time range Any
risk_get_high_risk_entities Returns high-risk entities of a given type above a score threshold Any

Search and source evidence

Tool What it does Module required
search_search Searches Recorded Future intelligence and returns answers with the references behind them Threat Intelligence, Geopolitical Intelligence
entity_recent_mentions Returns recent reporting that mentions specific entities (roughly the last month) Any

Insikt Group research

Tool What it does Module required
insikt_find_notes_by_text Finds Insikt notes by free text within a time range Any
insikt_find_notes_by_diamond_model Finds Insikt notes whose Diamond Model includes specific entities Any
insikt_search_analyst_notes Keyword search across Insikt notes Any
insikt_get_summaries Returns analyst-written summaries for Insikt notes Any
insikt_get_full_note Returns the full content of an Insikt note Any

Your organisation's analyst notes

Read and write access to notes authored inside your own organisation. Published notes are visible to your organisation, and every write is reversible.

Tool What it does Module required
analyst_notes_search_notes Searches your organisation's analyst notes Any
analyst_notes_get_note Retrieves one of your organisation's analyst notes by ID Any
analyst_notes_list_topics Lists the analyst note topics available to you Any
analyst_notes_list_sources Lists the sources for your analyst notes Any
analyst_notes_publish_note Publishes a new analyst note, visible to your organisation Any
analyst_notes_edit_note Updates and republishes one of your organisation's existing analyst notes Any

Threat maps and MITRE ATT&CK

Tool What it does Module required
threatmap_get_threat_actor_map_information Returns threat actor threat-map scores and supporting evidence Threat Intelligence
threatmap_get_malware_map_information Returns malware threat-map scores and supporting evidence Threat Intelligence
threatmap_get_threat_actor_information Returns scores and evidence for a specific threat actor Threat Intelligence
threatmap_get_malware_information Returns scores and evidence for a specific malware family Threat Intelligence
threatmap_get_threat_actor_map_diff Compares your threat actor map between two dates Threat Intelligence
threatmap_get_malware_map_diff Compares your malware map between two dates Threat Intelligence
threatmap_get_map_mitre_matrix Returns the MITRE ATT&CK matrix for your threat map Threat Intelligence
threatmap_get_map_mitre_evidence Returns the MITRE ATT&CK evidence behind your threat map Threat Intelligence
get_adversary_mitre_matrix Returns the MITRE ATT&CK matrix for specific adversaries Threat Intelligence
get_adversary_mitre_evidence Returns the MITRE ATT&CK evidence for specific adversaries Threat Intelligence

Malware and sandbox analysis

Tool What it does Module required
malware_tools_malware_search_translate Translates a natural-language malware question into sandbox query syntax Threat Intelligence, SecOps Intelligence
malware_tools_malware_search_count Counts sandbox samples matching a translated query Threat Intelligence,  SecOps Intelligence
malware_tools_malware_search_aggregate Aggregates sandbox samples by a field over a date range Threat Intelligence, SecOps Intelligence

Ransomware

Tool What it does Module required
ransomware_get_ransomware_victim_information Returns ransomware victim references for external entities Threat Intelligence, Brand Intelligence, Third-Party Intelligence
ransomware_get_ransomware_metadata Returns ransomware metadata relevant to your organisation Threat Intelligence
ransomware_get_malware_ttp_attributes Returns MITRE TTP evidence for a malware entity Threat Intelligence
ransomware_get_threat_actor_ttp_attributes Returns MITRE TTP evidence for a threat actor entity Threat Intelligence

Malicious Traffic Analysis

Tool What it does Module required
mta_get_mta_references Searches Malicious Traffic Analysis references using natural language Threat Intelligence

Influence Operations

Tool What it does Module required
io_mcp_server_influence_operations_query Query influence operations data. Threat Intelligence, Geopolitical Intelligence
io_mcp_server_influence_operations_stats Influence operations statistics. Threat Intelligence, Geopolitical Intelligence
io_mcp_server_influence_network_reports Influence network reports. Threat Intelligence, Geopolitical Intelligence
io_mcp_server_list_influence_networks List influence networks. Threat Intelligence, Geopolitical Intelligence

Collective Insights — your own detections

These tools read the detection data your organisation has submitted from its own security stack.

Tool What it does Module required
have_i_seen_this Checks whether a threat, IOC, TTP, malware family, actor or device appears in your detections SecOps Intelligence, Threat Intelligence
detection_summary Summarises your detection landscape SecOps Intelligence, Threat Intelligence
detection_trends Returns detection volume trends over time SecOps Intelligence, Threat Intelligence
top_malware_families Ranks the malware families seen in your detections SecOps Intelligence, Threat Intelligence
malware_community_comparison Compares your top malware families against a community benchmark SecOps Intelligence, Threat Intelligence
top_related_iocs Ranks the IOCs most associated with an entity in your detections SecOps Intelligence, Threat Intelligence
top_related_devices Ranks the devices most associated with an entity in your detections SecOps Intelligence, Threat Intelligence
top_related_threat_actors Ranks the threat actors most associated with an entity in your detections SecOps Intelligence, Threat Intelligence
top_related_ttps Ranks the ATT&CK techniques most associated with an entity in your detections SecOps Intelligence, Threat Intelligence
top_related_vulnerabilities Ranks the CVEs most associated with an entity in your detections SecOps Intelligence, Threat Intelligence
attack_heatmap Returns a MITRE ATT&CK technique heatmap built from your detections SecOps Intelligence, Threat Intelligence
attack_ttp_summary Returns your most prevalent ATT&CK techniques and the threats associated with them SecOps Intelligence, Threat Intelligence

Alerts and alert rules

Tool What it does Module required
searchAlerts Searches your alerts, with filtering and pagination Any
getAlert Retrieves a single alert by ID Any
getAlertImage Retrieves an image attached to an alert Any
searchAlertRules Searches your alert rules by free text Any
pd_mcp__list_alert_rules Lists your organisation's alert rules Any

Intelligence requirements

Tool What it does Module required
pd_mcp__list_intelligence_requirements Lists your organisation's intelligence requirements Any

Watch lists and custom lists

Read and write access to your organisation's watch lists and custom lists.

Tool What it does Module required
watchlists_get_watchlist Get entities on a watch list Any 
custom_lists_get_custom_list_by_name Get entities on a custom list Any
GetWatchlistInfo Returns metadata for lists by Master ID Any 
GetCustomListInfo Returns metadata for lists by Master ID Any
GetThreatListInfo Returns metadata for lists by Master ID Any
GetWatchlistsByEntity Returns the lists an entity belongs to, by Master ID Any
GetCustomListsByEntity Returns the lists an entity belongs to, by Master ID Any

GetThreatListsByEntity


 

Returns the lists an entity belongs to, by Master ID Any
GetAllWatchlists Lists the names of your organisation's watch lists Any 
SearchWatchlistsByName Finds a list by name  Any
SearchCustomListsByName Finds a list by name  Any
SearchThreatListsByName Finds a list by name  Any
UpdateWatchlistEntries Adds, edits or removes entries on a watch list or custom list, including bulk updates Any

UpdateCustomListEntries


 

Adds, edits or removes entries on a watch list or custom list, including bulk updates Any

Attack Surface Intelligence

Tool What it does Module required
asi_list_projects Lists the ASI projects you can access Attack Surface Intelligence
asi_search_assets Searches and filters assets in an ASI project Attack Surface Intelligence
asi_get_asset_details Returns full details for a single asset Attack Surface Intelligence
asi_list_asset_exposures Lists the exposures on a specific asset Attack Surface Intelligence
asi_list_project_exposures Summarises exposures across an ASI project Attack Surface Intelligence
asi_get_exposure_assets Returns the assets affected by an exposure signature Attack Surface Intelligence
asi_get_filter_options Returns available asset filter values and their counts Attack Surface Intelligence
asi_list_tags Lists user-defined tags in an ASI project Attack Surface Intelligence
asi_list_static_asset_rules Lists static include and exclude asset rules Attack Surface Intelligence
asi_get_workflow Returns the playbook for a named ASI investigation workflow Attack Surface Intelligence

Third-Party Intelligence and Vulnerability Intelligence

Tool What it does Module required
vulnerability_get_company_vulnerabilities Returns the top vulnerabilities affecting a company Third-Party Intelligence
vulnerability_get_company_affected_assets Returns a company's affected assets, grouped by product Third-Party Intelligence
product_get_product_vulnerabilities Returns the top vulnerabilities affecting a product, plus CVE detail Vulnerability Intelligence, Third-Party Intelligence
vulnerability_get_portfolio_vuln_exposure Returns the percentage of your monitored portfolio affected by a CVE Third-Party Intelligence
vulnerability_get_watchlist_vendors_by_vuln Returns the monitored vendors on your watch list affected by a CVE Third-Party Intelligence

vulnerability_get_vulnerability_detail


 

Returns a full intelligence profile for a specific vulnerability.



 

Third-Party Intelligence, Vulnerability Intelligence
risk_get_company_risk_score Returns a risk score for a company  Third-Party Intelligence

Connection context

Tool What it does Module required
whoami Returns the identity, organisation and context of the credential currently connected Any

 

Related articles

This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.

This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.
Was this article helpful?
0 out of 0 found this helpful

Articles in this section