Recorded Future MCP is generally available from 28 September 2026.
This article lists every tool available through Recorded Future MCP at general availability, grouped by capability. For what Recorded Future MCP is, how to connect and which clients are supported, see Recorded Future MCP.
The Module required column states which Recorded Future module a tool needs. "Any module" means the tool is available with any Recorded Future intelligence module. Where several modules are listed, any one of them is enough.
You will only see the tools your entitlements cover — a tool you are not licensed for does not appear in your client at all. The parent article explains how entitlement gating works.
Tool names may appear in your client with a server prefix (for example rf-ai-mcp__), depending on how the client displays them.
Additional tools will continue to be added as part of our ongoing improvements to the service. They will be added to this article as they go live.
N.B: Some tools available to any module will only display content available to the specific entitlements available to you. For example, some Insikt Notes related to Fraud are available only to Fraud customers.
Entity research
Resolution tools turn names and free text into Recorded Future Master IDs, which is what most of the rest of the catalogue takes as input.
| Tool | What it does | Module required |
| entity_lookup_resolve_entities_in_text | Extracts the entities mentioned in a block of text and resolves them to Master IDs | Any |
| entity_lookup_lookup_master_ids | Resolves Master IDs into readable entity metadata | Any |
| raw_api_find_entities_by_name | Finds entities by name and type to resolve their Master IDs | Any |
| intelligence_cards_get_intelligence_cards | Returns Intelligence Cards summarising the key attributes of one or more entities | Any |
| links_get_links_for_entities | Pivots from an entity to related IOCs, malware, CVEs, TTPs and other linked entities | SecOps Intelligence, Threat Intelligence |
Risk scoring
| Tool | What it does | Module required |
| risk_get_risk_rules | Lists the risk rules that apply to a supported entity type | Any |
| risk_get_risk_score_history | Returns risk score history for an entity across a time range | Any |
| risk_get_high_risk_entities | Returns high-risk entities of a given type above a score threshold | Any |
Search and source evidence
| Tool | What it does | Module required |
| search_search | Searches Recorded Future intelligence and returns answers with the references behind them | Threat Intelligence, Geopolitical Intelligence |
| entity_recent_mentions | Returns recent reporting that mentions specific entities (roughly the last month) | Any |
Insikt Group research
| Tool | What it does | Module required |
| insikt_find_notes_by_text | Finds Insikt notes by free text within a time range | Any |
| insikt_find_notes_by_diamond_model | Finds Insikt notes whose Diamond Model includes specific entities | Any |
| insikt_search_analyst_notes | Keyword search across Insikt notes | Any |
| insikt_get_summaries | Returns analyst-written summaries for Insikt notes | Any |
| insikt_get_full_note | Returns the full content of an Insikt note | Any |
Your organisation's analyst notes
Read and write access to notes authored inside your own organisation. Published notes are visible to your organisation, and every write is reversible.
| Tool | What it does | Module required |
| analyst_notes_search_notes | Searches your organisation's analyst notes | Any |
| analyst_notes_get_note | Retrieves one of your organisation's analyst notes by ID | Any |
| analyst_notes_list_topics | Lists the analyst note topics available to you | Any |
| analyst_notes_list_sources | Lists the sources for your analyst notes | Any |
| analyst_notes_publish_note | Publishes a new analyst note, visible to your organisation | Any |
| analyst_notes_edit_note | Updates and republishes one of your organisation's existing analyst notes | Any |
Threat maps and MITRE ATT&CK
| Tool | What it does | Module required |
| threatmap_get_threat_actor_map_information | Returns threat actor threat-map scores and supporting evidence | Threat Intelligence |
| threatmap_get_malware_map_information | Returns malware threat-map scores and supporting evidence | Threat Intelligence |
| threatmap_get_threat_actor_information | Returns scores and evidence for a specific threat actor | Threat Intelligence |
| threatmap_get_malware_information | Returns scores and evidence for a specific malware family | Threat Intelligence |
| threatmap_get_threat_actor_map_diff | Compares your threat actor map between two dates | Threat Intelligence |
| threatmap_get_malware_map_diff | Compares your malware map between two dates | Threat Intelligence |
| threatmap_get_map_mitre_matrix | Returns the MITRE ATT&CK matrix for your threat map | Threat Intelligence |
| threatmap_get_map_mitre_evidence | Returns the MITRE ATT&CK evidence behind your threat map | Threat Intelligence |
| get_adversary_mitre_matrix | Returns the MITRE ATT&CK matrix for specific adversaries | Threat Intelligence |
| get_adversary_mitre_evidence | Returns the MITRE ATT&CK evidence for specific adversaries | Threat Intelligence |
Malware and sandbox analysis
| Tool | What it does | Module required |
| malware_tools_malware_search_translate | Translates a natural-language malware question into sandbox query syntax | Threat Intelligence, SecOps Intelligence |
| malware_tools_malware_search_count | Counts sandbox samples matching a translated query | Threat Intelligence, SecOps Intelligence |
| malware_tools_malware_search_aggregate | Aggregates sandbox samples by a field over a date range | Threat Intelligence, SecOps Intelligence |
Ransomware
| Tool | What it does | Module required |
| ransomware_get_ransomware_victim_information | Returns ransomware victim references for external entities | Threat Intelligence, Brand Intelligence, Third-Party Intelligence |
| ransomware_get_ransomware_metadata | Returns ransomware metadata relevant to your organisation | Threat Intelligence |
| ransomware_get_malware_ttp_attributes | Returns MITRE TTP evidence for a malware entity | Threat Intelligence |
| ransomware_get_threat_actor_ttp_attributes | Returns MITRE TTP evidence for a threat actor entity | Threat Intelligence |
Malicious Traffic Analysis
| Tool | What it does | Module required |
| mta_get_mta_references | Searches Malicious Traffic Analysis references using natural language | Threat Intelligence |
Influence Operations
| Tool | What it does | Module required |
| io_mcp_server_influence_operations_query | Query influence operations data. | Threat Intelligence, Geopolitical Intelligence |
| io_mcp_server_influence_operations_stats | Influence operations statistics. | Threat Intelligence, Geopolitical Intelligence |
| io_mcp_server_influence_network_reports | Influence network reports. | Threat Intelligence, Geopolitical Intelligence |
| io_mcp_server_list_influence_networks | List influence networks. | Threat Intelligence, Geopolitical Intelligence |
Collective Insights — your own detections
These tools read the detection data your organisation has submitted from its own security stack.
| Tool | What it does | Module required |
| have_i_seen_this | Checks whether a threat, IOC, TTP, malware family, actor or device appears in your detections | SecOps Intelligence, Threat Intelligence |
| detection_summary | Summarises your detection landscape | SecOps Intelligence, Threat Intelligence |
| detection_trends | Returns detection volume trends over time | SecOps Intelligence, Threat Intelligence |
| top_malware_families | Ranks the malware families seen in your detections | SecOps Intelligence, Threat Intelligence |
| malware_community_comparison | Compares your top malware families against a community benchmark | SecOps Intelligence, Threat Intelligence |
| top_related_iocs | Ranks the IOCs most associated with an entity in your detections | SecOps Intelligence, Threat Intelligence |
| top_related_devices | Ranks the devices most associated with an entity in your detections | SecOps Intelligence, Threat Intelligence |
| top_related_threat_actors | Ranks the threat actors most associated with an entity in your detections | SecOps Intelligence, Threat Intelligence |
| top_related_ttps | Ranks the ATT&CK techniques most associated with an entity in your detections | SecOps Intelligence, Threat Intelligence |
| top_related_vulnerabilities | Ranks the CVEs most associated with an entity in your detections | SecOps Intelligence, Threat Intelligence |
| attack_heatmap | Returns a MITRE ATT&CK technique heatmap built from your detections | SecOps Intelligence, Threat Intelligence |
| attack_ttp_summary | Returns your most prevalent ATT&CK techniques and the threats associated with them | SecOps Intelligence, Threat Intelligence |
Alerts and alert rules
| Tool | What it does | Module required |
| searchAlerts | Searches your alerts, with filtering and pagination | Any |
| getAlert | Retrieves a single alert by ID | Any |
| getAlertImage | Retrieves an image attached to an alert | Any |
| searchAlertRules | Searches your alert rules by free text | Any |
| pd_mcp__list_alert_rules | Lists your organisation's alert rules | Any |
Intelligence requirements
| Tool | What it does | Module required |
| pd_mcp__list_intelligence_requirements | Lists your organisation's intelligence requirements | Any |
Watch lists and custom lists
Read and write access to your organisation's watch lists and custom lists.
| Tool | What it does | Module required |
| watchlists_get_watchlist | Get entities on a watch list | Any |
| custom_lists_get_custom_list_by_name | Get entities on a custom list | Any |
| GetWatchlistInfo | Returns metadata for lists by Master ID | Any |
| GetCustomListInfo | Returns metadata for lists by Master ID | Any |
| GetThreatListInfo | Returns metadata for lists by Master ID | Any |
| GetWatchlistsByEntity | Returns the lists an entity belongs to, by Master ID | Any |
| GetCustomListsByEntity | Returns the lists an entity belongs to, by Master ID | Any |
|
GetThreatListsByEntity
|
Returns the lists an entity belongs to, by Master ID | Any |
| GetAllWatchlists | Lists the names of your organisation's watch lists | Any |
| SearchWatchlistsByName | Finds a list by name | Any |
| SearchCustomListsByName | Finds a list by name | Any |
| SearchThreatListsByName | Finds a list by name | Any |
| UpdateWatchlistEntries | Adds, edits or removes entries on a watch list or custom list, including bulk updates | Any |
|
UpdateCustomListEntries
|
Adds, edits or removes entries on a watch list or custom list, including bulk updates | Any |
Attack Surface Intelligence
| Tool | What it does | Module required |
| asi_list_projects | Lists the ASI projects you can access | Attack Surface Intelligence |
| asi_search_assets | Searches and filters assets in an ASI project | Attack Surface Intelligence |
| asi_get_asset_details | Returns full details for a single asset | Attack Surface Intelligence |
| asi_list_asset_exposures | Lists the exposures on a specific asset | Attack Surface Intelligence |
| asi_list_project_exposures | Summarises exposures across an ASI project | Attack Surface Intelligence |
| asi_get_exposure_assets | Returns the assets affected by an exposure signature | Attack Surface Intelligence |
| asi_get_filter_options | Returns available asset filter values and their counts | Attack Surface Intelligence |
| asi_list_tags | Lists user-defined tags in an ASI project | Attack Surface Intelligence |
| asi_list_static_asset_rules | Lists static include and exclude asset rules | Attack Surface Intelligence |
| asi_get_workflow | Returns the playbook for a named ASI investigation workflow | Attack Surface Intelligence |
Third-Party Intelligence and Vulnerability Intelligence
| Tool | What it does | Module required |
| vulnerability_get_company_vulnerabilities | Returns the top vulnerabilities affecting a company | Third-Party Intelligence |
| vulnerability_get_company_affected_assets | Returns a company's affected assets, grouped by product | Third-Party Intelligence |
| product_get_product_vulnerabilities | Returns the top vulnerabilities affecting a product, plus CVE detail | Vulnerability Intelligence, Third-Party Intelligence |
| vulnerability_get_portfolio_vuln_exposure | Returns the percentage of your monitored portfolio affected by a CVE | Third-Party Intelligence |
| vulnerability_get_watchlist_vendors_by_vuln | Returns the monitored vendors on your watch list affected by a CVE | Third-Party Intelligence |
|
vulnerability_get_vulnerability_detail
|
Returns a full intelligence profile for a specific vulnerability.
|
Third-Party Intelligence, Vulnerability Intelligence |
| risk_get_company_risk_score | Returns a risk score for a company | Third-Party Intelligence |
Connection context
| Tool | What it does | Module required |
| whoami | Returns the identity, organisation and context of the credential currently connected | Any |
Related articles
- Recorded Future MCP — what it is, how to connect, supported clients
- Recorded Future MCP: Entitlement and Quota
This content is confidential. Do not distribute or download content in a manner that violates your Recorded Future license agreement. Sharing this content outside of licensed Recorded Future users constitutes a breach of the terms and/or agreement and shall be considered a breach by your organization.