Recorded Future Opens MCP and Debuts Autonomous Defense
Recorded Future made its MCP generally available and debuted autonomous defense agents that act on threat intelligence.
Recorded Future announced general availability of Recorded Future MCP on September 28, 2026, giving AI agents OAuth 2.0 access to its Intelligence Graph. The release includes more than 80 tools covering threat-actor profiles, risk scores, ransomware metadata, malware sandbox data, and dark-web intelligence, plus write access to Watch Lists and Platform Analyst Notes. Supported clients include Claude, ChatGPT, Copilot, Cursor, and Gemini CLI, and more than 100 enterprise customers piloted it for alert enrichment, executive reporting, and incident response. A day later, the company premiered Autonomous Defense at Mastercard RiskX in Arizona, where analysts assign a goal and agents use the Intelligence Graph plus a customer's Private Graph to act across more than 100 integrations. Example workflows include hunting and blocking threats, assessing and monitoring takedowns, and notifying third parties while tracking remediation. Execution defaults to full autonomy, with an option to require human review. The two reports describe complementary launches and do not conflict.
- Recorded Future MCP became generally available on 2026-09-28 with OAuth 2.0 access to the Intelligence Graph.
- MCP exposes more than 80 tools covering threat-actor profiles, risk scores, ransomware metadata, malware sandbox data, and dark-web intelligence.
- Agents can update Watch Lists and author Platform Analyst Notes; supported clients include Claude, ChatGPT, Copilot, Cursor, and Gemini CLI.
- More than 100 enterprise customers piloted MCP for alert enrichment, executive reporting, and incident response.
- Autonomous Defense premiered on 2026-09-29 at Mastercard RiskX in Arizona.
- Agents use the Intelligence Graph plus a customer's Private Graph and act across more than 100 integrations.
- Example workflows include hunting and blocking, assessing and monitoring takedowns, and notifying a third party while tracking remediation.
- Execution defaults to full autonomy, with an option to require human review.
Coverage timelineoldest first · each row is one article
- · 3d agoRecorded Future Launches MCP, the Intelligence Layer for Agentic Security Operations
Recorded Future· 48
Recorded Future made its MCP generally available so AI agents can query its threat intelligence.
- · 2d agoRecorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats
Recorded Future· 28
Recorded Future debuted an autonomous defense platform that acts on threat intelligence at machine speed.