Skip to main content

Prerequisites

Before configuring the integration, ensure the following requirements are met:
  • Active Recorded Future Subscription with
    • User Role with API Access to generate API tokens under API Access
  • Admin access to AirMDR application
  • Testing Tools (Optional) - curl, Postman to verify API token validity before integration.

Supported Versions

  • Recorded Future API: v2
  • AirMDR: Compatible with all standard cloud deployments
  • Integration Method: API Key (HTTPS REST)

Authentication

The integration uses a static API key generated via the Recorded Future Intelligence Services portal.
An active Recorded Future subscription with API access is required.

Generate a New API Key

To generate an API key in the Recorded Future Platform for integrating with AirMDR, follow these steps:
1

Login to the Recorded Future Platform

  1. Navigate to Recorded Future Platform.
  2. Enter your credentials (Email Address or Username and Password) to access the Recorded Future dashboard.
2

Access Settings

  1. Click on your profile icon in the top-right corner of the page.
  2. From the dropdown menu, select “Settings”.
    🔎 You must have “User” or “Admin” privileges to access API token settings.
3

Navigate to API Access

  1. In the Settings panel, go to the left-hand menu.
  2. Click on “API Access” under the Account section.
4

Generate a New API Key

  1. Under the API Tokens section, click the “Generate New Token” button.
  2. In the prompt that appears:
    • Enter a meaningful label for the token (e.g., AirMDR Integration)
    • Click “Generate”
Best Practice: Use a unique label for each integration to track usage easily.
5

Copy and Store the API Key

  1. Click Copy to save it to your clipboard.
    This is the only time the API Key will be displayed.
    Copy and securely save the secret API key in your preferred password manager, or secure storage solution like password vault.
  2. Once you successfully copy and securely saved the Key, click Done.
    Email the API Key to AirMDR
    or
    Self configure Recorded Future in the AirMDR Integrations Dashboard.

Error Handling

Check AirMDR’s system logs for API timeout or failure events.

Support & Maintenance

Post-Setup Security Best Practices (Optional)

  • Token Rotation:
    API keys should be rotated every 90 days as a security best practice.
  • Update Integration:
    To update the API Key, go to AirMDR → Integrations → Recorded Future → Edit, then paste the new token and re-authenticate.

Skills Provided by this Integration

To view the details of Input Parameters and Output for the respective skills

Recorded Future API Testing

Open cURL and run the following command to check if your API Key is working: Sample cURLCommand
Replace CLIENT_X_RFTOKEN with your actual secret API key.

Configure OpenAI in the AirMDR Integrations Dashboard

  1. Navigate to AirMDR, provide the credentials, and click Login
  2. Navigate to the AirMDR Integrations Dashboard in the left navigation pane and select Integrations. Slack24 Pn
  3. Use the search option, enter the keyword “Recorded Future”, select the Connections tab, and click Create. Recorded Future1 Pn
  4. Enter an unique name to the Instance (e.g., your org name-RecordedFuture) to easily identify the user connection by AirMDR.
  5. Enter the generated API Key in the Authentication Details field params, and click Create. Recorded Future2 Pn