Recorded Future arms security teams with the only complete threat intelligence solution powered by patented machine learning to lower risk. Recorded Future can help you find threats 10 times faster, identify 22 percent more threats before impact, and resolve threats 63 percent quicker.
Threat intelligence can sit at the very center of your information security strategy, applied to add value across all functions and teams: -CISOs gain critical insights into the threat landscape to inform strategy. -Threat analysts proactively defend their companies against cyberattacks with alerts and insight. -Security operations can investigate indicators 10 times faster and more effectively prioritize vulnerabilities. -Incident responders can investigate incidents more confidently with a broader context.
THE SOLUTION
-SaaS Platform: Research, analyze, and collaborate on intelligence through our intuitive web interface. -Integrations: Layer our contextualized threat intelligence onto your existing security infrastructure.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy each intelligence capability as a separate contract unit, priced independently rather than as stacked tiers. The units cover distinct use cases: Threat Intelligence, SecOps Intelligence, Brand Intelligence, Vulnerability Intel, Geopolitical Intel, Attack Surface Intelligence (ASI), and Third Party Intel. Several units scale by capacity or coverage. Identity Intel External supports up to 1M identities, while Identity Intel Workforce supports up to 25k workforce identities. Third Party Intel monitors up to 100 companies. Other units set user seat limits, ranging from 2 to 10 users. You select and combine the units that match your needs.
Top-of-mind questions for buyers
How is one Identity Intel unit counted, and what is the difference between the Workforce and External options?
Identity Intel Workforce covers up to 25,000 workforce identities, meaning your own employee accounts. Identity Intel External covers up to 1 million identities, aimed at broader external credential monitoring. Each option is a separate contract unit sized by identity count, so you pick based on which population you need to monitor.
If I need more than one capability, do the units bundle at a combined rate or bill separately?
Each intelligence capability is a separate contract unit priced on its own. Buying multiple units does not merge them into one tier or combined rate. Your total is the sum of each unit you select. This lets you add or drop capabilities like Threat Intelligence, ASI, or Third Party Intel independently.
What happens if I exceed a unit's capacity, such as more than 100 monitored companies or the listed user seats?
Each unit sets a fixed capacity: Third Party Intel monitors up to 100 companies, and user-based units cap seats from 2 to 10 depending on the capability. Growing past a limit means adding capacity rather than automatic overage billing. Contact the vendor to size a unit for larger needs.
www.recordedfuture.com+1
Helpful?
Vendor refund policy
All orders and fees are non-cancellable and non-refundable once placed except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Patented machine learning algorithms enable identification of threats with enhanced accuracy and speed compared to traditional methods.
Real-Time Threat Intelligence Integration
Contextualized threat intelligence can be integrated into existing security infrastructure including SIEM, SOAR, and incident response systems.
Browser Extension for Threat Context
Browser extension provides accessible threat intelligence context from any web-based application without requiring separate tool switching.
Threat Investigation and Analysis Portal
Web-based portal enables research, analysis, collaboration on intelligence with real-time alerting and dashboard visualization of trending threats.
Multi-Function Security Team Support
Platform supports threat intelligence application across security operations, incident response, threat analysis, and strategic planning functions.
Security Information and Event Management
Real-time monitoring and visibility for threat detection including ransomware, insider threats, and cloud attacks with security analytics for rapid investigation and prioritization of critical threats.
Incident Response Automation and Orchestration
Automation and orchestration of incident response workflows with consistent, optimized, and measurable process execution.
Enterprise-Grade AI and Automation
Embedded artificial intelligence and automation capabilities designed to increase analyst productivity and accelerate incident lifecycle management.
Multi-Source Data Correlation
Correlation of data across users, networks, and cloud-native services to identify threats including cloud misconfigurations, policy changes, and suspicious user activity with alert deduplication.
Hybrid and Cloud Environment Integration
Centralized visibility across hybrid cloud and on-premises environments with deep integrations to AWS security services including Security Hub, CloudTrail, GuardDuty, Network Firewall, WAF, Detective, CloudWatch, and VPC Flow Logs.
Multi-Source Threat Data Integration
Correlates and ingests security data from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
AI-Driven Detection and Alert Triage
Applies artificial intelligence-driven analytics and automated alert triage to prioritize threats and provide GenAI-powered insights for threat investigation and remediation guidance.
No-Code Automation for Investigation and Response
Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
Pre-Built Analytics and Correlation Rules
Utilizes pre-built analytics and correlation rules to rapidly correlate multi-vector threat detections and reconstruct complete attack narratives from ingested security events.
Hybrid and Air-Gapped Deployment Support
Supports deployment across cloud, hybrid, and air-gapped environments with flexible integration architecture for diverse infrastructure configurations.
User-Friendly Recording and CRM Solution with Room for Improvement
Reviewed on Sep 29, 2026
Review provided by G2
What do you like best about the product?
I like Recorded Future because it allows me to use recorded sessions for meetings, which is really helpful if I get busy or distracted elsewhere. I really appreciate its user-friendly interface, which has no hidden catches, and the built-in recording feature that makes it easy to start and report sessions without needing another app like Zoom. It's easy and simple. I also use it for training purposes and as a CRM, which is great.
What do you dislike about the product?
I think the quality of the video recordings could definitely be improved. Sometimes the microphone quality is a bit of an issue too; I've noticed it stumbles occasionally, but it's not a huge problem.
What problems is the product solving and how is that benefiting you?
I use Recorded Future to review meetings and gain insights when I've missed something. It's user-friendly and helps me with disruptions using recorded sessions. The built-in recording feature is convenient without needing extra apps, making it simple and quick to use.
Information Services
Powerful Real-Time Threat Intelligence, But a Steep Learning Curve and High Cost
Reviewed on Sep 29, 2026
Review provided by G2
What do you like best about the product?
Recorded Future provides exceptional real-time threat intelligence that gives our team actionable insights before potential security incidents occur. The Intelligence Graph automatically correlates vast amounts of data across the open, deep, and dark web, which significantly speeds up our threat hunting and incident response workflows. Its seamless integration options with existing SIEM and security tools help streamline alerts, reduce false positives, and improve our overall cybersecurity posture.
What do you dislike about the product?
While Recorded Future is a powerful platform, its high cost can be prohibitive for smaller organizations or teams with tight budgets. The sheer volume of data and intelligence can also feel overwhelming initially, creating a steep learning curve for newer analysts. Navigating and customizing advanced query filters takes time to master, and fine-tuning alert settings is necessary to avoid notification fatigue from minor updates.
What problems is the product solving and how is that benefiting you?
Recorded Future helps us solve the critical challenge of sifted threat data overload by consolidating real-time threat intelligence into clear risk scores. Instead of manually monitoring dark web forums or unvetted feed sources, our security team receives early warnings regarding leaked credentials, active exploits, and target vulnerabilities. This proactive visibility enables us to prioritize patch management, accelerate incident response, and significantly reduce organizational cyber exposure.
Samuel Z.
Streamlined Threat Detection, Premium Pricing
Reviewed on Sep 28, 2026
Review provided by G2
What do you like best about the product?
I really like Recorded Future's ability to bring structure, clarity, and speed to high-pressure security environments. It helps in detecting, understanding, and mitigating cyber threats effectively. The out-of-the-box phase of setup was easy as soon as I got my login credentials, and that was a smooth experience.
What do you dislike about the product?
I find the premium pricing and fragmented licensing of Recorded Future to be a bit challenging. The platform has a high total cost of ownership and uses a modular licensing structure, meaning that key capabilities like identity intelligence, brand protection, or third-party risk often require separate expensive add-on licenses. For smaller security teams or companies with tighter budgets, the price-to-value ratio for these incremental modules can be hard to justify.
What problems is the product solving and how is that benefiting you?
I use Recorded Future to detect, understand, and mitigate cyber threats, which brings structure, clarity, and speed to high-pressure security environments.
Computer & Network Security
Powerful and Efficient, but the Query Language and Learning Curve Need Simplifying
Reviewed on Sep 25, 2026
Review provided by G2
What do you like best about the product?
The UI has improved over time, the more minimal it gets, the easier it is to use and navigate. Integrations such as the sandboxing capabilities make work more efficient and secure. Performance is good, though the query language remains hard to keep up with due to its complexity and how it is not as straightforward as variables are named. Pricing is reasonable based on the tool capabilities vs market. Onboarding was supported well with workshops. I have not used the AI tool much, but its recommended workflows are quite helpful in investigating different indicator types.
What do you dislike about the product?
The query language is too complex and not aligned with the variable names. Onboarding and continuing to use the platform when you are not on it every day is challenging due to the high knowledge barrier to usage, in conjunction with the changing UI and additional features, it can be hard to navigate.
What problems is the product solving and how is that benefiting you?
Recorded future helps quickly assess external exposure of a number of clients, but due to security reasons, most clients are unable to be integrated into RF itself, which restricts a lot of the tool's core functionality and value. The insikt group reports are largely helpful for intelligence production, though a number of news and research items are published too late, and competitors such as feedly have a significant upper hand on OSINT news correlation and analysis.
Marta J.
My go-to tool for quick threat context
Reviewed on Sep 24, 2026
Review provided by G2
What do you like best about the product?
What I like most is how fast I can get context on a threat. When an IP, domain or CVE shows up in an alert, I can check it in Recorded Future and immediately see a risk score, why it was flagged and what it's linked to, instead of digging through five different sources. The browser extension and the SIEM integrations save me a lot of time, and the alerts are usually relevant, so I'm not drowning in noise. It also helps when I have to explain a risk to people outside the security team, because the reports are easy to follow.
What do you dislike about the product?
The interface can feel overwhelming at first because there's so much data, and it took me a while to learn where everything is and how to tune the alerts. Some risk scores are hard to interpret without opening the evidence behind them, and every so often a low-priority alert still gets through. I'd also like more flexibility in custom reporting and dashboards, since the built-in views don't always match what I need to show. Some of the more advanced features also seem to sit behind higher-tier access, so I can't always use everything I see mentioned.
What problems is the product solving and how is that benefiting you?
I use it in my day-to-day work as a Cyber Threat Analyst. I can’t count how much time I would have wasted if I didn’t have the opportunity to use Recorded Future. It feels like it brings together all the necessary tools and data that are crucial for me to carry out deep, thorough investigations and support effective remediation.