Recorded Future arms security teams with the only complete threat intelligence solution powered by patented machine learning to lower risk. Recorded Future can help you find threats 10 times faster, identify 22 percent more threats before impact, and resolve threats 63 percent quicker.
Threat intelligence can sit at the very center of your information security strategy, applied to add value across all functions and teams: -CISOs gain critical insights into the threat landscape to inform strategy. -Threat analysts proactively defend their companies against cyberattacks with alerts and insight. -Security operations can investigate indicators 10 times faster and more effectively prioritize vulnerabilities. -Incident responders can investigate incidents more confidently with a broader context.
THE SOLUTION
-SaaS Platform: Research, analyze, and collaborate on intelligence through our intuitive web interface. -Integrations: Layer our contextualized threat intelligence onto your existing security infrastructure.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
You buy each intelligence capability as a separate contract unit, priced independently rather than as stacked tiers. The units cover distinct use cases: Threat Intelligence, SecOps Intelligence, Brand Intelligence, Vulnerability Intel, Geopolitical Intel, Attack Surface Intelligence (ASI), and Third Party Intel. Several units scale by capacity or coverage. Identity Intel External supports up to 1M identities, while Identity Intel Workforce supports up to 25k workforce identities. Third Party Intel monitors up to 100 companies. Other units set user seat limits, ranging from 2 to 10 users. You select and combine the units that match your needs.
Top-of-mind questions for buyers
How is one Identity Intel unit counted, and what is the difference between the Workforce and External options?
Identity Intel Workforce covers up to 25,000 workforce identities, meaning your own employee accounts. Identity Intel External covers up to 1 million identities, aimed at broader external credential monitoring. Each option is a separate contract unit sized by identity count, so you pick based on which population you need to monitor.
If I need more than one capability, do the units bundle at a combined rate or bill separately?
Each intelligence capability is a separate contract unit priced on its own. Buying multiple units does not merge them into one tier or combined rate. Your total is the sum of each unit you select. This lets you add or drop capabilities like Threat Intelligence, ASI, or Third Party Intel independently.
What happens if I exceed a unit's capacity, such as more than 100 monitored companies or the listed user seats?
Each unit sets a fixed capacity: Third Party Intel monitors up to 100 companies, and user-based units cap seats from 2 to 10 depending on the capability. Growing past a limit means adding capacity rather than automatic overage billing. Contact the vendor to size a unit for larger needs.
www.recordedfuture.com+1
Helpful?
Vendor refund policy
All orders and fees are non-cancellable and non-refundable once placed except as required by law.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Patented machine learning algorithms enable identification of threats with enhanced accuracy and speed compared to traditional methods.
Real-Time Threat Intelligence Integration
Contextualized threat intelligence can be integrated into existing security infrastructure including SIEM, SOAR, and incident response systems.
Browser Extension for Threat Context
Browser extension provides accessible threat intelligence context from any web-based application without requiring separate tool switching.
Threat Investigation and Analysis Portal
Web-based portal enables research, analysis, collaboration on intelligence with real-time alerting and dashboard visualization of trending threats.
Multi-Function Security Team Support
Platform supports threat intelligence application across security operations, incident response, threat analysis, and strategic planning functions.
Security Information and Event Management
Real-time monitoring and visibility for threat detection including ransomware, insider threats, and cloud attacks with security analytics for rapid investigation and prioritization of critical threats.
Incident Response Automation and Orchestration
Automation and orchestration of incident response workflows with consistent, optimized, and measurable process execution.
Enterprise-Grade AI and Automation
Embedded artificial intelligence and automation capabilities designed to increase analyst productivity and accelerate incident lifecycle management.
Multi-Source Data Correlation
Correlation of data across users, networks, and cloud-native services to identify threats including cloud misconfigurations, policy changes, and suspicious user activity with alert deduplication.
Hybrid and Cloud Environment Integration
Centralized visibility across hybrid cloud and on-premises environments with deep integrations to AWS security services including Security Hub, CloudTrail, GuardDuty, Network Firewall, WAF, Detective, CloudWatch, and VPC Flow Logs.
Multi-Source Threat Data Integration
Correlates and ingests security data from Trellix Security Platform and over 500 third-party tools including 13 AWS integrations to create unified threat visibility across the security stack.
AI-Driven Detection and Alert Triage
Applies artificial intelligence-driven analytics and automated alert triage to prioritize threats and provide GenAI-powered insights for threat investigation and remediation guidance.
No-Code Automation for Investigation and Response
Provides UI-driven, point-and-click automation capabilities to offload repetitive security operations tasks and accelerate investigation and response workflows.
Pre-Built Analytics and Correlation Rules
Utilizes pre-built analytics and correlation rules to rapidly correlate multi-vector threat detections and reconstruct complete attack narratives from ingested security events.
Hybrid and Air-Gapped Deployment Support
Supports deployment across cloud, hybrid, and air-gapped environments with flexible integration architecture for diverse infrastructure configurations.
Easy-to-Use Threat Intelligence with Powerful AI Insights
Reviewed on Sep 21, 2026
Review provided by G2
What do you like best about the product?
I like that Recorded Future is easy to use and presents threat intelligence clearly. The platform performs well and integrates with other security tools, which helps with investigations. The threat data and AI-driven insights are useful for quickly understanding risks. Support and onboarding are also helpful.
What do you dislike about the product?
The main downside is the cost, as some advanced features can be expensive. The platform can also feel complex at first, with a lot of information to review. Some alerts may need extra investigation, and onboarding can take time before users become fully comfortable with all the features. Reporting and dashboards could also be more customizable for different security teams.
What problems is the product solving and how is that benefiting you?
Recorded Future helps us identify threats faster by providing clear intelligence on suspicious IPs, domains, vulnerabilities, and emerging risks. This saves investigation time, improves decision-making, and helps us respond to security incidents more quickly. It also helps us prioritise the most important risks.
Consulting
Powerful Threat Intelligence, But Complexity and Info Overload Slow New Users
Reviewed on Sep 18, 2026
Review provided by G2
What do you like best about the product?
What I like best about Recorded Future is the quality and breadth of its threat intelligence. It brings together information from multiple sources and makes it easy to identify relevant threats, vulnerabilities, malicious activity, and emerging risks. The platform is also useful for supporting proactive security monitoring and threat hunting.
What do you dislike about the product?
One potential downside is that the platform can be quite complex, especially for new users, and it may take some time to fully understand and use all of its features. The amount of information available can also be overwhelming, making it sometimes difficult to quickly identify the most relevant intelligence. Better customization and prioritization of information could make the overall user experience even more efficient
What problems is the product solving and how is that benefiting you?
It helps me quickly find and understand relevant cybersecurity information without having to search across many different sources. This saves time during daily research and investigations, while giving me a clearer view of potential threats, vulnerabilities, and suspicious activity that may require further attention.
Verified User
Exceptional Security, Effortless Setup
Reviewed on Sep 18, 2026
Review provided by G2
What do you like best about the product?
I really like the security features of Recorded Future, especially its architecture. The overall experience I've had using it has been positive, and I feel satisfied with the safety aspect. Additionally, the initial setup was quite easy, and I appreciate that.
What do you dislike about the product?
nil
What problems is the product solving and how is that benefiting you?
I use Recorded Future to detect cybersec threats, appreciating its security architecture and customer satisfaction focus.
Omar L.
Easy Setup Experience with Recorded Future
Reviewed on Sep 17, 2026
Review provided by G2
What do you like best about the product?
The setup was extremely easy, with no issues, and anyone can rely on it.
What do you dislike about the product?
I think Recorded Future can be improved to provide more accurate answers. I hope it has more data to respond with precise answers instead of responding with any answer without sufficient accuracy.
What problems is the product solving and how is that benefiting you?
n/a
Haftu A.
Excited for Cybersecurity Potential, a 10/10 Recommendation
Reviewed on Sep 16, 2026
Review provided by G2
What do you like best about the product?
I like that Recorded Future focuses on cybersecurity, especially in today's world with many scammers and hackers. I plan to use threat intelligence and identity intelligence, as well as threat monitoring.
What do you dislike about the product?
No
What problems is the product solving and how is that benefiting you?