National Cyber Warfare Foundation (NCWF)

Recorded Future Debuts Autonomous Defense, Built for Machine-Speed Threats


0 user ratings
2026-09-30 17:19:30
milo
Blue Team (CND)
Recorded Future just revealed autonomous defense capabilities. The platform hunts, investigates, and stops threats on its own, acting on real intelligence.

Rethinking defense entirely


We know attackers are already using AI to operate at machine speed, running more frequent and more effective attacks. They're automating reconnaissance, standing up infrastructure, and pivoting faster than human analysts can triage an alert. We have seen the cyber kill chain that used to unfold step by step now happens in the blink of an eye, and defenders are struggling to keep up in a fight that no longer gives them time to react.


It's clear that organizations need to reduce risk, defend pre-attack, and act at machine speed. But beyond just moving faster, they may need to rethink defense entirely. Imagine not scrambling to keep pace with the threat landscape, but moving with it: changing as it changes and acting as fast as the attacker acts. That's a world where an autonomous defense system works alongside defenders, applying intelligence at the speed and scale today's threats demand.


Today at Mastercard RiskX in Arizona, we premiered an autonomous defense platform built into Recorded Future. The age of AI action has arrived, and we're excited to show you what's next. Read on to see how this capability came to be, why it's a fundamentally different way to defend, and how you can be a part of it.


From answers to actions


AI for threat intelligence has come a long way. In a short time, analysts and security leaders have gone from searching for answers to finding them fast, thanks to capabilities like AI Insights and Sessions in Recorded Future AI. At the core of it all is the Intelligence Graph®, which turns large sums of data and information into actionable insights, and gives Recorded Future AI the context to deliver the right answer to analysts in seconds.


That success created a new demand: Analysts and business leaders wanted this same intelligence, at the same speed, everywhere they worked — not just inside the Recorded Future Platform. That's why we built Recorded Future Model Context Protocol (MCP). Agents, whether ours or our customers', run across many tools and platforms. This gives them direct, standardized, and cost-efficient access to Recorded Future intelligence.


The Intelligence Graph®, Recorded Future AI's Insights and Sessions, and Recorded Future MCP have laid the foundation for what comes next: defending at the pace adversaries set. To keep up with adversaries, analysts need to act at their speed, confidently taking 10 actions where they once had time for one. They need to spend their time focused on business outcomes, not buried in process. Ultimately, they need a fundamentally different way to use intelligence and act. That's why we're building autonomous defense.


What autonomous defense can do


This is a different way to think about the day-to-day analyst workflow. Analysts can task Recorded Future’s autonomous defense with a goal, not just a question, and it will go from there: drawing on the Intelligence Graph®, deciding what the situation calls for, and delivering outputs directly into your team's existing tools across over 100 integrations. It can act on your behalf, clearing away work so your team can focus on the outcome, not the process.


Autonomous defense runs on the Intelligence Graph® with over 15 years of threat intelligence and analyst research, combined with your own organizational context through your Private Graph, so the system knows what's relevant before anything happens. It's the same intelligence layer customers already use across cyber operations, third-party risk, digital risk protection, and counter-fraud, now can be put to work taking agentic action. When your threat priorities shift or a new vulnerability surfaces, agents already understand why it matters to your environment and start acting in real time.


What this looks like from start to finish: A trigger like a new high-priority threat actor, a malicious website notification, or a critical third-party vulnerability starts the workflow. The Platform reasons through what matters, pulling intelligence and building a hunting package, checking a site's ownership to assess takedown eligibility, or drafting outreach and confirming approvals. Then it can act, including running the hunt and blocking the threat, initiating and monitoring a takedown, or notifying your third party and tracking remediation.


Agents default to fully autonomous execution, because defending at machine speed requires it, but teams that want human review first can dial back to managed autonomy. The result is a system, not just a model, that connects detection, investigation, and response into a single workflow. But a capability like this only matters if you can trust it, which is where Recorded Future’s autonomous defense sets itself apart.


A fundamentally different approach


AI security tools have exploded, but much of the industry feels oversold. Dashboards relabeled. SOAR engines rebranded, chatbots dressed up in analyst clothing. Security teams have grown skeptical of the pattern, and rightly so.


What makes Recorded Future's autonomous defense different?



  1. Reasoning models and agent frameworks are becoming commodities. Nearly any vendor can wire up an agent loop. What's scarce is trustworthy, structured intelligence for those agents to reason over. That's what we've spent over 15 years building, and it's the foundation every Recorded Future agent runs on. Frontier models generally lack this training on relevant data.

  2. It's grounded in the deepest threat intelligence available. Claims about a threat actor's infrastructure, a vulnerability's exploitation status, or a campaign's targeting come from the Intelligence Graph®: continuous analysis across open, dark, and technical web sources, enriched by Insikt Group's analysts. Not plausible-sounding guesses from general training data. Real intelligence, sourced, traceable, and trustworthy.

  3. It's architecturally agentic, not superficially so. Most agents have to poll the world to notice that something has changed. Recorded Future agents subscribe to changes in the Intelligence Graph® and get real-time triggers the moment something relevant moves, so they act on signals instead of burning cycles searching for them. This isn't a chat interface bolted onto a search box. It's purpose-built for how security work actually happens.

  4. Every output is auditable. Security teams can't operate on black-box AI. Trust requires transparency. Recorded Future shows its work, so every source, step, and conclusion can be traced. When it flags a threat as high priority, you can see exactly why.

  5. Intelligence that ends in a chat window has limited value. Recorded Future delivers outputs into SIEM platforms, ticketing systems, communication tools, and the rest of your security stack where the work actually happens.


This is the beginning


We believe that what we're announcing today is a real leap in what security teams can accomplish: workflows that can eliminate critical threats, hours returned to the analyst, and coverage that wasn't previously achievable. And we're not stopping here.


We're already building expanded multi-agent architectures, where AI agents collaborate on complex, long-running investigations. We're building toward AI that monitors threat groups and updates intelligence continuously over weeks, not sessions. And we're extending the integration layer so Recorded Future AI doesn't just deliver intelligence into your stack, it participates in it.


This is a new era of defense, and we know that many of our customers are as excited about it as we are. If you're a Recorded Future customer and want to be part of what's next, apply for early access here. Autonomous defense is planned for general availability early next year.



Source: RecordedFuture
Source Link: https://www.recordedfuture.com/blog/autonomous-defense-platform


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.