Back to Intelligence

Recorded Future MCP Server: Securing Agentic AI Access to Threat Intelligence — Deployment and Detection Guide

SA
Security Arsenal Team
September 28, 2026
12 min read

Recorded Future has launched a Model Context Protocol (MCP) server that exposes its Intelligence Graph® directly to AI agents and LLM-driven workflows. The pitch is straightforward and, frankly, significant: instead of analysts pivoting manually through a threat intel portal, agentic security operations can now query Recorded Future's intelligence in natural language, enrich alerts, correlate entities, and drive automated decision-making inside AI-orchestrated SOC workflows.

I've spent the better part of two decades watching SOC tooling evolve from grep-and-pray to SIEM correlation to SOAR playbooks. Agentic operations — where an LLM agent autonomously enriches, triages, and in some cases acts on alerts — is the next real shift, not marketing vapor. But here's the practitioner's reality: every MCP server you deploy is a new privileged API endpoint sitting between an AI model and your most sensitive data. MCP is a young protocol. Its security model is still maturing, and attackers have noticed. Tool poisoning, prompt injection against agent workflows, rogue MCP servers, and over-permissive tool scopes are active, current attack patterns — not theoretical ones.

This post covers both sides: how Recorded Future's MCP changes defensive operations for the better, and how to deploy it so it doesn't become the soft underbelly of your SOC.

What Recorded Future's MCP Actually Does

MCP is an open protocol (originated by Anthropic, now broadly adopted across the AI ecosystem) that standardizes how LLMs and AI agents connect to external tools and data sources. Recorded Future's implementation gives authorized AI agents direct, structured access to the Intelligence Graph — their correlated dataset of threat actors, infrastructure, vulnerabilities, malware, and observables.

Practical defensive use cases this unlocks:

  • Autonomous alert enrichment. An agent triaging a phishing alert can query Recorded Future for domain risk scores, associated infrastructure, and linked threat actors without an analyst touching a console.
  • Vulnerability prioritization. Agents can pull real-time exploitation intelligence to re-rank your patch queue based on what's actually being weaponized, not just CVSS.
  • Threat hunting accelerators. Natural-language hunt hypotheses get translated into intelligence lookups against the graph at machine speed.
  • SOAR/agent hybrid workflows. MCP tools can be composed into multi-step agentic chains — enrich, correlate, decide, escalate.

The affected "platform" here isn't a vulnerability in Recorded Future's product — it's your environment the moment you wire an LLM agent into a high-value intelligence API. That's the threat model we need to address.

The Threat Model: Why MCP Servers Are the New High-Value Target

There are no CVEs associated with this announcement, and I won't invent any. But the MCP attack surface is well-documented in current 2025–2026 tradecraft discussion, and any honest assessment has to cover it:

1. Rogue and typosquatted MCP servers. The MCP ecosystem relies on developers pulling server packages from registries (npm, PyPI). An attacker publishing a malicious recordedfuture-mcp lookalike package gets code execution inside your agent runtime with whatever credentials you've handed it. Supply-chain compromise of MCP tooling is a present-day risk, not a hypothetical.

2. Prompt injection via tool output. When an agent ingests threat intelligence data — which is, by definition, attacker-adjacent content like malware descriptions, phishing lures, and adversary-controlled strings — a crafted payload embedded in returned data can attempt to hijack the agent's instruction context. An intelligence feed is literally a channel carrying adversary-authored text into your agent's context window.

3. Credential and token exposure. MCP servers authenticate to upstream APIs with tokens. Those tokens live in config files, environment variables, or secrets stores on the host running the agent. A Recorded Future API token is a high-value target — it represents paid access to one of the richest intelligence datasets available.

4. Over-scoped agents. If your agent can query intelligence and execute response actions, a compromised or manipulated agent inherits both. Blast radius control is an architectural decision you make at deployment time.

Detection & Response: Monitoring Your MCP and Agentic Layer

If you deploy Recorded Future's MCP server (or any MCP server), you need telemetry on three things: what processes the agent runtime spawns, where the MCP server connects on the network, and what happens to the credentials. These detections assume a standard deployment where the MCP server runs as a local process (Node.js or Python) invoked by an agent client such as Claude Desktop, Cursor, or a custom orchestrator.

Sigma Rules

YAML
---
title: MCP Server Process Spawning Unexpected Child Processes
id: 3f8a2c14-7b1e-4d59-a6c2-9e1f0a5b8d73
status: experimental
description: Detects MCP server runtimes (node, python, uvx, npx) spawning shells, download cradles, or reconnaissance tools. MCP servers should be leaf processes that make API calls — child process creation is a strong indicator of tool poisoning, a malicious package, or prompt-injection-driven execution.
references:
  - https://www.recordedfuture.com/blog/mcp-intelligence-layer
  - https://attack.mitre.org/techniques/T1059/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.execution
  - attack.t1059
logsource:
  category: process_creation
  product: windows
detection:
  selection_parent:
    ParentImage|endswith:
      - '\node.exe'
      - '\python.exe'
      - '\python3.exe'
      - '\uvx.exe'
      - '\npx.exe'
  selection_child:
    Image|endswith:
      - '\powershell.exe'
      - '\pwsh.exe'
      - '\cmd.exe'
      - '\curl.exe'
      - '\wget.exe'
      - '\certutil.exe'
      - '\bitsadmin.exe'
      - '\mshta.exe'
  condition: selection_parent and selection_child
falsepositives:
  - MCP servers that legitimately wrap CLI tooling during development; baseline known servers and tune by ParentCommandLine
level: high
---
title: Suspicious Access to MCP Configuration and Credential Files
id: 8c4d1e96-2a7f-4b38-b5d1-6f3e9a0c4d82
status: experimental
description: Detects processes other than approved agent clients reading MCP configuration files (claude_desktop_config.json, mcp.json, .env) which frequently contain API tokens for services such as Recorded Future. Token theft from MCP configs is an emerging credential-access vector.
references:
  - https://attack.mitre.org/techniques/T1552/001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.credential_access
  - attack.t1552.001
logsource:
  category: file_event
  product: windows
detection:
  selection_path:
    TargetFilename|contains:
      - 'claude_desktop_config.json'
      - '\.cursor\mcp.json'
      - '\mcp\settings.json'
      - '\.codeium\windsurf\mcp_config.json'
  filter_legit:
    Image|endswith:
      - '\Claude.exe'
      - '\Cursor.exe'
      - '\Code.exe'
      - '\Windsurf.exe'
  condition: selection_path and not filter_legit
falsepositives:
  - Backup software, EDR scanners, and IT management tools; filter known binaries by hash or signer
level: high
---
title: Outbound Connection to Unapproved Threat Intelligence API Endpoint
id: b2e7a3f5-9c1d-4e68-a7b4-2d8f1c6e5a09
status: experimental
description: Detects MCP-related runtimes establishing network connections to domains outside the approved intelligence provider list. Legitimate Recorded Future MCP traffic should terminate at Recorded Future infrastructure; connections elsewhere may indicate a rogue MCP server or data exfiltration through the agent channel.
references:
  - https://attack.mitre.org/techniques/T1071/001/
author: Security Arsenal
date: 2026/04/06
tags:
  - attack.command_and_control
  - attack.t1071.001
  - attack.exfiltration
logsource:
  category: network_connection
  product: windows
detection:
  selection_process:
    Image|endswith:
      - '\node.exe'
      - '\python.exe'
      - '\uvx.exe'
  filter_approved:
    DestinationHostname|endswith:
      - '.recordedfuture.com'
      - '.anthropic.com'
      - '.npmjs.org'
      - '.pypi.org'
  filter_local:
    DestinationIp|cidr:
      - '10.0.0.0/8'
      - '172.16.0.0/12'
      - '192.168.0.0/16'
  condition: selection_process and not filter_approved and not filter_local
falsepositives:
  - Additional legitimate MCP servers connecting to their own vendor APIs; maintain an allowlist of approved MCP provider domains and update as deployments grow
level: medium

KQL — Microsoft Sentinel / Defender Hunt

KQL — Microsoft Sentinel / Defender
// Hunt: MCP runtime processes spawning shells or download tools
// Run over 14 days to establish baseline, then alert on new Parent/Child pairs
let Lookback = 14d;
let McpRuntimes = dynamic(["node.exe", "python.exe", "python3.exe", "uvx.exe", "npx.exe", "uv.exe"]);
let SuspiciousChildren = dynamic(["powershell.exe", "pwsh.exe", "cmd.exe", "curl.exe", "wget.exe", "certutil.exe", "bitsadmin.exe", "mshta.exe", "rundll32.exe", "bash.exe", "sh.exe"]);
DeviceProcessEvents
| where TimeGenerated > ago(Lookback)
| where InitiatingProcessFileName in~ (McpRuntimes)
| where FileName in~ (SuspiciousChildren)
| extend ParentCmd = InitiatingProcessCommandLine, ChildCmd = ProcessCommandLine
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), ExecutionCount = count(), DistinctHosts = dcount(DeviceName)
    by DeviceName, InitiatingProcessFileName, ParentCmd, FileName, ChildCmd, AccountName
| where ExecutionCount < 20  // suppress high-volume known-good automation
| sort by FirstSeen desc;
KQL — Microsoft Sentinel / Defender
// Hunt: Reads of MCP config / credential files by unexpected processes
let Lookback = 7d;
let ApprovedReaders = dynamic(["claude.exe", "cursor.exe", "code.exe", "windsurf.exe", "msmpeng.exe"]);
let McpConfigPaths = dynamic(["claude_desktop_config.json", "mcp.json", "mcp_config.json", ".env"]);
DeviceFileEvents
| where TimeGenerated > ago(Lookback)
| where FileName has_any (McpConfigPaths) or FolderPath has_any ("\\.cursor\\", "\\Claude\\")
| where ActionType in~ ("FileCreated", "FileModified", "FileRenamed")
   or (ActionType == "FileAccessed" and not (InitiatingProcessFileName in~ (ApprovedReaders)))
| project TimeGenerated, DeviceName, ActionType, FolderPath, FileName,
          InitiatingProcessFileName, InitiatingProcessCommandLine, InitiatingProcessAccountName
| sort by TimeGenerated desc;

Velociraptor VQL

VQL — Velociraptor
-- Hunt: enumerate MCP server processes and their network connections
-- Deploy as a hunt across the fleet to map where agentic tooling actually runs
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Name =~ '(?i)node|python|uvx|npx'
  AND CommandLine =~ '(?i)mcp|model.context.protocol|recordedfuture'
VQL — Velociraptor
-- Hunt: locate MCP configuration files that may contain API tokens
-- Review results for unauthorized servers or plaintext credentials
SELECT FullPath, Size, Mtime, Btime
FROM glob(globs=[
  'C:/Users/*/AppData/Roaming/Claude/claude_desktop_config.json',
  'C:/Users/*/.cursor/mcp.json',
  'C:/Users/*/.codeium/windsurf/mcp_config.json',
  'C:/Users/*/.config/*/mcp*.json'
])
VQL — Velociraptor
-- Hunt: network connections from MCP runtimes to non-approved destinations
-- Tune the approved regex to your sanctioned intelligence providers
SELECT Pid, Name, CommandLine, Family, Type, Status,
       Laddr, Lport, Raddr, Rport
FROM netstat()
WHERE Name =~ '(?i)node|python|uvx'
  AND Status =~ 'ESTAB'
  AND NOT Raddr =~ '^(10\\.|172\\.(1[6-9]|2[0-9]|3[01])\\.|192\\.168\\.|127\\.)'

Hardening and Audit Script

PowerShell
# Audit-MCPDeployment.ps1
# Run as Administrator on hosts where agent clients / MCP servers are deployed.
# Inventories MCP configs, flags plaintext tokens, and checks file ACLs.

$ErrorActionPreference = 'SilentlyContinue'
$report = @()

# --- Locate MCP configuration files ---
$configPaths = @(
    "$env:APPDATA\Claude\claude_desktop_config.json",
    "$env:USERPROFILE\.cursor\mcp.json",
    "$env:USERPROFILE\.codeium\windsurf\mcp_config.json"
)

foreach ($path in $configPaths) {
    if (Test-Path $path) {
        $content = Get-Content $path -Raw

        # Flag plaintext API tokens in config
        $hasPlaintextToken = $content -match '(?i)(api[_-]?key|token|secret)"\s*:\s*"[A-Za-z0-9_\-]{20,}'

        # Check ACL for overly broad read access
        $acl = Get-Acl $path
        $broadAccess = $acl.Access | Where-Object {
            $_.IdentityReference -match 'Everyone|Users|Authenticated Users' -and
            $_.FileSystemRights -match 'Read|FullControl|Modify'
        }

        $report += [PSCustomObject]@{
            ConfigFile        = $path
            PlaintextToken    = $hasPlaintextToken
            OverlyPermissive  = [bool]$broadAccess
            LastModified      = (Get-Item $path).LastWriteTime
        }

        # Tighten ACLs: restrict to current user + SYSTEM + Administrators
        if ($broadAccess) {
            Write-Warning "Tightening ACL on $path"
            $user = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name
            $newAcl = New-Object System.Security.AccessControl.FileSecurity
            $newAcl.SetAccessRuleProtection($true, $false)  # disable inheritance
            foreach ($identity in @($user, 'NT AUTHORITY\SYSTEM', 'BUILTIN\Administrators')) {
                $rule = New-Object System.Security.AccessControl.FileSystemAccessRule(
                    $identity, 'FullControl', 'Allow')
                $newAcl.AddAccessRule($rule)
            }
            Set-Acl -Path $path -AclObject $newAcl
        }
    }
}

# --- Inventory running MCP-related processes ---
$mcpProcs = Get-Process | Where-Object {
    $_.Name -match '^(node|python|python3|uvx|npx|uv)$'
} | ForEach-Object {
    $cmd = (Get-CimInstance Win32_Process -Filter "ProcessId=$($_.Id)").CommandLine
    if ($cmd -match '(?i)mcp|recordedfuture') {
        [PSCustomObject]@{
            PID         = $_.Id
            Process     = $_.Name
            CommandLine = $cmd
            StartTime   = $_.StartTime
        }
    }
}

Write-Output "=== MCP Config Audit ==="
$report | Format-Table -AutoSize
Write-Output "=== Running MCP Server Processes ==="
$mcpProcs | Format-List

if ($report.PlaintextToken -contains $true) {
    Write-Warning "Plaintext API tokens detected in MCP configs. Migrate to environment variables or a secrets manager and rotate exposed tokens immediately."
}
Bash / Shell
#!/usr/bin/env bash
# audit-mcp-linux.sh — inventory MCP configs and flag plaintext tokens on Linux/macOS hosts
set -euo pipefail

CONFIG_GLOBS=(
  "$HOME/.config/Claude/claude_desktop_config.json"
  "$HOME/.cursor/mcp.json"
  "$HOME/.codeium/windsurf/mcp_config.json"
)

echo "=== MCP Config Audit ==="
for cfg in "${CONFIG_GLOBS[@]}"; do
  if [[ -f "$cfg" ]]; then
    perms=$(stat -c '%a' "$cfg" 2>/dev/null || stat -f '%Lp' "$cfg")
    echo "[FOUND] $cfg (perms: $perms)"
    if grep -Eiq '(api[_-]?key|token|secret)"[[:space:]]*:[[:space:]]*"[A-Za-z0-9_-]{20,}' "$cfg"; then
      echo "  [ALERT] Plaintext token pattern detected — rotate and move to secrets manager"
    fi
    if [[ "$perms" != "600" ]]; then
      echo "  [FIX] Tightening permissions to 600"
      chmod 600 "$cfg"
    fi
  fi
done

echo "=== Running MCP-Related Processes ==="
ps -eo pid,ppid,user,comm,args | grep -Ei 'node|python|uvx|npx' | grep -Ei 'mcp|recordedfuture' | grep -v grep || echo "None found"

echo "=== Outbound Connections from MCP Runtimes ==="
ss -tnp 2>/dev/null | grep -Ei 'node|python|uvx' | grep -vE '127\.0\.0\.1|::1' || echo "None found (or insufficient privileges — re-run with sudo)"

Remediation and Secure Deployment Checklist

There's no patch here — this is architecture and hygiene. If you're deploying Recorded Future's MCP server (or any agentic intelligence layer), hold the line on these:

  1. Pin and verify the MCP server package. Install only from Recorded Future's official distribution channel per their documentation at the official announcement. Pin the exact version and hash in your package manifest. Never install MCP servers from unverified registry listings — check publisher identity, not just package name.

  2. Scope the API token to the minimum. Issue a dedicated Recorded Future API token for the MCP integration with read-only intelligence access. Do not reuse a token that also powers enrichment pipelines or has administrative scope. Rotate on a defined schedule and on any suspected exposure.

  3. Store tokens in a secrets manager, not config files. Use environment injection from your vault (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) rather than plaintext env blocks in mcp.json. The audit scripts above will tell you if you're currently exposed.

  4. Run the MCP server under a dedicated low-privilege service account. No domain admin, no sudo, no shared analyst accounts. If the agent gets manipulated via prompt injection, the account's privileges define the blast radius.

  5. Egress-filter the agent host. The MCP runtime only needs to reach Recorded Future's API endpoints and your LLM provider. Deny-all-else egress on that host kills most exfiltration and rogue-server callbacks dead.

  6. Treat tool output as untrusted input. Instruct agent system prompts to treat intelligence data as data, never as instructions. Where your agent framework supports it, isolate tool results from the instruction channel and add human-in-the-loop gates for any action the agent proposes (blocking, ticket closure, email quarantine release).

  7. Log everything the agent does. Capture tool invocations, parameters, and responses to your SIEM. When something goes wrong with an agentic workflow, your investigation will live or die on that telemetry. If you're forwarding to Sentinel, the KQL hunts above give you a starting point.

  8. Maintain an approved MCP server inventory. Any MCP server not on the list is an incident until proven otherwise. The VQL hunts above make fleet-wide inventory a 10-minute exercise.

Executive Takeaways

  • Agentic SOC operations are arriving whether your security program is ready or not — Recorded Future's MCP launch is a signal that threat intelligence consumption is moving from portals to agent pipelines. Get governance in place before adoption, not after the first incident.
  • The intelligence feed is now part of your attack surface. Adversary-controlled strings flow directly into your agent's context. Design for prompt-injection resilience.
  • API tokens in MCP config files are the new .env leak. Audit for plaintext secrets this week; the scripts above do it for you.
  • Visibility gaps in the agent layer are where the next generation of intrusions will hide. If your SOC can't see MCP process trees, network egress, and config file access, you're flying blind on the fastest-growing part of your stack.

Related Resources

Security Arsenal Managed SOC Services AlertMonitor Platform Book a SOC Assessment soc-mdr Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.