Recorded Future's Insikt Group research team combines human expertise with automated analysis to produce actionable threat intelligence. The team comprises individuals with backgrounds in government, military, law enforcement, and intelligence agencies, bringing decades of experience to their work. This approach, described as a "centaur model," leverages seasoned human judgment alongside automated data indexing and analysis, aiming to achieve insights that neither component could produce independently. The name "Insikt" is Swedish for "insight."
Insikt Group analysts utilize their deep understanding of specific adversary groups and their tactics, techniques, and procedures (TTPs) to contextualize data within broader geopolitical and criminal landscapes. This allows them to identify nuances that automated systems might overlook. The team employs advanced technical analysis methodologies to uncover threat actor operations.
Key research methodologies include infrastructure detection and pivoting, where proprietary network traffic analysis, large-scale automated analytics, and expert analysis are used to identify malicious infrastructure before it becomes active. Sophisticated methods are used to track changes in adversary server configurations, domain registrations, autonomous system numbers (ASNs), and multi-tiered infrastructure. These findings contribute to research streams like annual malicious infrastructure reports.
Victim identification is achieved through the analysis of adversary infrastructure and exfiltration events, combined with geographical intelligence. By monitoring communications between victims and command-and-control (C2) servers across billions of daily network intelligence records, analysts can identify targeted organizations and sectors across various malware families and detect ongoing intrusions in near real-time. Recent work in this area involved identifying five distinct activity clusters attributed to TAG-144 (Blind Eagle) that targeted Colombian government institutions.
The team also focuses on network traffic analysis and exfiltration event correlation. They maintain an analysis pipeline that examines billions of network intelligence records to detect patterns indicative of active compromises, persistence mechanisms, and data exfiltration. This capability allows for the detection of threat actor activities within minutes rather than days or weeks. Examples of recent reports include the identification of victims targeted by GrayCharlie through compromised WordPress sites.
Multi-source validation and cross-referencing are crucial to their process. Analysts integrate data from over one million sources within the Intelligence Graph, including the Recorded Future Platform, the open web, the dark web, technical feeds, malware intelligence, and customer telemetry. This comprehensive approach helps validate findings across disparate data points and reveals connections between threat actors, infrastructure, and targets that might not be apparent when examining sources in isolation. For instance, by combining multiple sources, Insikt Group analysts reported on Telegram-based "guarantee" marketplaces used by Chinese-speaking criminal groups to understand cyber and fraud campaigns.
The multilingual analysis capabilities and cultural expertise of Insikt Group analysts are vital for identifying and interpreting threats that automated systems may not fully contextualize. With native foreign-language skills and deep regional knowledge, analysts can examine activity on dark web forums, underground criminal networks, and foreign-language sources, uncovering subtleties in adversary communications and intent that could be lost in translation or missed by automated tools. This human layer of analysis is particularly important when monitoring threat actors operating in regions like China, Russia, Iran, and North Korea, where understanding cultural context, geopolitical motivations, and regional dynamics is essential for accurate threat attribution and prediction.
Insikt Group's research is integrated directly into the Recorded Future Platform, offering various analytical formats. These include Flash Reports and Threat Leads for emerging activity, as well as in-depth Cyber Threat Analyses, Actor Profiles, and Malware/Tool Profiles that detail adversary behavior, capabilities, and infrastructure. For organizations assessing broader risk, Insikt Group also provides Geopolitical Intelligence Summaries, Country Risk Updates, and forward-looking Geopolitical Threat Forecasts. Practitioners can access Hunting Packages with actionable detections, TTP Instances sourced and verified across multiple sources, and Vulnerability Intelligence for prioritizing exposure. Payment fraud teams receive dedicated coverage, including Payment Card Breach Alerts, Magecart E-Skimmer Reports, and Fraud TTP Analysis. All intelligence is linked to Intelligence Cards, which are consolidated profiles on entities like threat actors, IP addresses, hashes, and domains, allowing analysts to pivot directly from Insikt Group research to related indicators and context.
Beyond customer benefits, Insikt Group publishes much of its research on the Recorded Future blog and in publicly available threat intelligence reports. These reports cover topics such as state-sponsored threat groups, emerging malware, and attacker infrastructure, contributing to the broader security industry's knowledge base. The division's work also informs Recorded Future's product development, creating a feedback loop that enhances the platform. This approach distinguishes Insikt Group from many threat intelligence vendors who may rely more heavily on automation, potentially leaving customers with an intelligence gap.






