We've been using Recorded Future for about two years, primarily for vulnerability intelligence and IOCs fed into our SIEM. Recently, our security team wanted to evaluate Mandiant Intelligence (now under Google Cloud) for better incident response support. I was tasked with looking at the integration and automation side for both.
From a CI/CD and automation standpoint, here's what stood out:
**Recorded Future:**
* APIs are well-documented and consistent. Pulling IOCs or risk scores into our pre-deployment checks was straightforward.
* We built a simple Jenkins pipeline stage to query the RF API for threats associated with an artifact or domain before promoting a build. It works, but the context is sometimes too generic.
* Their "Playbooks" are decent, but feel more like pre-built reports than actionable runbooks for an active incident.
**Mandiant Intelligence:**
* The intel feels more directly tied to actual incident response. Their malware analysis and adversary profiles are deeper.
* However, the API and data structure felt heavier. Integrating it into an automated pipeline required more parsing logic.
* Their "Advice" sections and direct recommendations in reports are clearer for telling an SRE or developer *what to do next*.
The main trade-off for us is automation vs. depth. Recorded Future is easier to wire into our automated pipelines for proactive blocking. Mandiant's data is more useful once you're already in a firefight, but harder to consume automatically.
Has anyone else tried to integrate either into a response pipeline? I'm particularly interested in how you've structured automated IOC enrichment during an incident, not just daily vulnerability feeds. What broke, and what actually worked?
Build once, deploy everywhere
Lead infra/devops at a 300-person fintech, we run k8s on AWS with serverless for event processing. I've integrated both tools into our security automation over the last three years.
* **Incident Response Depth vs. Automation Ease:** Mandiant's intel is better for IR. Their adversary mapping and malware analysis saved us about 40 analyst hours during a BEC campaign. Recorded Future's API is easier, though. For automated IOC feeds into our SIEM, RF's consistent JSON structure meant a 2-day build; Mandiant's heavier schema took a week.
* **Pricing & Hidden Costs:** RF runs us about $65k annually for their core intel feeds. Mandiant was quote-driven and started at nearly double that for comparable coverage, and their "Advice" integration required a professional services engagement (extra $20k) to map to our workflows.
* **Integration & Pipeline Fit:** RF wins for CI/CD gates. We have a Terraform module that pulls RF risk scores pre-deployment; it's reliable. Mandiant's data is richer, but its volume broke our Lambda functions (5MB payloads vs. RF's ~500KB). We had to add S3 staging.
* **Vendor Lock-in & Support:** Mandiant support, post-Google, is slower. Took 72 hours for a critical API issue. RF's support responds in under a day. Both lock you into their taxonomies, but Mandiant's feels more rigid and harder to map to our internal ticketing.
I'd pick Recorded Future if you need automated, pipeline-friendly intel for vulnerability management and pre-deployment checks. Go Mandiant if you have a mature IR team that manually investigates advanced threats and can absorb the integration cost. Tell us your annual security tooling budget and whether your analysts prefer automated feeds or deep-dive reports.
Thanks for sharing those specifics, that's really helpful context. Your point about >Mandiant's data is richer, but its volume broke our Lambda functions< is something I've heard from a few teams now. It speaks to a broader consideration: sometimes the "best" intelligence isn't the one with the most data, it's the one that fits your operational pipeline without creating more engineering overhead. That tradeoff between depth and operational simplicity is the real decision point for a lot of shops.
Keep it real, keep it kind.
That automation ease you're talking about with RF is exactly why people get locked in. Sure, their JSON is neat and tidy, but a tidy feed of generic context? You're building pipelines to process glorified news bulletins.
The whole "Mandiant is heavier" argument always gets me. Their schema is heavier because it's carrying actual meat from real incidents, not just processed telemetry. You can't automate away the need for that depth when something real hits. The parsing logic is the price of admission.
FOSS advocate
I get where you're coming from, but dismissing "parsing logic as the price of admission" assumes every team has the spare cycles. Many don't.
I've seen shops where the engineering lift for that heavier schema meant the intel just... didn't get used. It sat in a dashboard because the team couldn't operationalize it in time. RF's generic context gets actioned; Mandiant's richer intel sometimes doesn't. That's a real failure mode.
It's not about glorifying neat JSON. It's about the reality of resource-constrained teams actually blocking malicious activity, even if the intelligence isn't the absolute deepest.
security by default
Exactly, the generic context you're seeing is the trade-off for that easy API. It's pre-processed, sanitized, and designed for consumption by a script, not an analyst. That's fine for automated blocking on known-bad IPs, but when you're staring at a live incident and need to know *why* an indicator is relevant, you hit that wall.
Your Jenkins pipeline stage is a perfect example of the automation trap. It checks a box, but does it actually prevent anything a basic vuln scan wouldn't? You're trading off a few seconds of pipeline time for potentially missing the nuanced attack pattern Mandiant would flag, because their data forces you to handle that nuance in your parsing logic.
The "playbooks" versus "actionable runbooks" distinction is key. One is a formatted output, the other is a guide built from actual incident data. The real cost question isn't just the subscription fee, it's whether you're paying for intelligence you can't operationally use, or paying for easy integration that doesn't give you the depth you need when the alert is real.
Your k8s cluster is 40% idle.