TheHive Project
TheHive Project
One-liner: Open-source incident response and case management platform for SOC/CSIRT workflows.
π― What Is It?
TheHive provides case, task, and artifact management, analyst collaboration, and integrations with Cortex analyzers for enrichment and automation.
π€ Why It Matters
- Centralises investigations and evidence.
- Streamlines triage, tasking, and reporting.
- Enables automation and enrichment at scale.
π¬ How It Works
Core Principles
- Cases contain tasks, observables, and timelines.
- Collaboration via comments, assignments, and templates.
- Integration with Cortex for automated analysis/playbooks.
Technical Deep-Dive
- Artifacts: IOCs (hashes, URLs, IPs) with tags and TLP.
- Templates: standardise investigations by type (e.g., phishing, malware).
- APIs: integrate with SIEM/EDR and ticketing.
π‘οΈ Detection & Prevention
How to Prevent / Mitigate
- Use templates+workflows to reduce MTTR and improve consistency.
π€ Interview Angles
- "How would you model a phishing case in TheHive?"
β Best Practices
- Define severity model and case fields.
- Enforce naming, tagging, and ownership conventions.
β Common Misconceptions
- Itβs not a SIEM β it manages investigations, not raw logs.