Each entry describes the documented operation and links to its source. A format reference, an optional connector and built-in execution are different capabilities. Check the note before shortlisting.
Before you connect it
Confirm your product version, edition, connector and access requirements in the upstream instructions. These listings record documentation, not a tested configuration. Read the evidence standard.
2 tools with documented Cortex integration evidence.
Connects to a separately installed Cortex server for analyzers and responders. Multiple Cortex servers require a paid license; TheHive 5.5 drops support for Cortex 3.1.5 and earlier.
Dispatches analysis jobs to a configured Cortex instance and processes returned reports. Analyzer identifiers must match installed Cortex analyzers; the documented configuration requires a shared webhook secret.