TheHive Integration
TheHive calls Cortex analyzers for observable analysis and Cortex responders for response actions. Each analyzer or responder needs its own configuration.
An independent tool index
for incident response teams
Feed automation EU-developed
Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations.
By StrangeBee · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Fully developed and maintained by French company StrangeBee since 2018, according to its official documentation.
Cortex itself remains open source; that does not make current TheHive 5 open source. External analyzers can have separate terms.
identity / origin / capabilities / license / deployment
StrangeBee docs describe analyzers/responders, deployment methods and AGPL licensing, and say StrangeBee has fully developed and maintained Cortex since 2018.
Read sourcecountry
StrangeBee's legal agreement locates the developer in Paris, France.
Read sourcemaintenance
Upstream release list includes a Cortex 4.1.0 release in June 2026.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
TheHive calls Cortex analyzers for observable analysis and Cortex responders for response actions. Each analyzer or responder needs its own configuration.
Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.
Automate security feeds without losing context