Feed automation EU-developed

Cortex

Observable analysis and response engine that runs analyzers and responders through a shared API, commonly connected to TheHive investigations.

By StrangeBee · France

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Feed automation
Developer or maintainer
StrangeBee
Recorded country
France
Product model
Open source
Deployment
Self-hosted
Software license
AGPL-3.0
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Fully developed and maintained by French company StrangeBee since 2018, according to its official documentation.

Reported capabilities

  • Automates observable analysis through analyzers.
  • Runs responders as investigation actions.
  • Licensed under AGPL-3.0 and deployable with packages, Docker or Kubernetes.

Scope and limits

Cortex itself remains open source; that does not make current TheHive 5 open source. External analyzers can have separate terms.

Inspect the research evidence 3 source observations
  1. identity / origin / capabilities / license / deployment

    StrangeBee docs describe analyzers/responders, deployment methods and AGPL licensing, and say StrangeBee has fully developed and maintained Cortex since 2018.

    Read source
  2. country

    StrangeBee's legal agreement locates the developer in Paris, France.

    Read source
  3. maintenance

    Upstream release list includes a Cortex 4.1.0 release in June 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

TheHive Integration

TheHive calls Cortex analyzers for observable analysis and Cortex responders for response actions. Each analyzer or responder needs its own configuration.

Put the tool in context.

Plan a security feed pipeline with parsing, validation, deduplication, delivery and failure checks. Source-linked guidance for IntelMQ and n6 evaluation.

Automate security feeds without losing context