MISP Integration
Imports MISP events as alerts and exports case observables marked as IOCs to MISP. Connecting multiple MISP servers requires a paid TheHive license.
An independent tool index
for incident response teams
Response coordination EU-developed
Incident response platform for triaging alerts, opening cases, coordinating investigation tasks, and analyzing observables through connected Cortex services.
By StrangeBee · France
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Began in an unnamed European financial institution CSIRT; current developer and licensor is French company StrangeBee. The original CSIRT country was not established.
Current TheHive 5 is proprietary despite older TheHive 4 AGPL releases. Cloud placement is not guaranteed in France; a trial becomes read-only without an activated license.
identity / capabilities
TheHive documentation covers alert triage and conversion to cases, supporting its incident-response workflow classification.
Read sourcelicense / deployment
Current documentation says Community is free but activated and on-prem only; Gold is paid on-prem; Platinum is paid on-prem or cloud; expired trial becomes read-only.
Read sourcelicense
TheHive 5 Community terms forbid modification, reverse engineering and redistribution, so free Community use is not open source.
Read sourceorigin
StrangeBee's history describes TheHive's inception in a European financial institution's CSIRT and its subsequent development by StrangeBee.
Read sourcecountry
StrangeBee's own SaaS agreement identifies the company as a French SAS based in Paris.
Read sourcemaintenance
The current release policy lists maintained TheHive 5 versions and 2026 release activity.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Imports MISP events as alerts and exports case observables marked as IOCs to MISP. Connecting multiple MISP servers requires a paid TheHive license.
Connects to a separately installed Cortex server for analyzers and responders. Multiple Cortex servers require a paid license; TheHive 5.5 drops support for Cortex 3.1.5 and earlier.
A separately installed Splunk add-on turns saved-search results into TheHive alerts, with explicit field mapping and an alert action.
Move from alert triage to assigned tasks, evidence, shift handoff and closure. A practical case management guide with TheHive and DFIR-IRIS references.
An incident response case management workflow