TheHive is a scalable, open-source and free Security Incident Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security incidents.
Use TheHive as a trigger to kick off a workflow, or use it as an action to do something automatically in your workflow.
No triggers available
Create a new case in TheHive
Get a case by ID or number
Update an existing case
Delete a case from TheHive
Create a new alert in TheHive
Get an alert by ID
Update an existing alert
Delete an alert from TheHive
Create a case from an alert
Merge an alert into an existing case
Create a new task in a case
Get a task by ID
Update an existing task
Delete a task from a case
Add a log entry to a task
Create a new observable in a case
Get an observable by ID
Update an existing observable
Delete an observable from a case
Add a comment to a case
Execute a query using TheHive Query API
Create a new user in TheHive
Get user details by ID or login
Update an existing user
Delete a user from TheHive
Create a new organisation in TheHive
Get organisation details by ID
Update an existing organisation
Get the timeline of events for a case
Create a new custom field definition
Merge multiple cases into a new case
Get TheHive instance status and capabilities
Get the current authenticated user information
Check TheHive connection, version, and user permissions