TheHive

TheHive

TheHive is a scalable, open-source and free Security Incident Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security incidents.

Visit Website

Triggers & Actions

Use TheHive as a trigger to kick off a workflow, or use it as an action to do something automatically in your workflow.

Triggers

No triggers available

Actions

  • Create Case

    Create a new case in TheHive

  • Get Case

    Get a case by ID or number

  • Update Case

    Update an existing case

  • Delete Case

    Delete a case from TheHive

  • Create Alert

    Create a new alert in TheHive

  • Get Alert

    Get an alert by ID

  • Update Alert

    Update an existing alert

  • Delete Alert

    Delete an alert from TheHive

  • Promote Alert to Case

    Create a case from an alert

  • Merge Alert into Case

    Merge an alert into an existing case

  • Create Task

    Create a new task in a case

  • Get Task

    Get a task by ID

  • Update Task

    Update an existing task

  • Delete Task

    Delete a task from a case

  • Create Task Log

    Add a log entry to a task

  • Create Observable

    Create a new observable in a case

  • Get Observable

    Get an observable by ID

  • Update Observable

    Update an existing observable

  • Delete Observable

    Delete an observable from a case

  • Create Comment

    Add a comment to a case

  • Query API

    Execute a query using TheHive Query API

  • Create User

    Create a new user in TheHive

  • Get User

    Get user details by ID or login

  • Update User

    Update an existing user

  • Delete User

    Delete a user from TheHive

  • Create Organisation

    Create a new organisation in TheHive

  • Get Organisation

    Get organisation details by ID

  • Update Organisation

    Update an existing organisation

  • Get Case Timeline

    Get the timeline of events for a case

  • Create Custom Field

    Create a new custom field definition

  • Merge Cases

    Merge multiple cases into a new case

  • Get System Status

    Get TheHive instance status and capabilities

  • Get Current User

    Get the current authenticated user information

  • Run Diagnostics

    Check TheHive connection, version, and user permissions