awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoAcerca deCómo clasificamosPrensaServidor MCP
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
TheHive-Project avatar

TheHive-Project/TheHiveArchived

0
View on GitHub↗
3,891 estrellas·681 forks·Scala·agpl-3.0·15 vistasstrangebee.com↗

TheHive

TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables.

The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions through external connectors.

The system covers a broad range of capabilities, including incident lifecycle management, threat intelligence synchronization with frameworks like MITRE ATT&CK and MISP, and automated data ingestion. It provides extensive identity and access management through role-based access control and integration with various identity providers.

The software can be installed on Linux, via Docker containers, or deployed to Kubernetes clusters using Helm charts.

Features

  • Incident Management - Provides a comprehensive system for managing the entire lifecycle of security cases, from creation to ownership assignment and merging.
  • Multi-Tenant Data Management - Provides a multi-tenant architecture that isolates users and data across organizations with selective sharing.
  • Incident Response Management - Provides a platform for tracking and managing the entire security incident response workflow.
  • Security Observable Extractions - Identifies and extracts critical security observables like IP addresses and file hashes from events.

Búsqueda con IA

Explora más repositorios increíbles

Describe lo que necesitas en lenguaje sencillo: la IA clasifica miles de proyectos open-source curados por relevancia.

Start searching with AI
  • Incident Response Platforms - Functions as a comprehensive platform for coordinating security investigations through cases, alerts, and observables.
  • Threat Intelligence - Integrates external TTP catalogs to track and analyze the specific behaviors and methods used by threat actors.
  • Automated Case Generation - Uses templates to standardize the automatic generation of tasks and metrics for security investigations.
  • Alert-to-Case Promotion - Allows the promotion of an alert to a full investigation case or links it to an existing case.
  • Case Management Systems - Manages investigation progress by attaching files, tags, and secured archives to security cases.
  • Technical Indicator Tracking - Creates and updates observables and procedures within cases or alerts to document technical indicators.
  • Cross-Tenant Collaboration - Links independent organizational units to enable the exchange of security cases, tasks, and observables.
  • Organization Switching - Toggles the current active workspace to access data and resources associated with a specific organization.
  • Workspace Creations - Provides the ability to create isolated organizational tenants for distinct business units to manage incidents independently.
  • Data Ingestion - Transforms data from external sources and detection tools into standardized security alerts.
  • Global Content Searches - Provides global keyword and advanced search capabilities to locate specific security alerts across the platform.
  • Analyzer Triggers - Automatically triggers security analyzers to run when specific filtered events are detected.
  • Security Response Triggers - Automatically executes predefined security responders when events like case creation or alert imports occur.
  • Organization Management - Implements multi-tenant organizational structures to isolate data and coordinate security efforts between different entities.
  • API Request Authentication - Validates programmatic service requests using API keys, Basic authentication, and HTTP headers.
  • User Management - Manages the creation of user profiles for humans or services and assigns them to organizations with specific permission levels.
  • Permission Assignments - Allows administrators to customize available actions by assigning or revoking specific access rights for user profiles.
  • Permission Set Definitions - Enables the creation and management of user profiles with specific permission sets to control feature access.
  • Custom Role Definitions - Enables the creation of tailored permission sets beyond predefined roles to meet organizational security requirements.
  • Identity Providers - Verifies user identities using various identity providers including LDAP, Active Directory, OAUTH2, and Multi-Factor Authentication.
  • Multi-Tenant Hierarchy Organizers - Implements a multi-tenant architecture that isolates users, roles, and configurations across distinct organizations.
  • Observable Analyzers - Launches analyzer jobs on observables via external connectors to identify threats and enrich data.
  • Permission-Based Access Control - Regulates who can share security cases with external parties using profile-based permissions.
  • Role-Based Access Control - Regulates system capabilities and data visibility using granular user profiles and permission sets tied to organizational roles.
  • Case Visibility Controls - Restricts or grants visibility of security cases to specific internal users, organizations, or external parties.
  • Security Analysis Integrations - Connects the platform to external analysis and response engines to automate threat intelligence gathering.
  • Security Response Actions - Triggers responder actions on alerts, cases, or tasks through external connectors to mitigate threats.
  • Vulnerability Context Enrichers - Connects to external analysis engines to retrieve additional context and detailed reports on security observables.
  • Security Operations Automation - Creates programmable functions to process data and automate repetitive tasks within the incident response lifecycle.
  • Threat Actor Tracking Tools - Provides capabilities to catalog and analyze adversary tactics, techniques, and procedures to monitor malicious entities.
  • Threat Intelligence Platforms - Integrates with external intelligence platforms and analyzers to enrich data and automate threat containment.
  • Contextual Enrichment - Enriches security observables such as IP addresses and hashes with contextual intelligence from external analysis tools.
  • Threat Intelligence Synchronizers - Imports taxonomies and events from external threat intelligence servers to generate alerts or cases.
  • User Access Management - Provides centralized tools for managing user access levels and permissions to control the creation and modification of components.
  • Case Management Engines - Uses a template engine with custom fields and metrics to ensure consistency across cases and tasks.
  • Workflow Automation Engines - Includes an execution engine for sandboxed JavaScript logic and automated playbooks to process security events.
  • Security Alert Monitors - Implements advanced filtering of security alerts and related cases using predefined and custom field criteria.
  • Alerting and Incident Management - Implements comprehensive management of security alerts, including creation, searching, and conversion into investigation cases.
  • Alert Triage - Enables the review and triage of security alerts to identify false positives and escalate threats.
  • Automated Incident Response Workflows - Automates investigation workflows by triggering responders to execute actions on cases and alerts.
  • Organization Management - Implements administrative tools for assigning and removing users from organizations and defining their permission profiles.
  • Security Event Collection - Collects security events from external detection tools, threat intelligence platforms, and email servers.
  • File Storage - Centralizes attachments and observables in shared storage for accessibility across all cluster nodes.
  • Investigation Logs - Maintains chronological investigation logs and audit trails for security tasks.
  • MITRE ATT&CK Analysis - Links security incidents and alerts to known adversary techniques and tactics using the MITRE ATT&CK framework.
  • Automated Status Transitions - Runs periodic scripts to automatically update alert statuses and properties based on specific criteria.
  • Permissioned Status Transitions - Controls the movement of alerts between investigation stages based on the permissions of the user.
  • Case Template Exchange - Exports and imports predefined case configurations between different organizations or system instances.
  • Scheduled External API Syncs - Retrieves data from external REST APIs on a schedule to generate alerts, cases, or tasks.
  • Incident Report Generation - Produces formatted incident reports using case descriptions and structured data widgets.
  • Organization-Based Access Management - Provides the ability to prevent all users of a specific organization from logging into the system.
  • Report Layout Standardization - Defines predefined layouts for incident reports to transform case data into a consistent, standardized format.
  • Email-to-Alert Pipelines - Processes incoming emails and attachments to create detailed security alerts.
  • Real-time Collaboration - Enables multiple security analysts to work simultaneously on the same investigation case with real-time activity streams.
  • User Activity Logs - Records all actions performed by external portal users within the system's history and live feed.
  • Workflow Status Management - Defines and updates the various statuses and stages used to track the progress of security incidents.
  • Documentation and Knowledge Management - Provides tools for creating and managing instructional pages and documentation at both organizational and case levels.
  • Security Event Logic - Evaluates incoming security events against field values and operators to trigger automated actions.
  • Cluster Node Management - Manages individual database nodes, including decommissioning healthy nodes and removing crashed ones.
  • Template-Based Reports - Creates and manages standardized reporting layouts to ensure consistent security incident documentation.
  • Retention Policies - Permanently deletes or redacts sensitive security information once defined retention periods are exceeded.
  • Standardized Threat Intelligence Exports - Sends cases and indicators of compromise to external threat intelligence servers for community sharing.
  • Data Replication Strategies - Provides controls to adjust the number of data copies across a cluster to increase fault tolerance.
  • Custom Field Type Definitions - Enables the creation of new categories for security artifacts to extend trackable data points.
  • Search Index Migrations - Moves stored data from local file-based indices to distributed search engines to improve query performance.
  • External Indexing Offloaders - Offloads search indexing to a separate dedicated engine to improve query performance for security alerts and cases.
  • Label-Based Categorization - Provides mechanisms to group security cases, alerts, and observables using free-text labels for better organization.
  • Investigation Layouts - Uses predefined layouts and custom fields to ensure consistent documentation and workflow across security investigations.
  • Webhook Notification Systems - Sends automated HTTP requests to external systems when specific platform events are triggered.
  • Custom Logic Extensions - Implements a system for creating and managing custom JavaScript functions to automate security workflows.
  • Cloud Infrastructure Deployment - Supports deploying instances to cloud providers using dedicated images and infrastructure-as-code templates.
  • Cluster Coordination - Implements synchronization of state and workload distribution across multiple server nodes to ensure high availability.
  • Cluster Scaling Orchestrators - Supports scaling database capacity by adding new nodes to an existing cluster or transitioning from a standalone setup.
  • Application Cluster Deployments - Enables connecting multiple application nodes into a single cluster to ensure continuous service availability.
  • Event-Driven Triggers - Automatically executes specific functions in response to defined security events, such as case closure.
  • Helm Chart Deployment - Uses predefined Helm charts to automate the installation of the system and its dependencies on Kubernetes.
  • High Availability Clusters - Deploys the system as a multi-node cluster across dedicated hosts to ensure fault tolerance.
  • Containerized Production Setups - Provides a production-ready installation of the application stack on a single server using container orchestration.
  • Multi-Platform Installation Systems - Supports system installation across Linux distributions, Docker containers, and Kubernetes clusters.
  • Chat Platform Integrations - Integrates with external chat services to send incident notifications directly to team communication channels.
  • Event Notifications - Triggers automated actions via email, webhooks, or messaging platforms in response to specific system events.
  • Virtual IP Failover Systems - Implements automatic traffic redirection to standby load balancers using virtual IP addresses for high availability.
  • Notification Routing Platforms - Routes automated incident alerts to external platforms such as Slack, Teams, or Mattermost.
  • Sandboxed JavaScript Execution - Runs programmable sandboxed JavaScript blocks to automate security tasks and transform ingested data.
  • API Key Generation - Generates unique secret keys to authenticate programmatic requests to the platform.
  • API Key Management - Provides capabilities to generate, reveal, and revoke API keys for system authentication.
  • Lifecycle Management - Provides tools to generate, reveal, and revoke authentication keys for programmatic system access.
  • Automated IP Banning - Automatically bans IP addresses based on repeated failed login attempts detected in authentication logs.
  • Case Sharing Overrides - Customizes sharing settings for specific cases to deviate from global defaults based on investigation needs.
  • Identity Synchronization - Automates account creation, updates, and deletion by linking a directory server for centralized identity management.
  • Observable-Based Event Correlation - Filters and displays cases and alerts that share common observables to identify related security incidents.
  • LDAP Authentication - Verifies user identities using credentials stored in an LDAP or Active Directory server during login.
  • Local Authentication - Stores usernames and passwords in a local database using cryptographic hashing to control access.
  • Multi-Factor Authentication - Adds a second layer of security to the account login process by requiring a time-based verification code.
  • On-Demand Security Functions - Triggers predefined security functions via HTTP calls and returns processed data to the requester.
  • OpenID Connect Support - Connects to an external OpenID identity provider to manage user authentication and single sign-on.
  • SAML Authentication - Connects to an external identity provider to authenticate users via the SAML protocol.
  • External Information Gateways - Provides a secure gateway for non-security users to view specific cases and shared comments.
  • Intelligence Reporting - Provides capabilities to format and display intelligence reports received from external analysis tools consistently.
  • Intelligence Report Templates - Allows the import of templates to standardize how contextual intelligence reports are formatted and displayed.
  • Directory Service Authenticators - Authenticates users against an Active Directory domain to centralize identity management and access control.
  • Plugin-Based Architectures - Uses a standardized connector model to integrate remote analysis engines and response tools for observable enrichment.
  • Taxonomies - Provides structured classification schemes to categorize security incidents and observables.
  • Custom Case Statuses - Creates custom labels for cases and alerts to track investigation progress beyond default options.
  • Event-Driven Notification Triggers - Triggers automated alerts across email, webhooks, and chat platforms based on filtered system audit logs.
  • Related Alert Identification - Finds alerts related to known incidents by applying filters to specific alerts, cases, or tasks.
  • Custom Alert Statuses - Creates specialized labels and colors to categorize alerts and flag them for specific workflows.
  • Audit Logging Systems - Maintains a high-performance record of system activities to ensure a complete audit trail.
  • Email Alert Ingestion - Connects to mailboxes to automatically convert incoming security alert emails into actionable incident alerts.
  • Incident Task Trackers - Provides systems for managing and tracking tasks throughout the security incident lifecycle.
  • Case Documentation Templates - Prefills content automatically during page creation to standardize the documentation of security incidents.
  • Incident Checklists - Provides structured validation checklists within cases to ensure consistent incident handling.
  • Incident Data Auto-Population - Automatically populates predefined fields during the initiation of a security incident to ensure consistency.
  • Metadata Customization - Tailors security incident categorization through custom fields, observable types, taxonomies, and statuses.
  • Slack Notifications - Routes event-driven alerts to Slack channels using customizable templates and triggers.
  • OAuth 2.0 Provider Integrations - Authenticates users via external identity providers using the OAuth 2.0 protocol.
  • Custom Data Fields - Supports the creation of custom data fields to capture specialized information during security investigations.
  • Page Layout Templates - Provides tools to create and remove customized page layouts to organize how security incident data is displayed.
  • Attachment Managers - Links files, images, and reports to organizations and cases to store supporting evidence and materials.
  • Security Orchestration Tools - Scalable incident response platform for security teams.
  • Historial de estrellas

    Gráfico del historial de estrellas de thehive-project/thehiveGráfico del historial de estrellas de thehive-project/thehive

    Alternativas open-source a TheHive

    Proyectos open-source similares, clasificados según cuántas características comparten con TheHive.
    • velocidex/velociraptorAvatar de Velocidex

      Velocidex/velociraptor

      3,769Ver en GitHub↗

      Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

      Godigital-forensicsendpoint-discoveryendpoint-protection
      Ver en GitHub↗3,769
    • passbolt/passbolt_apiAvatar de passbolt

      passbolt/passbolt_api

      5,974Ver en GitHub↗

      Passbolt is an open-source, self-hosted password manager designed for teams. It provides a centralized, encrypted vault where organizations can store, share, and manage credentials securely. The server exposes a JSON REST API that authenticates requests using either GPGAuth or JWT tokens, and all secrets are protected with OpenPGP end-to-end encryption, ensuring the server never has access to plaintext passwords. The platform distinguishes itself through a comprehensive role-based access control system that governs resource sharing and administrative actions. Teams can organize users into gro

      PHPcakephpcakephp5credentials
      Ver en GitHub↗5,974
    • aws/aws-cdkAvatar de aws

      aws/aws-cdk

      12,817Ver en GitHub↗

      The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

      TypeScriptawscloud-infrastructurehacktoberfest
      Ver en GitHub↗12,817
    • area17/twillAvatar de area17

      area17/twill

      3,956Ver en GitHub↗

      Twill is a Laravel CMS toolkit and admin panel generator designed for building custom administrative consoles and content management systems. It serves as a headless CMS framework and a toolkit for defining content models and managing structured data through a dedicated administrative interface. The project features a visual block editor that allows publishers to arrange and configure reusable content sections via a drag-and-drop interface. It includes a dedicated digital asset manager for storing, cropping, and optimizing images and files across local or cloud storage, as well as a multiling

      PHP
      Ver en GitHub↗3,956
    Ver las 30 alternativas a TheHive→

    Preguntas frecuentes

    ¿Qué hace thehive-project/thehive?

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables.

    ¿Cuáles son las características principales de thehive-project/thehive?

    Las características principales de thehive-project/thehive son: Incident Management, Multi-Tenant Data Management, Incident Response Management, Security Observable Extractions, Incident Response Platforms, Threat Intelligence, Automated Case Generation, Alert-to-Case Promotion.

    ¿Qué alternativas de código abierto existen para thehive-project/thehive?

    Las alternativas de código abierto para thehive-project/thehive incluyen: velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… passbolt/passbolt_api — Passbolt is an open-source, self-hosted password manager designed for teams. It provides a centralized, encrypted… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… area17/twill — Twill is a Laravel CMS toolkit and admin panel generator designed for building custom administrative consoles and… kanboard/kanboard — Kanboard is a self-hosted Kanban project management tool and productivity suite designed for tracking software tasks… tencent/weknora — WeKnora is a multi-tenant retrieval-augmented generation (RAG) knowledge platform and autonomous AI agent framework.…