awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
TheHive-Project avatar

TheHive-Project/TheHiveArchived

0
View on GitHub↗
3,891 stars·681 forks·Scala·agpl-3.0·49 viewsstrangebee.com↗

TheHive

TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables.

The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions through external connectors.

The system covers a broad range of capabilities, including incident lifecycle management, threat intelligence synchronization with frameworks like MITRE ATT&CK and MISP, and automated data ingestion. It provides extensive identity and access management through role-based access control and integration with various identity providers.

The software can be installed on Linux, via Docker containers, or deployed to Kubernetes clusters using Helm charts.

Features

  • Incident Management - Provides a comprehensive system for managing the entire lifecycle of security cases, from creation to ownership assignment and merging.
  • Multi-Tenant Data Management - Provides a multi-tenant architecture that isolates users and data across organizations with selective sharing.
  • Incident Response Management - Provides a platform for tracking and managing the entire security incident response workflow.
  • Security Observable Extractions - Identifies and extracts critical security observables like IP addresses and file hashes from events.
  • Incident Response Platforms - Functions as a comprehensive platform for coordinating security investigations through cases, alerts, and observables.
  • Threat Intelligence - Integrates external TTP catalogs to track and analyze the specific behaviors and methods used by threat actors.
  • Automated Case Generation - Uses templates to standardize the automatic generation of tasks and metrics for security investigations.
  • Alert-to-Case Promotion - Allows the promotion of an alert to a full investigation case or links it to an existing case.
  • Case Management Systems - Manages investigation progress by attaching files, tags, and secured archives to security cases.
  • Technical Indicator Tracking - Creates and updates observables and procedures within cases or alerts to document technical indicators.
  • Cross-Tenant Collaboration - Links independent organizational units to enable the exchange of security cases, tasks, and observables.
  • Organization Switching - Toggles the current active workspace to access data and resources associated with a specific organization.
  • Workspace Creations - Provides the ability to create isolated organizational tenants for distinct business units to manage incidents independently.
  • Data Ingestion - Transforms data from external sources and detection tools into standardized security alerts.
  • Global Content Searches - Provides global keyword and advanced search capabilities to locate specific security alerts across the platform.
  • Analyzer Triggers - Automatically triggers security analyzers to run when specific filtered events are detected.
  • Security Response Triggers - Automatically executes predefined security responders when events like case creation or alert imports occur.
  • Organization Management - Implements multi-tenant organizational structures to isolate data and coordinate security efforts between different entities.
  • API Request Authentication - Validates programmatic service requests using API keys, Basic authentication, and HTTP headers.
  • User Management - Manages the creation of user profiles for humans or services and assigns them to organizations with specific permission levels.
  • Permission Assignments - Allows administrators to customize available actions by assigning or revoking specific access rights for user profiles.
  • Permission Set Definitions - Enables the creation and management of user profiles with specific permission sets to control feature access.
  • Custom Role Definitions - Enables the creation of tailored permission sets beyond predefined roles to meet organizational security requirements.
  • Identity Providers - Verifies user identities using various identity providers including LDAP, Active Directory, OAUTH2, and Multi-Factor Authentication.
  • Multi-Tenant Hierarchy Organizers - Implements a multi-tenant architecture that isolates users, roles, and configurations across distinct organizations.
  • Observable Analyzers - Launches analyzer jobs on observables via external connectors to identify threats and enrich data.
  • Permission-Based Access Control - Regulates who can share security cases with external parties using profile-based permissions.
  • Role-Based Access Control - Regulates system capabilities and data visibility using granular user profiles and permission sets tied to organizational roles.
  • Case Visibility Controls - Restricts or grants visibility of security cases to specific internal users, organizations, or external parties.
  • Security Analysis Integrations - Connects the platform to external analysis and response engines to automate threat intelligence gathering.
  • Security Response Actions - Triggers responder actions on alerts, cases, or tasks through external connectors to mitigate threats.
  • Vulnerability Context Enrichers - Connects to external analysis engines to retrieve additional context and detailed reports on security observables.
  • Security Operations Automation - Creates programmable functions to process data and automate repetitive tasks within the incident response lifecycle.
  • Threat Actor Tracking Tools - Provides capabilities to catalog and analyze adversary tactics, techniques, and procedures to monitor malicious entities.
  • Threat Intelligence Platforms - Integrates with external intelligence platforms and analyzers to enrich data and automate threat containment.
  • Contextual Enrichment - Enriches security observables such as IP addresses and hashes with contextual intelligence from external analysis tools.
  • Threat Intelligence Synchronizers - Imports taxonomies and events from external threat intelligence servers to generate alerts or cases.
  • User Access Management - Provides centralized tools for managing user access levels and permissions to control the creation and modification of components.
  • Case Management Engines - Uses a template engine with custom fields and metrics to ensure consistency across cases and tasks.
  • Workflow Automation Engines - Includes an execution engine for sandboxed JavaScript logic and automated playbooks to process security events.
  • Security Alert Monitors - Implements advanced filtering of security alerts and related cases using predefined and custom field criteria.
  • Alerting and Incident Management - Implements comprehensive management of security alerts, including creation, searching, and conversion into investigation cases.
  • Alert Triage - Enables the review and triage of security alerts to identify false positives and escalate threats.
  • Automated Incident Response Workflows - Automates investigation workflows by triggering responders to execute actions on cases and alerts.
  • Organization Management - Implements administrative tools for assigning and removing users from organizations and defining their permission profiles.
  • Security Event Collection - Collects security events from external detection tools, threat intelligence platforms, and email servers.
  • File Storage - Centralizes attachments and observables in shared storage for accessibility across all cluster nodes.
  • Investigation Logs - Maintains chronological investigation logs and audit trails for security tasks.
  • MITRE ATT&CK Analysis - Links security incidents and alerts to known adversary techniques and tactics using the MITRE ATT&CK framework.
  • Automated Status Transitions - Runs periodic scripts to automatically update alert statuses and properties based on specific criteria.
  • Permissioned Status Transitions - Controls the movement of alerts between investigation stages based on the permissions of the user.
  • Case Template Exchange - Exports and imports predefined case configurations between different organizations or system instances.
  • Scheduled External API Syncs - Retrieves data from external REST APIs on a schedule to generate alerts, cases, or tasks.
  • Incident Report Generation - Produces formatted incident reports using case descriptions and structured data widgets.
  • Organization-Based Access Management - Provides the ability to prevent all users of a specific organization from logging into the system.
  • Report Layout Standardization - Defines predefined layouts for incident reports to transform case data into a consistent, standardized format.
  • Email-to-Alert Pipelines - Processes incoming emails and attachments to create detailed security alerts.
  • Real-time Collaboration - Enables multiple security analysts to work simultaneously on the same investigation case with real-time activity streams.
  • User Activity Logs - Records all actions performed by external portal users within the system's history and live feed.
  • Workflow Status Management - Defines and updates the various statuses and stages used to track the progress of security incidents.
  • Documentation and Knowledge Management - Provides tools for creating and managing instructional pages and documentation at both organizational and case levels.
  • Security Event Logic - Evaluates incoming security events against field values and operators to trigger automated actions.
  • Cluster Node Management - Manages individual database nodes, including decommissioning healthy nodes and removing crashed ones.
  • Template-Based Reports - Creates and manages standardized reporting layouts to ensure consistent security incident documentation.
  • Retention Policies - Permanently deletes or redacts sensitive security information once defined retention periods are exceeded.
  • Standardized Threat Intelligence Exports - Sends cases and indicators of compromise to external threat intelligence servers for community sharing.
  • Data Replication Strategies - Provides controls to adjust the number of data copies across a cluster to increase fault tolerance.
  • Custom Field Type Definitions - Enables the creation of new categories for security artifacts to extend trackable data points.
  • Search Index Migrations - Moves stored data from local file-based indices to distributed search engines to improve query performance.
  • External Indexing Offloaders - Offloads search indexing to a separate dedicated engine to improve query performance for security alerts and cases.
  • Label-Based Categorization - Provides mechanisms to group security cases, alerts, and observables using free-text labels for better organization.
  • Investigation Layouts - Uses predefined layouts and custom fields to ensure consistent documentation and workflow across security investigations.
  • Webhook Notification Systems - Sends automated HTTP requests to external systems when specific platform events are triggered.
  • Custom Logic Extensions - Implements a system for creating and managing custom JavaScript functions to automate security workflows.
  • Cloud Infrastructure Deployment - Supports deploying instances to cloud providers using dedicated images and infrastructure-as-code templates.
  • Cluster Coordination - Implements synchronization of state and workload distribution across multiple server nodes to ensure high availability.
  • Cluster Scaling Orchestrators - Supports scaling database capacity by adding new nodes to an existing cluster or transitioning from a standalone setup.
  • Application Cluster Deployments - Enables connecting multiple application nodes into a single cluster to ensure continuous service availability.
  • Event-Driven Triggers - Automatically executes specific functions in response to defined security events, such as case closure.
  • Helm Chart Deployment - Uses predefined Helm charts to automate the installation of the system and its dependencies on Kubernetes.
  • High Availability Clusters - Deploys the system as a multi-node cluster across dedicated hosts to ensure fault tolerance.
  • Containerized Production Setups - Provides a production-ready installation of the application stack on a single server using container orchestration.
  • Multi-Platform Installation Systems - Supports system installation across Linux distributions, Docker containers, and Kubernetes clusters.
  • Chat Platform Integrations - Integrates with external chat services to send incident notifications directly to team communication channels.
  • Event Notifications - Triggers automated actions via email, webhooks, or messaging platforms in response to specific system events.
  • Virtual IP Failover Systems - Implements automatic traffic redirection to standby load balancers using virtual IP addresses for high availability.
  • Notification Routing Platforms - Routes automated incident alerts to external platforms such as Slack, Teams, or Mattermost.
  • Sandboxed JavaScript Execution - Runs programmable sandboxed JavaScript blocks to automate security tasks and transform ingested data.
  • API Key Generation - Generates unique secret keys to authenticate programmatic requests to the platform.
  • API Key Management - Provides capabilities to generate, reveal, and revoke API keys for system authentication.
  • Lifecycle Management - Provides tools to generate, reveal, and revoke authentication keys for programmatic system access.
  • Automated IP Banning - Automatically bans IP addresses based on repeated failed login attempts detected in authentication logs.
  • Case Sharing Overrides - Customizes sharing settings for specific cases to deviate from global defaults based on investigation needs.
  • Identity Synchronization - Automates account creation, updates, and deletion by linking a directory server for centralized identity management.
  • Observable-Based Event Correlation - Filters and displays cases and alerts that share common observables to identify related security incidents.
  • LDAP Authentication - Verifies user identities using credentials stored in an LDAP or Active Directory server during login.
  • Local Authentication - Stores usernames and passwords in a local database using cryptographic hashing to control access.
  • Multi-Factor Authentication - Adds a second layer of security to the account login process by requiring a time-based verification code.
  • On-Demand Security Functions - Triggers predefined security functions via HTTP calls and returns processed data to the requester.
  • OpenID Connect Support - Connects to an external OpenID identity provider to manage user authentication and single sign-on.
  • SAML Authentication - Connects to an external identity provider to authenticate users via the SAML protocol.
  • External Information Gateways - Provides a secure gateway for non-security users to view specific cases and shared comments.
  • Intelligence Reporting - Provides capabilities to format and display intelligence reports received from external analysis tools consistently.
  • Intelligence Report Templates - Allows the import of templates to standardize how contextual intelligence reports are formatted and displayed.
  • Directory Service Authenticators - Authenticates users against an Active Directory domain to centralize identity management and access control.
  • Plugin-Based Architectures - Uses a standardized connector model to integrate remote analysis engines and response tools for observable enrichment.
  • Taxonomies - Provides structured classification schemes to categorize security incidents and observables.
  • Custom Case Statuses - Creates custom labels for cases and alerts to track investigation progress beyond default options.
  • Event-Driven Notification Triggers - Triggers automated alerts across email, webhooks, and chat platforms based on filtered system audit logs.
  • Related Alert Identification - Finds alerts related to known incidents by applying filters to specific alerts, cases, or tasks.
  • Custom Alert Statuses - Creates specialized labels and colors to categorize alerts and flag them for specific workflows.
  • Audit Logging Systems - Maintains a high-performance record of system activities to ensure a complete audit trail.
  • Email Alert Ingestion - Connects to mailboxes to automatically convert incoming security alert emails into actionable incident alerts.
  • Incident Task Trackers - Provides systems for managing and tracking tasks throughout the security incident lifecycle.
  • Case Documentation Templates - Prefills content automatically during page creation to standardize the documentation of security incidents.
  • Incident Checklists - Provides structured validation checklists within cases to ensure consistent incident handling.
  • Incident Data Auto-Population - Automatically populates predefined fields during the initiation of a security incident to ensure consistency.
  • Metadata Customization - Tailors security incident categorization through custom fields, observable types, taxonomies, and statuses.
  • Slack Notifications - Routes event-driven alerts to Slack channels using customizable templates and triggers.
  • OAuth 2.0 Provider Integrations - Authenticates users via external identity providers using the OAuth 2.0 protocol.
  • Custom Data Fields - Supports the creation of custom data fields to capture specialized information during security investigations.
  • Page Layout Templates - Provides tools to create and remove customized page layouts to organize how security incident data is displayed.
  • Attachment Managers - Links files, images, and reports to organizations and cases to store supporting evidence and materials.
  • Security Orchestration Tools - Scalable incident response platform for security teams.

Star history

Star history chart for thehive-project/thehiveStar history chart for thehive-project/thehive

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with TheHive

These projects share indexed features with TheHive. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • passbolt/passbolt_apipassbolt avatar

    passbolt/passbolt_api

    5,974View on GitHub↗

    Passbolt is an open-source, self-hosted password manager designed for teams. It provides a centralized, encrypted vault where organizations can store, share, and manage credentials securely. The server exposes a JSON REST API that authenticates requests using either GPGAuth or JWT tokens, and all secrets are protected with OpenPGP end-to-end encryption, ensuring the server never has access to plaintext passwords. The platform distinguishes itself through a comprehensive role-based access control system that governs resource sharing and administrative actions. Teams can organize users into gro

    PHPcakephpcakephp5credentials
    View on GitHub↗5,974
  • aws/aws-cdkaws avatar

    aws/aws-cdk

    12,817View on GitHub↗

    The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision cloud resources using familiar programming languages. By utilizing construct-based synthesis, it translates high-level, object-oriented code into declarative templates, allowing for the automated management of complex cloud environments through a centralized, code-driven control plane. The framework distinguishes itself through its ability to model infrastructure as a dependency-aware resource graph, ensuring that components are provisioned and updated in the correct order. It

    TypeScriptawscloud-infrastructurehacktoberfest
    View on GitHub↗12,817
  • area17/twillarea17 avatar

    area17/twill

    3,956View on GitHub↗

    Twill is a Laravel CMS toolkit and admin panel generator designed for building custom administrative consoles and content management systems. It serves as a headless CMS framework and a toolkit for defining content models and managing structured data through a dedicated administrative interface. The project features a visual block editor that allows publishers to arrange and configure reusable content sections via a drag-and-drop interface. It includes a dedicated digital asset manager for storing, cropping, and optimizing images and files across local or cloud storage, as well as a multiling

    PHP
    View on GitHub↗3,956
Compare all 30 related projects→

Frequently asked questions

What does thehive-project/thehive do?

TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables.

What are the main features of thehive-project/thehive?

The main features of thehive-project/thehive are: Incident Management, Multi-Tenant Data Management, Incident Response Management, Security Observable Extractions, Incident Response Platforms, Threat Intelligence, Automated Case Generation, Alert-to-Case Promotion.

Which projects share features with thehive-project/thehive?

Projects with overlapping indexed features include: velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… passbolt/passbolt_api — Passbolt is an open-source, self-hosted password manager designed for teams. It provides a centralized, encrypted… aws/aws-cdk — The AWS Cloud Development Kit is an infrastructure-as-code framework that enables developers to define and provision… area17/twill — Twill is a Laravel CMS toolkit and admin panel generator designed for building custom administrative consoles and… kanboard/kanboard — Kanboard is a self-hosted Kanban project management tool and productivity suite designed for tracking software tasks… tencent/weknora — WeKnora is a multi-tenant retrieval-augmented generation (RAG) knowledge platform and autonomous AI agent framework.…