Explore the full potential of OpenCTI Enterprise Edition, start your 30 days free trial.Learn more
XTM Hub by FiligranSign In
TheHive Cortex Analyzer logo

TheHive Cortex Analyzer

Incident Response & Ticketing

Overview

This integration enables TheHive to query OpenCTI for observable matches through Cortex analyzers, allowing investigators to enrich observables with threat intelligence directly from case artifacts.

The TheHive Cortex OpenCTI integration provides TheHive users with the ability to search and enrich observables using OpenCTI's threat intelligence database through Cortex analyzers. This integration streamlines threat investigation workflows by enabling direct lookups of observables from within TheHive cases.

Key capabilities include:

  • Exact Observable Matching: Use the OpenCTI_SearchExactObservable analyzer to retrieve precise matches for observables in the OpenCTI platform
  • Broad Observable Search: Leverage the OpenCTI_SearchObservables analyzer to find all observables containing the input data, enabling broader threat context discovery

Basic information

Filigran
Nino Rowlands
Third party integrations
Case Management, Other
January 26, 2026
5.6.1
0
0