TheHive Cortex Analyzer
Incident Response & Ticketing
Overview
This integration enables TheHive to query OpenCTI for observable matches through Cortex analyzers, allowing investigators to enrich observables with threat intelligence directly from case artifacts.
The TheHive Cortex OpenCTI integration provides TheHive users with the ability to search and enrich observables using OpenCTI's threat intelligence database through Cortex analyzers. This integration streamlines threat investigation workflows by enabling direct lookups of observables from within TheHive cases.
Key capabilities include:
- Exact Observable Matching: Use the OpenCTI_SearchExactObservable analyzer to retrieve precise matches for observables in the OpenCTI platform
- Broad Observable Search: Leverage the OpenCTI_SearchObservables analyzer to find all observables containing the input data, enabling broader threat context discovery
Basic information
Filigran
Nino Rowlands
Third party integrations
Case Management, Other
January 26, 2026
5.6.1
0
0