TheHive
· #112 most-usedCollaborative security incident response, automated
TheHive is an open-source, scalable security incident response platform built for collaborative SOC investigation — cases, alerts, observables, and tasks in one place. Connect it to Actionist and your agents can create alerts the moment a threat signal arrives, open full incident cases from any trigger, attach observables for enrichment, and log every action automatically. Your team spends time investigating, not filling in forms.
Eliminates manual work. Automated case creation, alert triage, observable attachment, and task assignment eliminate the manual data entry that consumes the first 20–40 minutes of every incident response.
What your TheHive agent runs on autopilot
A week of scheduled jobs your Actionist agent will execute on your behalf.
TheHive × every other app you use
End-to-end automations that span multiple apps — each one a real business outcome.
Security incident to customer comms in minutes
When a customer-reported security concern arrives by email, your agent creates a TheHive case, reads the incident's current observables to assess scope, logs the initial response action, and posts a holding message in Slack for the support team — all while drafting a calendar hold for the customer call. Nothing falls through the cracks during the frantic first twenty minutes of an incident, and the customer receives a response before a human has finished reading the email.
Time saved for your team — every week, on autopilot
Savings
What your team gets back — two angles: what you stop doing manually, and what that's worth.
What you do manually today
What your agent runs for you
- Sales18 min / weekVendor security review triage
Sales reps email the security team and wait 24–48 hours to learn whether a vendor questionnaire has been picked up.
Sales Agent0 minAgent opens TheHive case on requestAgent creates a TheHive review case, assigns it to security, and replies to the sales rep with the case number and expected completion time — all in under 5 minutes.
- Marketing13 min / weekIncident disclosure coordination
Marketing waits for security to confirm incident scope before drafting customer communications, causing multi-day delays during breach scenarios.
Marketing Agent0 minAgent reads case status in real timeAgent reads the TheHive case severity and resolution status on demand, so marketing has an accurate scope statement within seconds of asking.
- Customer Support18 min / weekSecurity ticket to case hand-off
Support agents manually summarise security-related tickets and paste them into emails to the IR team, losing context and creating duplicate work.
Customer Support Agent0 minAgent creates TheHive case from support ticketAgent parses the support ticket, creates a TheHive case with all relevant details, and notifies the IR team in Slack — the hand-off is complete before the support agent finishes the conversation.
- Human Resources7 min / weekOffboarding security checks
HR manually notifies the security team when employees leave, relying on email threads to confirm account revocation and insider-risk case closure.
Human Resources Agent0 minAgent creates offboarding case in TheHiveAgent creates a TheHive task for access revocation on each offboarding, with the employee name and last-login data attached — HR gets a closed-case confirmation automatically.
- Finance13 min / weekAudit incident register export
Finance exports incident data from multiple tools manually each quarter, reconciling dates, severities, and resolution types into a spreadsheet for auditors.
Finance Agent0 minAgent fetches and formats TheHive case registerAgent reads all closed TheHive cases for the audit period, writes the register to a structured sheet with severity and MTTR columns, and delivers it to the auditor folder.
- Operations25 min / weekThreat IOC intake and case creation
Operations copies new IOCs from spreadsheets into TheHive by hand, spending 20–30 minutes per batch ensuring correct observable types, tags, and case assignments.
Operations Agent0 minAgent ingests IOCs and creates cases automaticallyAgent reads new rows from the IOC spreadsheet, checks for duplicates in TheHive, creates a case per unique threat, and attaches the observables — a 30-minute manual task in under 2 minutes.
- Legal6 min / weekBreach notification evidence gathering
Legal manually requests incident timelines from the security team before drafting breach notifications, waiting days for formatted case exports.
Legal Agent0 minAgent exports case timeline on demandAgent fetches the relevant TheHive case with its full log history, formats a timeline summary, and delivers it to legal's shared folder — ready for the notification draft within minutes.
Calculate what your team saves
Based on TheHive's typical team usage — the visible tasks plus a few other automations the agent runs: ~2.5 hrs / person / week of admin work automated.
How to plug TheHive into Actionist
Pick the connection method that suits your environment.
The fastest path for AI-native incident response. Install the gbrigandi/mcp-server-thehive MCP server and Actionist gains full case, alert, and observable management without a token rotation policy to maintain.
Find TheHive in the Apps library and click Connect. MCP is selected by default.
The MCP server requires your TheHive instance URL (e.g. https://thehive.yourcompany.com) and an API key generated from Organisation > Create API Key in TheHive's admin panel. Paste both into the Actionist connection dialog.
Actionist runs a read-only call to verify the handshake. You're ready.
15 actions your agent can call
Read and write operations available to your Actionist agent.
6 events your agent can react to
Events your agent watches for, and the actions it kicks off in response.
Skills that pair with TheHive
Reusable agent skills that work well alongside this app.
MCP servers that work with TheHive
Connect Actionist to MCP servers built for or around this app.
A Rust-based MCP server that exposes TheHive's case management and alert APIs to AI agents, enabling collaborative incident response without manual API wiring.