TheHive-Project/TheHive
TheHive is a Collaborative Case Management Platform, now distributed as a commercial version observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 33
- Release rhythm 8
- Longevity 100
Flags: archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3590
- days_rel: n/a
- days_push: 404
- n_releases_24m: 0
Adoption not part of the score
3947 stars · 694 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
TheHive is a collaborative security incident response and case management platform for SOC teams, supporting alert triage, case investigation, observables/IOC tracking, and MISP/Cortex integrations. The open-source versions 3.x and 4.x are archived and no longer distributed; the project has transitioned to a commercial product (TheHive 5) by StrangeBee.
Use cases
- manage security incident cases for a SOC team
- triage alerts and convert them into investigation cases
- track IOCs and observables during forensics investigations
- integrate MISP threat intelligence into incident workflows
- automate alert ingestion from mailboxes and external feeders
- run analyzers and responders on observables
- generate case reports for incident response documentation
When to choose
- you need collaborative case management for security incident response
- you want MISP and Cortex integration for threat intel and automated analysis
- you are a SOC or MSSP needing alert triage, case templates, and KPI dashboards
- you can use the commercial TheHive 5 or already have legacy 3/4 deployments
When to avoid
- you need a fully open-source, self-hosted case management platform - versions 3/4 are archived and unsupported
- you want a free community edition - TheHive is now commercial only
- you need general-purpose project or ticket management rather than security incident response
- you cannot adopt StrangeBee licensing or paid support
Facets
application · maturity maintenance
security workflow-automation api-framework self-hosted security developer-tools self-hosted incident-response case-management soc dfir misp threat-intel siem-adjacent commercial-transition automation web-server linux
9 sources
- readme: https://github.com/TheHive-Project/TheHive · fetched 2026-08-28 · d9870d59cdbf
- homepage: https://strangebee.com/ · fetched 2026-08-29 · 3c0d6edf3e67
- site_page: https://strangebee.com/about-strangebee · fetched 2026-08-29 · 314e4b0d6874
- site_page: https://strangebee.com/thehive-features · fetched 2026-08-29 · 32b3ec8a83c7
- site_page: https://docs.strangebee.com · fetched 2026-08-29 · 1ed6c17ecb4d
- site_page: https://docs.strangebee.com/ · fetched 2026-08-29 · 1ed6c17ecb4d
- site_page: https://strangebee.com/thehive-pricing · fetched 2026-08-29 · ee63c03d6507
- site_page: https://strangebee.com/thehive-integrations · fetched 2026-08-29 · 3cb0ddb76a17
- site_page: https://strangebee.com/integrations · fetched 2026-08-29 · 3cb0ddb76a17
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| TheHive-Project/TheHive | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="TheHive-Project/TheHive")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem