TheHive-Project/Cortex
Cortex: a Powerful Observable Analysis and Active Response Engine observed · 2026-08-28
Health v2 · maintenance only
84/100
- Activity 90
- Release rhythm 66
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: 134
- age_days: 3522
- days_rel: 64
- days_push: 64
- n_releases_24m: 4
Adoption not part of the score
1618 stars · 265 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Cortex is an open-source observable analysis and active response engine for SOCs, CSIRTs, and security researchers. It lets analysts analyze observables like IPs, URLs, domains, files, and hashes at scale via a web interface or REST API, using dozens of pluggable analyzers and responders, and integrates tightly with TheHive and MISP.
Use cases
- analyze IPs, URLs, domains, and file hashes in bulk during incident response
- enrich IOCs with threat intelligence from a single tool
- automate observable analysis via a REST API
- run responders to take active response actions on observables
- integrate automated analysis into TheHive or MISP workflows
- write custom analyzers for internal tools and services
When to choose
- you run a SOC or CSIRT and need to analyze many observables at scale
- you want one tool to orchestrate dozens of threat-intel enrichment services
- you use TheHive or MISP and want native analyzer integration
- you need a horizontally scalable, stateless REST API for automated enrichment
When to avoid
- you need a general-purpose SIEM or case management platform (use TheHive alongside it)
- you want a lightweight one-off IOC lookup script rather than an analysis engine
- you cannot host a JVM-based Linux service or maintain Docker deployments
Facets
service · maturity maintenance
security workflow-automation api-framework http-server security self-hosted dfir soc csirt observable-analysis analyzer-engine responder thehive misp ioc-enrichment rest-api scala agpl incident-response threat-intelligence digital-forensics automation linux web-server docker
9 sources
- readme: https://github.com/TheHive-Project/Cortex · fetched 2026-08-28 · d3d3f9971635
- homepage: https://strangebee.com/cortex/ · fetched 2026-08-29 · fb410c256a84
- site_page: https://strangebee.com/about-strangebee · fetched 2026-08-29 · 314e4b0d6874
- site_page: https://strangebee.com/thehive-features · fetched 2026-08-29 · 32b3ec8a83c7
- site_page: https://docs.strangebee.com · fetched 2026-08-29 · 1ed6c17ecb4d
- site_page: https://docs.strangebee.com/ · fetched 2026-08-29 · 1ed6c17ecb4d
- site_page: https://strangebee.com/thehive-pricing · fetched 2026-08-29 · ee63c03d6507
- site_page: https://strangebee.com/thehive-integrations · fetched 2026-08-29 · 3cb0ddb76a17
- site_page: https://strangebee.com/integrations · fetched 2026-08-29 · 3cb0ddb76a17
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| TheHive-Project/Cortex | main | 84 |
For agents
markdown · JSON · MCP: product_card(name="TheHive-Project/Cortex")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem