(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WRBNM36X'); (function(ss,ex){ window.ldfdr=window.ldfdr||function(){(ldfdr._q=ldfdr._q||[]).push([].slice.call(arguments));}; (function(d,s){ fs=d.getElementsByTagName(s)[0]; function ce(src){ var cs=d.createElement(s); cs.src=src; cs.async=1; fs.parentNode.insertBefore(cs,fs); }; ce('https://sc.lfeeder.com/lftracker_v1_'+ss+(ex?'_'+ex:'')+'.js'); })(document,'script'); })('bElvO7322MM8ZMqj');
EN
Request a demo
EN

Entity management (customFields & statuses)

Add custom values and assign statuses to alerts and cases in TheHive to contextualize your incident management.

The first step you should consider when starting with TheHive, customFields and statuses should match your team’s workflows and your company’s context. Creating these entities might take a bit of time, but it’s worth it in the long run: they will be later reused in all of your alerts and cases.

CustomFields

If we were to describe TheHive’s customFields with a quote, we’d choose this one:

Little things make big things happen.
American-basketball-coach-John-Wooden-1993
John Wooden,

American basketball coach and player

customFields are the open gate to many great features for your case management and incident response, while being as simple as adding a field to your alerts and cases that you can associate with value(s).

The more customFields you create based on your company context or team behaviors, the more value they will provide. Let’s see some examples that might inspire you:

Threat-Category (string) Which threat category an alert/case is related to.

Possible values example: Malware, Social engineering, Data leak, Credentials theft, DDoS…

Detection source (string) SIEM, EDR, Suspicious Emails, NDR…
Business-Unit (string) Which business unit/department is impacted by this alert/case.

Possible values example: Sales, Marketing, IT…

Site (string) Which place or region is impacted by this alert/case.

Possible values example: Paris, New-York, Tokyo / EMEA, APAC, Americas…

When you create a customField, you have to define the type it will have—String, Boolean, Integer, Date, etc. Any customField can be assigned to a group, which can help separate them by theme if you have dozens customFields in each of your cases.

CustomFields are probably the best way to contextualize your incidents. And over time, you will get a very valuable outcome of this qualification for your cases, such as searchability, dashboarding and automations. As TheHive comes with an open API, these great qualification capabilities are also fertile ground for AI.

See here how to create your customFields:

Case & alert status

Experienced teams create custom workflows for investigating and responding to cases based on their specific context. Each step in these workflows represents a part of the case lifecycle and can be given a title, which then becomes a status for the case.

Since your team probably has its own workflows, TheHive 5 allows you to define your own alert and case statuses. Simple and efficient.

Each status must be associated with one of these stages: New, In progress, Closed or Imported* (*For alerts only). You can also choose a color to represent each status. Best of all, statuses and stages can trigger notifications and other automations.

Some examples of common custom statuses you might want to create and use:

  • Pending reply
  • Investigating
  • Post-incident activities
See how to create your custom statuses
Entity management (customFields & statuses)

Entity management (customFields & statuses)

_stq = window._stq || []; _stq.push([ "view", {"v":"ext","blog":"234289117","post":"6744","tz":"0","srv":"strangebee.com","hp":"atomic","ac":"2","amp":"0","j":"1:16.3-a.7"} ]); _stq.push([ "clickTrackerInit", "234289117", "6744" ]); //# sourceURL=jetpack-stats-js-before