The first step you should consider when starting with TheHive, customFields and statuses should match your team’s workflows and your company’s context. Creating these entities might take a bit of time, but it’s worth it in the long run: they will be later reused in all of your alerts and cases.
If we were to describe TheHive’s customFields with a quote, we’d choose this one:
customFields are the open gate to many great features for your case management and incident response, while being as simple as adding a field to your alerts and cases that you can associate with value(s).
The more customFields you create based on your company context or team behaviors, the more value they will provide. Let’s see some examples that might inspire you:
|
Threat-Category (string)
|
Which threat category an alert/case is related to.
Possible values example: Malware, Social engineering, Data leak, Credentials theft, DDoS…
|
|
Detection source (string)
|
SIEM, EDR, Suspicious Emails, NDR…
|
|
Business-Unit (string)
|
Which business unit/department is impacted by this alert/case.
Possible values example: Sales, Marketing, IT…
|
|
Site (string)
|
Which place or region is impacted by this alert/case.
Possible values example: Paris, New-York, Tokyo / EMEA, APAC, Americas…
|
When you create a customField, you have to define the type it will have—String, Boolean, Integer, Date, etc. Any customField can be assigned to a group, which can help separate them by theme if you have dozens customFields in each of your cases.
CustomFields are probably the best way to contextualize your incidents. And over time, you will get a very valuable outcome of this qualification for your cases, such as searchability, dashboarding and automations. As TheHive comes with an open API, these great qualification capabilities are also fertile ground for AI.