(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WRBNM36X'); (function(ss,ex){ window.ldfdr=window.ldfdr||function(){(ldfdr._q=ldfdr._q||[]).push([].slice.call(arguments));}; (function(d,s){ fs=d.getElementsByTagName(s)[0]; function ce(src){ var cs=d.createElement(s); cs.src=src; cs.async=1; fs.parentNode.insertBefore(cs,fs); }; ce('https://sc.lfeeder.com/lftracker_v1_'+ss+(ex?'_'+ex:'')+'.js'); })(document,'script'); })('bElvO7322MM8ZMqj');
EN
Request a demo
EN

Case templates

Bring consistency and speed to your case management in TheHive. Predefined fields and tasks guide analysts step by step, ensuring every case is handled efficiently and accurately.

If you like playbooks, you’ll love case templates. In fact, most mature teams even disable the option to create cases from scratch, ensuring analysts rely on predefined templates for consistency and efficiency.

Let’s explore why this is one of the greatest features of TheHive.

Usage & benefits

When creating a case or an alert, you can start from scratch or use a case template.

With a template, each case automatically inherits predefined customFields (and their values), tasks with clear descriptions to guide analysts, tags, TLP, severity and much more.

Having these customFields already included—and even pre-filled with values—significantly improves your average case qualification, while reducing analysts’ workload and the risk of errors.

And if you need to complete a post-mortem analysis for your incidents, templates have you covered too, with pre-written sections automatically added to the case’s text page.

(Did we already tell you that you’re going to love case templates?)

Threat- or source-oriented templates

Before creating a case template, it’s worth considering which approach or philosophy you want to follow.
A threat-oriented approach is the most commonly used and often the most effective for security teams.

For example, a phishing case template allows analysts to go deeper into every step required to analyze and respond to that specific threat. As a result, analysts are guided through successive tasks right up to case closure.

On the other hand, detection source-oriented playbooks are higher-level and often easier to implement. They give analysts more flexibility to adapt their response to each situation and can also simplify the mapping of alert sources during integration.

So far, these are the two main approaches we’ve seen in use. But because TheHive is highly flexible, you can design templates that follow your own methodology—no matter how advanced or unique it is.

The anatomy of a case template

Let’s take a closer look at each component of a case template and see how to extract the most value from this feature.

  • Prefix: Text added before the title of cases created from this template to improve readability in the case list. Keep it short and clear, e.g. “Phishing –”.
  • Name: The technical name of your case template, mainly used via the API.
  • Display name: The name as it appears in the GUI.
  • TLP, PAP, Severity, Tags and Description*: Default values for their respective fields in the case.
  • Tasks: The list of actions analysts will perform to bring the case to closure. Each task can include a description that explains what is expected and how to complete it.
  • CustomFields: The list of customFields automatically added to the case. You can define one or more default values for each field.
  • Pages: Add default pages to the case.

*These values can be overridden by the analyst or by data coming from an alert.

Building an efficient task list

If your team already has well-defined playbooks, building your task list will be as easy as ABC. And if not, it might be the perfect time to create them!

Starting from your existing playbooks or workflows, simply break down each step into a task and use the task description to define the what and how:

  • What is expected from the analyst when performing this task.
  • How they are expected to do it.
Expand

Another way to build a task list is to reuse a structure that’s widely adopted across the community for all your case templates: Preparation, Identification, Containment, Remediation, Recovery and Lessons Learned.

Using such a standard framework means you’ll need to clarify what each task represents in the context of your own playbook. In this case, the more information you provide to analysts through task descriptions, the less room there is for mistakes or omissions.

Expand

Missing inspiration to create your case template tasks? A great place to start is by looking at standard incident response procedures and adapting them over time to fit your team’s needs and context.

The next section might just give you the inspiration you’re looking for!

CERT-SG IRM case templates

At StrangeBee, we love the CERT-SG IRM sheets: they are an strong foundation for any team building its own incident response procedures.

We thought our users would enjoy using them as case templates and customizing them to add their own touch, so we made it happen:

Download and import the CERT-SG IRM case templates into your TheHive instance
_stq = window._stq || []; _stq.push([ "view", {"v":"ext","blog":"234289117","post":"6751","tz":"0","srv":"strangebee.com","hp":"atomic","ac":"2","amp":"0","j":"1:16.3-a.3"} ]); _stq.push([ "clickTrackerInit", "234289117", "6751" ]); //# sourceURL=jetpack-stats-js-before