(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WRBNM36X'); (function(ss,ex){ window.ldfdr=window.ldfdr||function(){(ldfdr._q=ldfdr._q||[]).push([].slice.call(arguments));}; (function(d,s){ fs=d.getElementsByTagName(s)[0]; function ce(src){ var cs=d.createElement(s); cs.src=src; cs.async=1; fs.parentNode.insertBefore(cs,fs); }; ce('https://sc.lfeeder.com/lftracker_v1_'+ss+(ex?'_'+ex:'')+'.js'); })(document,'script'); })('bElvO7322MM8ZMqj');
EN
Request a demo
EN

Cortex analyzers & responders

Speed up your investigations and response. Turn raw observables into actionable intelligence with a single click and instantly launch responses to discovered threats.

No more chaos in your browser tabs every time you investigate observables: thanks to TheHive’s native integration with the Cortex engine, you can launch analyses in a single click—and the results will flow straight into your TheHive cases.

With over 300 out-of-the-box integrations to third-party tools, you’re always ready to analyze and quickly respond to any threat.

Analyzers

Incident response teams often have a diverse set of tools in their toolbox to analyze observables. Some are highly efficient, while others are used to provide indications without being fully trusted. Analysts still prefer to confirm their judgments by obtaining reputations from multiple sources.

Once your Cortex is connected to TheHive and your Cortex analyzers are enabled, triggering an analysis and getting a report directly into the case is a breeze: just click on the little “fire” button (see the screenshot below). The great thing is that the report will be archived and available at any time, in case someone reviews the case and wonders why a particular decision was made.

Expand

Once the analysis is complete, small labels are applied so anyone viewing the list of observables can instantly see which items are marked as malicious, suspicious or safe. Blue labels indicate useful information.

Expand

All analyzers in the StrangeBee catalog come with an HTML report template, transforming each analysis result from a raw API JSON response into a clean, human-readable document that highlights the most relevant information for analysts.

By embedding analysis tools directly into cases, TheHive helps analysts eliminate redundant actions and stay focused on what matters most: analyzing data and making informed decisions.

Responders

Responders are another powerful way to eliminate the repetitive tasks your analysts perform every day. By automating these actions and making them directly accessible, you ensure that incident responses are handled faster and more effectively.

Imagine an alert about a suspicious file detected on a host. You run analyzers to learn more about the file or its hash—and discover it’s linked to a botnet known to spread across the network.

No time to lose! Instead of switching to your EDR, searching manually for the infected host and requesting its isolation, you can simply launch a responder straight from the observable in TheHive to isolate the host immediately.

By making this action available directly within TheHive, analysts save precious time when it matters most, protecting the organization before the threat spreads.

Cortex responders aren’t only designed for the most critical or urgent actions. They can also be used to transfer information from a case to third-party tools—for example, via their APIs.

With responders, your imagination is the only limit. They empower analysts with fast, effective and easily accessible automations that reduce response time and lighten their workload.

Learn all there is about the Cortex analyzers and responders
Cortex analyzers & responders

Cortex analyzers & responders

_stq = window._stq || []; _stq.push([ "view", {"v":"ext","blog":"234289117","post":"6786","tz":"0","srv":"strangebee.com","hp":"atomic","ac":"2","amp":"0","j":"1:16.1-beta.3"} ]); _stq.push([ "clickTrackerInit", "234289117", "6786" ]); //# sourceURL=jetpack-stats-js-before