Responders are another powerful way to eliminate the repetitive tasks your analysts perform every day. By automating these actions and making them directly accessible, you ensure that incident responses are handled faster and more effectively.
Imagine an alert about a suspicious file detected on a host. You run analyzers to learn more about the file or its hash—and discover it’s linked to a botnet known to spread across the network.
No time to lose! Instead of switching to your EDR, searching manually for the infected host and requesting its isolation, you can simply launch a responder straight from the observable in TheHive to isolate the host immediately.
By making this action available directly within TheHive, analysts save precious time when it matters most, protecting the organization before the threat spreads.
Cortex responders aren’t only designed for the most critical or urgent actions. They can also be used to transfer information from a case to third-party tools—for example, via their APIs.
With responders, your imagination is the only limit. They empower analysts with fast, effective and easily accessible automations that reduce response time and lighten their workload.