(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src= 'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f); })(window,document,'script','dataLayer','GTM-WRBNM36X'); (function(ss,ex){ window.ldfdr=window.ldfdr||function(){(ldfdr._q=ldfdr._q||[]).push([].slice.call(arguments));}; (function(d,s){ fs=d.getElementsByTagName(s)[0]; function ce(src){ var cs=d.createElement(s); cs.src=src; cs.async=1; fs.parentNode.insertBefore(cs,fs); }; ce('https://sc.lfeeder.com/lftracker_v1_'+ss+(ex?'_'+ex:'')+'.js'); })(document,'script'); })('bElvO7322MM8ZMqj');
EN
Request a demo
EN

TheHive MCP Server

Connect any AI assistant to your incident investigations
What TheHive MCP is

Connect AI models to your investigations, data and workflows in TheHive

What is MCP in TheHive?

Model Context Protocol is an open standard for connecting AI applications to external tools and data systems.

Security analysts spend hours on case documentation, manual lookups and status updates. TheHive MCP Server uses this standard to connect any AI assistant directly to TheHive.

Instead of switching between tools or writing scripts, analysts can describe what they need in natural language, and the AI acts on live TheHive data.

KEY BENEFITS

What security teams can achieve with TheHive MCP

Standardized AI access to investigations

Every new AI tool used to mean a new integration. TheHive MCP provides a unified interface for AI models to access cases, alerts, observables and analyzers.

Evolve your AI tooling without breaking integrations

AI models evolve fast. Switch or upgrade them without redesigning integrations or rebuilding your SOC workflows: MCP separates these models from TheHive via a stable protocol.

Controlled and secure AI interactions

AI systems acting on live security data raises real concerns. With TheHive MCP, they interact with TheHive through controlled access, so you have all actions governed by existing permissions and policies.

AI that understands investigation context

An AI assistant is only as useful as the context it has. TheHive MCP gives models direct access to the full investigation picture: alerts, observables and case history.

Let us show you how TheHive MCP can help your team!
TheHive
Let us show you how MCP can help your team!
USE CASES

What you can do
with TheHive MCP Server

See TheHive
in action
Request a free demo to discover how TheHive MCP Server can empower your security investigations with AI!
WANT TO KNOW MORE?

Frequently Asked Questions

What is TheHive MCP Server?

TheHive MCP Server is an implementation of the Model Context Protocol that connects LLMs (such as Claude or ChatGPT) directly to TheHive. Instead of switching between tools or writing scripts, analysts describe what they need in natural language, and the AI assistant acts on TheHive data.

How does TheHive MCP integrate with AI assistants and agentic workflows?

The Model Context Protocol standard means TheHive works with any MCP-compatible AI assistant. Once connected, the assistant gains direct access to TheHive’s API without any custom integration work. Analysts interact in natural language; the MCP translates those instructions into API calls against live TheHive data. Teams can choose the LLM that fits their security and infrastructure requirements, including fully on-prem setups where no data leaves the environment.

What TheHive actions can I perform through the MCP Server?

Through TheHive MCP Server, you can create and update cases, add and enrich observables, run Cortex analyzers on an observable, consolidate their outputs into a single summary and more. Actions that would normally require API calls or manual navigation can be triggered with a plain-language instruction.

What AI clients are compatible with TheHive MCP Server?

Any MCP-compatible AI client works with TheHive MCP Server. This includes Claude Desktop, ChatGPT and other tools built on the Model Context Protocol standard. As MCP adoption grows across the AI ecosystem, the list of compatible clients continues to expand.

Which TheHive deployment types are supported?

TheHive MCP Server supports both cloud and on-premises deployments. Teams running TheHive in air-gapped or restricted environments can use an on-prem LLM, keeping all data within their infrastructure.

Does the MCP Server bypass TheHive's access controls?

No. The MCP Server connects to TheHive using standard API authentication and operates within the permissions of the configured user account. Analysts can only access and modify data they are already authorized to see—the MCP layer adds no additional privileges.

_stq = window._stq || []; _stq.push([ "view", {"v":"ext","blog":"234289117","post":"9401","tz":"0","srv":"strangebee.com","hp":"atomic","ac":"2","amp":"0","j":"1:16.2-a.5"} ]); _stq.push([ "clickTrackerInit", "234289117", "9401" ]); //# sourceURL=jetpack-stats-js-before