Cortex
Open source analysis and response engine that automates observable enrichment and incident actions.
Technical Architecture & Overview
Cortex runs analyses against observables such as IPs, domains, hashes, and files using dozens of analyzer integrations, and it executes responders that take actions like blocking or quarantine. It pairs with TheHive but runs standalone through its API, and it remains fully open source under AGPL even after TheHive moved to a commercial license. Teams use it to standardize enrichment that analysts would otherwise do by hand.
Targeted Technical Use Cases
Automated multi-source enrichment of IOCs and response actions wired into case management.
Evaluation & Trade-offs
Core Strengths
- +Large analyzer catalog in one framework.
- +Still fully open source.
- +Responder actions close the loop from alert to action.
Trade-Offs & Limitations
- -Java-based deployment has operational weight.
- -Analyzer credentials and rate limits need management.
Defensive Security Application
Consistent, automated enrichment and response actions across investigation workflows.
Frequently Asked Questions
What is Cortex?→
Cortex runs analyses against observables such as IPs, domains, hashes, and files using dozens of analyzer integrations, and it executes responders that take actions like blocking or quarantine. It pairs with TheHive but runs standalone through its API, and it remains fully open source under AGPL even after TheHive moved to a commercial license. Teams use it to standardize enrichment that analysts would otherwise do by hand.
What is Cortex used for?→
Automated multi-source enrichment of IOCs and response actions wired into case management.
What are the strengths of Cortex?→
- +Large analyzer catalog in one framework.
- +Still fully open source.
- +Responder actions close the loop from alert to action.
What are the limitations of Cortex?→
- +Java-based deployment has operational weight.
- +Analyzer credentials and rate limits need management.
How is Cortex used defensively?→
Consistent, automated enrichment and response actions across investigation workflows.