TheHive
SOC case management platform, now freemium under StrangeBee after its open source era.
Technical Architecture & Overview
TheHive is the best-known SOC case management platform, organizing alerts into cases with tasks, observables, and timeline tracking, and pairing with MISP and Cortex. Version 5 moved from the original AGPL open source model to a proprietary freemium license in 2022 under StrangeBee, with a free tier for small teams and paid plans above it. TheHive 4 remains open source for teams that need that path.
Targeted Technical Use Cases
SOC teams that want mature case management with analyst workflow and integrations already designed in.
Evaluation & Trade-offs
Core Strengths
- +Purpose-built analyst workflow with a large user base.
- +Cortex and MISP integration are native.
- +Free tier covers small teams.
Trade-Offs & Limitations
- -v5 licensing is closed; open source only applies to v4.
- -Platform migration from v4 needs planning.
Defensive Security Application
Structuring alert triage and incident casework for security operations teams.
Frequently Asked Questions
What is TheHive?→
TheHive is the best-known SOC case management platform, organizing alerts into cases with tasks, observables, and timeline tracking, and pairing with MISP and Cortex. Version 5 moved from the original AGPL open source model to a proprietary freemium license in 2022 under StrangeBee, with a free tier for small teams and paid plans above it. TheHive 4 remains open source for teams that need that path.
What is TheHive used for?→
SOC teams that want mature case management with analyst workflow and integrations already designed in.
What are the strengths of TheHive?→
- +Purpose-built analyst workflow with a large user base.
- +Cortex and MISP integration are native.
- +Free tier covers small teams.
What are the limitations of TheHive?→
- +v5 licensing is closed; open source only applies to v4.
- +Platform migration from v4 needs planning.
How is TheHive used defensively?→
Structuring alert triage and incident casework for security operations teams.