Integration Catalog
Auto-generated catalog of TheHive and Cortex integrations.
About This Catalog
This catalog contains integrations built by StrangeBee and the community to help you integrate TheHive with your existing tools. Use them directly or as inspiration for your own.
Don't see what you need? You can build your own:
- Analyzers – enrich observables with external data
- Responders – automate actions on external systems
- Functions – custom workflow logic
- Custom tools – whatever your setup requires
Built something useful? Contributions are welcome!
📊 Summary Statistics
- Total Vendors: 194
- Total Analyzers: 259
- Total Responders: 132
- Total Functions: 7
- Total External Integrations: 10
- Total Integrations: 408
📂 Vendors by Category
Attack Surface Intelligence
ONYPHE (5 integrations) ONYPHE is a cyber defense search engine that collects and analyzes internet-wide scan data, provi...
Shodan (6 integrations) Shodan is the search engine for internet-connected devices, providing reconnaissance data on expo...
Breach Intelligence
Have I Been Pwned (1 integrations) Have I Been Pwned tracks billions of compromised credentials from data breaches, allowing analyst...
Collaboration
Slack (2 integrations) Slack is a is a team collaboration platform that provides channels, direct messaging, file sharin...
Telegram (1 integrations) Telegram is a cloud-based messaging platform that enables real-time security alerts, incident not...
DFIR
Velociraptor (1 integrations) Velociraptor is an advanced digital forensics and incident response (DFIR) platform that enables ...
EDR
CrowdStrike Falcon (22 integrations) CrowdStrike Falcon is a cloud-native endpoint protection platform that provides real-time threat ...
Microsoft Defender for Endpoint (8 integrations) Microsoft Defender for Endpoint is an enterprise EDR platform that provides threat detection, inv...
Email Security
Microsoft Defender for Office 365 (3 integrations) Microsoft Defender for Office 365 provides advanced threat protection for email and collaboration...
Proofpoint (3 integrations) Proofpoint is an enterprise email security and threat protection platform that provides advanced ...
Identity & Access Management
Microsoft Entra ID (9 integrations) Microsoft Entra ID (formerly Azure Active Directory) is an enterprise identity and access managem...
Malware Analysis
CAPA (1 integrations) CAPA (FLARE Capability Analysis) is a malware analysis tool that automatically identifies malware...
Hybrid Analysis (1 integrations) Hybrid Analysis (Falcon Sandbox) is a free malware analysis service powered by CrowdStrike that e...
VirusTotal (4 integrations) VirusTotal is a comprehensive malware analysis platform aggregating results from 70+ antivirus en...
YARA (1 integrations) YARA is a pattern matching engine for malware identification and classification that enables anal...
OSINT & Enrichment
Hunter.io (1 integrations) Hunter.io discovers and verifies email addresses associated with domains, enabling investigators ...
IPinfo (2 integrations) IPinfo provides comprehensive IP address intelligence including geolocation, ASN ownership, compa...
MaxMind (1 integrations) MaxMind provides geolocation and network intelligence data that maps IP addresses to geographic l...
Mnemonic Passive DNS (2 integrations) Mnemonic Passive DNS provides historical DNS resolution data that helps analysts track domain inf...
SIEM & Analytics
Elasticsearch (2 integrations) Elasticsearch is a distributed search and analytics engine that powers SIEM solutions and log ana...
Splunk (14 integrations) Splunk is a leading SIEM platform that aggregates, indexes, and analyzes machine data from across...
SOAR & Automation
Cortex XSOAR (1 integrations) Cortex XSOAR is Palo Alto Networks' SOAR platform that enables security teams to automate inciden...
n8n (2 integrations) n8n is a low-code/no-code workflow automation platform that enables technical teams to build, dep...
Rapid7 InsightConnect (1 integrations) Rapid7 InsightConnect is a security orchestration and automation platform that enables security t...
Shuffle (2 integrations) Shuffle is an open-source security orchestration, automation and response (SOAR) platform that au...
Tines (1 integrations)
Threat Intelligence
AbuseIPDB (2 integrations) AbuseIPDB is a crowdsourced IP reputation database that helps identify and track malicious IPs in...
AlienVault OTX (1 integrations) AlienVault Open Threat Exchange (OTX) is a collaborative threat intelligence platform where secur...
CrowdSec (1 integrations) CrowdSec is a collaborative security platform that aggregates attack data from community-deployed...
EmailRep (1 integrations) EmailRep analyzes email addresses to detect disposable emails, spam sources, and malicious sender...
Google Threat Intelligence (5 integrations) Google Threat Intelligence (formerly VirusTotal) provides comprehensive malware analysis, threat ...
Maltiverse (1 integrations) Maltiverse is a threat intelligence platform that aggregates and enriches IOCs from multiple sour...
MalwareBazaar (1 integrations) MalwareBazaar by Abuse.ch is a community-driven malware sample repository that enables analysts t...
MISP (1 integrations) MISP is an open-source threat intelligence platform for sharing, storing and correlating Indicato...
Recorded Future (1 integrations) Recorded Future is a real-time threat intelligence platform that analyzes data from the open web,...
ThreatConnect (1 integrations) ThreatConnect is a threat intelligence platform that enables security teams to aggregate, analyze...
URLhaus (1 integrations) URLhaus is a community-driven platform by Abuse.ch for tracking and sharing malware distribution ...
URL Analysis
URLScan.io (2 integrations) URLScan.io is an automated web scanner that analyzes URLs and websites in real-time, capturing sc...
Web Application Firewall
Cloudflare (1 integrations)
🔤 All Vendors (A-Z)
- Abuse_Finder - Uncategorized - 1 analyzers
- AbuseIPDB - Threat Intelligence - 1 analyzers, 1 responders
- AILOnionLookup - Uncategorized - 1 analyzers
- Airtable - Uncategorized - 1 functions
- AlienVault OTX - Threat Intelligence - 1 analyzers
- AMPforEndpoints - Uncategorized - 5 responders
- AnyRun - Uncategorized - 1 analyzers
- Autofocus - Uncategorized - 3 analyzers
- AWSLambda - Uncategorized - 1 responders
- AWX - Uncategorized - 1 responders
- Axur - Uncategorized - 1 analyzers
- BackscatterIO - Uncategorized - 2 analyzers
- BinalyzeAIR - Uncategorized - 2 responders
- C1fApp - Uncategorized - 1 analyzers
- CAPA - Malware Analysis - 1 analyzers
- Censys - Uncategorized - 1 analyzers
- CERTatPassiveDNS - Uncategorized - 1 analyzers
- ChainAbuse - Uncategorized - 1 analyzers
- CheckPhish - Uncategorized - 2 analyzers
- CheckPoint - Uncategorized - 2 responders
- CIRCLHashlookup - Uncategorized - 1 analyzers
- CIRCLPassiveDNS - Uncategorized - 1 analyzers
- CIRCLPassiveSSL - Uncategorized - 1 analyzers
- CIRCLVulnerabilityLookup - Uncategorized - 1 analyzers
- CiscoUmbrella - Uncategorized - 1 analyzers, 1 responders
- CISMCAP - Uncategorized - 1 analyzers
- ClamAV - Uncategorized - 1 analyzers
- Cloudflare - Web Application Firewall - 1 responders
- Cluster25 - Uncategorized - 1 analyzers
- ClusterHawk - Uncategorized - 1 analyzers
- Cortex XSOAR - SOAR & Automation - 1 external
- CrowdSec - Threat Intelligence - 1 analyzers
- CrowdStrike Falcon - EDR - 11 analyzers, 9 responders, 1 functions, 1 external
- Crtsh - Uncategorized - 1 analyzers
- CuckooSandbox - Uncategorized - 2 analyzers
- CyberChef - Uncategorized - 3 analyzers
- CyberCrime-Tracker - Uncategorized - 1 analyzers
- Cyberprotect - Uncategorized - 1 analyzers
- Cylance - Uncategorized - 1 analyzers
- Diario - Uncategorized - No integrations
- DNS-RPZ - Uncategorized - 1 responders
- DNSDB - Uncategorized - 3 analyzers
- DNSdumpster - Uncategorized - 1 analyzers
- DNSLookingglass - Uncategorized - 1 analyzers
- DNSSinkhole - Uncategorized - 1 analyzers
- DomainMailSPFDMARC - Uncategorized - 1 analyzers
- DomainTools - Uncategorized - 10 analyzers
- DomainToolsIris - Uncategorized - 2 analyzers, 2 responders
- DShield - Uncategorized - 1 analyzers
- Duo_Security - Uncategorized - 3 responders
- EchoTrail - Uncategorized - 1 analyzers
- EclecticIQ - Uncategorized - 1 analyzers
- EclecticIQIndicator - Uncategorized - 1 responders
- Elasticsearch - SIEM & Analytics - 1 analyzers, 1 external
- EmailRep - Threat Intelligence - 1 analyzers
- EmergingThreats - Uncategorized - 3 analyzers
- EmlParser - Uncategorized - 1 analyzers
- FalconCustomIOC - Uncategorized - 2 responders
- FalconSandbox - Uncategorized - 1 analyzers
- FileInfo - Uncategorized - 1 analyzers
- FireEyeiSight - Uncategorized - 1 analyzers
- FireHOLBlocklists - Uncategorized - 1 analyzers
- ForcepointWebsensePing - Uncategorized - 1 analyzers
- Fortiguard - Uncategorized - No integrations
- FoxIO - Uncategorized - 1 analyzers
- Gatewatcher_CTI - Uncategorized - 1 analyzers
- Gatewatcher_CTI_Identity - Uncategorized - 1 responders
- Gmail - Uncategorized - 5 responders
- Google Threat Intelligence - Threat Intelligence - 5 analyzers
- GoogleDNS - Uncategorized - 1 analyzers
- GoogleSafebrowsing - Uncategorized - 1 analyzers
- GoogleVisionAPI - Uncategorized - 1 analyzers
- GreyNoise - Uncategorized - 1 analyzers
- GRR - Uncategorized - 1 analyzers
- HarfangLab - Uncategorized - 31 responders
- Hashdd - Uncategorized - 2 analyzers
- Have I Been Pwned - Breach Intelligence - 1 analyzers
- Hippocampe - Uncategorized - No integrations
- Hunter.io - OSINT & Enrichment - 1 analyzers
- Hybrid Analysis - Malware Analysis - 1 analyzers
- IBMQRadar - Uncategorized - 1 responders
- IBMXForce - Uncategorized - 1 analyzers
- Inoitsu - Uncategorized - 1 analyzers
- IntezerCommunity - Uncategorized - 1 analyzers
- Investigate - Uncategorized - 2 analyzers
- IP-API - Uncategorized - 1 analyzers
- IPinfo - OSINT & Enrichment - 2 analyzers
- IPVoid - Uncategorized - 1 analyzers
- isMalicious - Uncategorized - 1 analyzers
- IVRE - Uncategorized - 1 analyzers
- JAMFProtect - Uncategorized - 2 responders, 1 functions
- JIRA - Uncategorized - 1 functions
- JoeSandbox - Uncategorized - 3 analyzers
- Jupyter - Uncategorized - 1 analyzers, 1 responders
- KasperskyTIP - Uncategorized - 1 analyzers
- KnowBe4 - Uncategorized - 1 responders
- LdapQuery - Uncategorized - 1 analyzers
- Lookyloo - Uncategorized - 1 analyzers
- LupovisProwl - Uncategorized - 1 analyzers
- Mailer - Uncategorized - 1 responders
- MailIncidentStatus - Uncategorized - 1 responders
- Malpedia - Uncategorized - 1 analyzers
- Maltiverse - Threat Intelligence - 1 analyzers
- MalwareBazaar - Threat Intelligence - 1 analyzers
- MalwareClustering - Uncategorized - 1 analyzers
- Malwares - Uncategorized - 2 analyzers
- MaxMind - OSINT & Enrichment - 1 analyzers
- MetaDefender - Uncategorized - 5 analyzers
- Microsoft Defender for Endpoint - EDR - 8 responders
- Microsoft Defender for Office 365 - Email Security - 1 analyzers, 2 responders
- Microsoft Entra ID - Identity & Access Management - 4 analyzers, 5 responders
- Minemeld - Uncategorized - 1 responders
- MISP - Threat Intelligence - 1 analyzers
- MISPWarningLists - Uncategorized - 1 analyzers
- Mnemonic Passive DNS - OSINT & Enrichment - 2 analyzers
- MsgParser - Uncategorized - 1 analyzers
- n8n - SOAR & Automation - 1 responders, 1 external
- NERD - Uncategorized - 1 analyzers
- Nessus - Uncategorized - 1 analyzers
- Netcraft - Uncategorized - 1 responders
- NSRL - Uncategorized - 1 analyzers
- Okta - Uncategorized - 1 analyzers
- ONYPHE - Attack Surface Intelligence - 5 analyzers
- ONYPHEActiveScan - Uncategorized - 1 analyzers
- OpenCTI - Uncategorized - 2 analyzers
- OrionMalware - Uncategorized - 1 analyzers
- PaloAltoCortexXDR - Uncategorized - 3 responders
- PaloAltoNGFW - Uncategorized - 16 responders
- PaloAltoWildFire - Uncategorized - 1 analyzers, 1 responders
- PassiveTotal - Uncategorized - 11 analyzers
- Patrowl - Uncategorized - 1 analyzers
- PayloadSecurity - Uncategorized - 2 analyzers
- PhishingInitiative - Uncategorized - 2 analyzers
- PhishTank - Uncategorized - 1 analyzers
- Proofpoint - Email Security - 1 analyzers, 2 functions
- Pulsedive - Uncategorized - 1 analyzers
- QrDecode - Uncategorized - 1 analyzers
- Rapid7 InsightConnect - SOAR & Automation - 1 external
- Recorded Future - Threat Intelligence - 1 analyzers
- Redmine - Uncategorized - 1 responders
- RiskIQ - Uncategorized - 16 analyzers, 1 responders
- Robtex - Uncategorized - 3 analyzers
- RT4 - Uncategorized - 1 responders
- SecurityTrails - Uncategorized - 2 analyzers
- SEKOIAIntelligenceCenter - Uncategorized - 3 analyzers
- SendGrid - Uncategorized - 1 responders
- SentinelOne - Uncategorized - 1 analyzers, 1 responders
- Shodan - Attack Surface Intelligence - 6 analyzers
- Shuffle - SOAR & Automation - 1 responders, 1 external
- SinkDB - Uncategorized - 1 analyzers
- Slack - Collaboration - 2 responders
- SoltraEdge - Uncategorized - 1 analyzers
- SophosIntelix - Uncategorized - 3 analyzers
- SpamAssassin - Uncategorized - 1 analyzers
- SpamhausDBL - Uncategorized - 1 analyzers
- Splunk - SIEM & Analytics - 11 analyzers, 1 functions, 2 external
- StamusNetworks - Uncategorized - 1 analyzers
- StaxxSearch - Uncategorized - 1 analyzers
- StopForumSpam - Uncategorized - 1 analyzers
- TalosReputation - Uncategorized - No integrations
- TeamCymruMHR - Uncategorized - 1 analyzers
- Telegram - Collaboration - 1 responders
- Test - Uncategorized - 2 responders
- TestAnalyzer - Uncategorized - 2 analyzers
- ThreatConnect - Threat Intelligence - 1 external
- Threatcrowd - Uncategorized - No integrations
- ThreatGrid - Uncategorized - 1 analyzers
- ThreatMiner - Uncategorized - 1 analyzers
- ThreatResponse - Uncategorized - 1 analyzers
- Thunderstorm - Uncategorized - 1 analyzers
- Tines - SOAR & Automation - 1 external
- TorBlutmagie - Uncategorized - 1 analyzers
- TorProject - Uncategorized - 1 analyzers
- Triage - Uncategorized - 1 analyzers
- UnshortenLink - Uncategorized - 1 analyzers
- urlDNA.io - Uncategorized - 2 analyzers
- URLhaus - Threat Intelligence - 1 analyzers
- URLScan.io - URL Analysis - 2 analyzers
- Valhalla - Uncategorized - 1 analyzers
- ValidateObservable - Uncategorized - 1 analyzers
- Velociraptor - DFIR - 1 responders
- Verifalia - Uncategorized - 1 analyzers
- Virusshare - Uncategorized - 1 analyzers
- VirusTotal - Malware Analysis - 4 analyzers
- VirustotalDownloader - Uncategorized - 1 responders
- VMRay - Uncategorized - 1 analyzers
- Vulners - Uncategorized - 2 analyzers
- Watcher - Uncategorized - 1 analyzers, 2 responders
- Wazuh - Uncategorized - 1 responders
- WOT - Uncategorized - 1 analyzers
- YARA - Malware Analysis - 1 analyzers
- Yeti - Uncategorized - 1 analyzers
- ZEROFOX - Uncategorized - 2 responders
- Zscaler - Uncategorized - 2 analyzers
This catalog is auto-generated. Do not edit manually.