Integrating TheHive and Cortex with MISP
TheHive and Cortex are powerful when they work together. TheHive is helpful in incident response, case management, collaboration, and threat analysis while Cortex is a powerful threat intel aggregator. Once we Integrate TheHive and Cortex with MISP, we can even run the observable analyzer directly from TheHive as a result; we don’t have to manually perform analysis by going to Cortex. In order to achieve this automation, we need to do three things:
- Integrate TheHive with Cortex
- Integrate Cortex with MISP
- Integrate TheHive with MISP
Integrate TheHive with Cortex
To integrate TheHive and Cortex, you need to enter the Cortex API key in the TheHive settings. I hope you’ve copied the Cortex API key, as explained in the earlier section Setting up TheHive and Cortex | Create an organization and user on Cortex. Now, in order to complete the integration, log in with the admin account or switch to the admin profile...