Chapter 10: Implementing an Incident Management System
An incident management system is a core component of the incident response process. Documentation and activity management allow the timely monitoring of each of the phases and facilitate decision making.
Fortunately, there are multiple incident management systems on the market, both open source and commercial, so you can make a diagnosis of the capabilities within the organization to then choose which is the best option.
TheHive is not just an incident ticketing system; this platform includes, among other things, case management capabilities, playbook integration, access to external intelligence sources through the tool known as Cortex, and support for MITRE ATT&CK, among other things.
In this chapter, you will learn how to use TheHive as an incident management system and we will cover the following topics:
- Understanding the TheHive architecture
- Setting up TheHive and creating cases
- Creating...