TheHive-Project / TheHive-Project/Cortex
Question: Internal Hive/Cortex Automations or Workflows
Nobody has claimed this yet.
- Dominant language
- Scala
- Stars
- 1.6k
- Forks
- 264
- PR merge metrics
- No merged PRs in 30d
Description
Request Type
Question
Work Environment
docker-compse running on Centos 7 (just testing this platform as a POC.)
Problem Description
Are there any internal workflows/automations within Hive/Cortex for running things automatically?
Use Case 1:
Say we generate an alert from a phishing email. And we strip out the observables, and populate them in the alert. Is there a way to auto run analyzers against those observables, and then create a case automatically if the analyzers come back with a certain threat level or something?
Use Case 2:
Case is created and observables are populated, can we auto run analyzers on this observables?
Use Case 3:
Phishing case created, observables analyzed, observables are malicious. Is there a way to automate off of those results? Like kick off an email search to delete malicious emails?
Thanks so much in advance! -Jim
Steps to Reproduce
NA
Complementary information
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No file, test, or entry point is identified in the issue. First review the documented Cortex and Hive automation capabilities, then clarify which workflow is intended and what existing behavior should be changed or added.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- centos, docker-compose
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 15/100