The Hive Zero Trust Alert to Case Integration
Support Statement
This documentation is provided "as is" without support for 3rd party software. The level of support for this integration guide is best effort without any SLA on response time. No 3rd party product support can be provided by Superna directly. 3rd party components require support contracts. See EULA for more details.
Overview
TheHive is a powerful and versatile tool for security incident response with strong automation capabilities. It has a user-friendly and intuitive interface that makes it easy to create, manage, and analyze security incidents.
Solution Overview
Superna Defender Zero Trust API receives webhook alerts and parses the key data into HTTPS API payload events that are sent to TheHive endpoint URL. TheHive is a modular architecture that provides real-time visibility of your IT infrastructure, which you can use for threat detection and prioritization.
Advanced Zero Trust Capabilities
- Webhook to native HTTPS collector API case creation
- Webhook updates to the same incident search for a pre-existing case and add a comment with the payload from the update
What Is TheHive?
TheHive offers a comprehensive 4-in-1 Security Incident Response Platform, serving as a vital tool for Security Operations Centers (SOCs), Computer Security Incident Response Teams (CSIRTs), Computer Emergency Response Teams (CERTs), and all information security professionals involved in swift and effective handling of security incidents. With its seamless integration with MISP and advanced capabilities for task management, evidence handling, and threat intelligence integration, TheHive is an indispensable tool for modern SOC, CSIRT, and CERT teams.
Integration Architecture
