Thanks to Cortex, observables such as IP and email addresses, URLs, domain names, files or hashes can be analyzed using a Web interface. Analysts can also automate these operations and submit large sets of observables from TheHive or through the Cortex REST API from alternative SIRP platforms, custom scripts or MISP. When used in conjunction with TheHive, Cortex largely facilitates the containment phase thanks to its Active Response features. This AMI is brought to you by StrangeBee, the company founded by three co-creators of TheHive to provide its users with deep expertise and a unique know-how. By doing so, StrangeBee boosts both the development of the product, new features for TheHive & Cortex as well as the ecosystem.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
This listing is free software, so you pay no license fee for Cortex itself. The 32 dimensions are all Amazon EC2 instance types, billed by the hour. They span several families, including general-purpose (t3, t3a, m5, m5a, m6i), compute-optimized (c5, c5a), and memory-optimized (r5, r5a) instances. Within each family, sizes range from large up to 12xlarge. Larger sizes give more CPU and memory. You choose the instance that fits your workload, then pay standard AWS hourly infrastructure charges for the EC2 capacity you run. No commitment or upfront fee applies.
Top-of-mind questions for buyers
The software is listed as free, so what am I actually paying for on each hourly dimension?
The Cortex software carries no license fee. Each hourly dimension reflects the standard AWS charge for running that EC2 instance type. You pay only for the compute capacity you run, billed per hour. When you stop the instance, hourly compute charges stop, though AWS storage fees may still apply.
How do I pick between the instance families like t3, m5, c5, and r5?
General-purpose families (t3, t3a, m5, m5a, m6i) balance CPU and memory for mixed work. Compute-optimized families (c5, c5a) favor CPU-heavy analysis. Memory-optimized families (r5, r5a) suit workloads needing more RAM. Cortex runs many analyzers at once, so choose the family and size that match your observable volume.
If I switch to a larger instance size to run more analyzers, how does my cost change?
Each size is its own hourly dimension. Moving from a large to an xlarge or higher means you launch that instance type instead, and its hourly rate applies. The change is manual — you select the new instance. Larger sizes give more CPU and memory but cost more per hour.
strangebee.com
Helpful?
Vendor refund policy
This is a free AMI, we offer no refund on any indirect costs such as AWS compute resources.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
An AMI is a virtual image that provides the information required to launch an instance. Amazon EC2 (Elastic Compute Cloud) instances are virtual servers on which you can run your applications and workloads, offering varying combinations of CPU, memory, storage, and networking resources. You can launch as many instances from as many different AMIs as you need.
Version release notes
*** AMI NOW BASED ON UBUNTU 24.04.2 LTS ***
This update includes Cortex v3.1.8 with ElasticSearch v7.17.28 on Ubuntu 24.04.2 LTS along with OS updates.
SECURITY INFORMATION
All sensitive information saved by customers is stored on the two (2) dedicated EBS data volumes attached to your instance: one volume for the Elasticsearch database, one volume for the Docker images. All data is thus located in the same region as your instance.
When using the recommended configuration, all EBS volumes (system and data) should be encrypted using your default regional KMS encryption key.
HEALTH CHECKS
To assess and monitor the health and proper function of the application:
navigate to your Amazon EC2 console and verify that you're in the correct region
choose Instance and select your launched instance
select the Status checks tab to review if your status checks passed or failed
Cortex listens on port 9001. You can configure your health checks to verify the following URL: http://server_ip:9001/api/status
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
Unlock the full potential of Cortex XSOAR with our Professional Services offer on AWS Marketplace. Our expert team provides comprehensive services, including implementation, customization, and ongoing support, empowering your organization to streamline and enhance your security operations.
Design, configuration and deployment of a Cortex XSOAR environment for AWS, including initial console configuration, optimization and knowledge transfer.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.