Overview

Product video
Cybersecurity teams today are under constant pressure: threats evolve, alerts keep coming, investigations pile up, and coordination between analysts isn't always clear. TheHive is built to change that.
TheHive is a dedicated collaborative security case management platform designed for SOCs, CSIRTs, CERTs and MSSPs. It is a single pane of glass that helps analysts reduce alert fatigue, spend less time switching between tools and resolve incidents faster together, in a structured way and with full traceability.
-
Centralize alerts from multiple sources into a single view for faster triage and consistent management
-
Manage cases end-to-end: create and assign tasks, collect evidence and track incident timelines
-
Support multiple organizations with multi-tenancy and precise access control via customizable roles and LDAP/AD synchronization
-
Keep teams informed automatically via webhooks, email, Slack, Mattermost or custom HTTP requests
-
Track performance with dynamic dashboards and actionable KPIs; create detailed incident reports using customizable templates
-
Connect with over 300 security tools: SIEMs, EDRs, threat intelligence platforms, ticketing systems and more
-
Share threat intelligence natively with MISP and map techniques to MITRE ATT&CK for more context
-
Automate analysis and response actions through tight integration with the native Cortex engine
-
Deploy the way you need: on-premises, SaaS on AWS or IaaS images on AWS and Azure
-
Available in multiple languages to support distributed, global teams
Whether you're running a lean in-house SOC or managing security operations across multiple clients, TheHive adapts to your scale. Its flexible architecture, broad integration ecosystem and straightforward interface mean teams get up to speed quickly and stay effective under pressure. Audit-ready case records support compliance requirements out of the box, and when you need help, a strong user community and responsive support team have you covered.
Highlights
- Centralized alert management and end-to-end case handling cut through the noise, helping SOC, CSIRT, CERT and MSSP teams respond to incidents faster
- Over 300 integrations with SIEMs, EDRs, threat intelligence platforms and ticketing systems fit into the workflows your team already relies on
- Flexible deployment (on-premises, SaaS or IaaS) gives you the freedom to choose what fits your organization's operational needs and growth trajectory
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
Standard plan | Standard license, with standard use included | $1,000.00 |
Vendor refund policy
Please contact us at support@strangebee.com .
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Resources
Vendor resources
Support
Vendor support
For general inquiries, troubleshooting or product guidance for TheHive, contact us at support@strangebee.com or visit our dedicated page .
Support is available between 9 AM and 6 PM Central European Time (CET), Monday through Friday, with multiple support tiers to meet the needs of different organizations.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.