TheHive Platform logo

    TheHive Platform

    Sold by
    A security case management platform trusted by 3500+ users in 50+ countries to centralize and speed up alert handling, collaboration, investigations and incident response.

    Ratings and reviews

    4.3
    18 ratings
    2 star
    1 star
    50%
    44%
    6%
    0%
    0%
    0 AWS reviews
    |
    18 external reviews
    External reviews are from G2 .

    Filters

    Review type

    AWS Marketplace reviews
    External reviews
    Reviews (18)
    Sam F.

    Incident Response Platform: TheHive

    Reviewed on May 29, 2024
    Review provided by G2
    What do you like best about the product?
    The platform plays a critical role in our incident response. It integrates with and automates many of our processes for our analysts, helping to decrease our response times.

    The platform is easy to set up, maintain, and use. There is also an active Discord community for sharing information and asking questions.
    What do you dislike about the product?
    None. We've fed back any problems we've had, which've all been taken onboard and resolved.
    What problems is the product solving and how is that benefiting you?
    The platform helps us automate our incident response processes and stores and correlates much of our data.
    Rohan G.

    Opensource Case Management: TheHive

    Reviewed on Jun 23, 2023
    Review provided by G2
    What do you like best about the product?
    TheHive is an open source which helps us to create & merge cases in which you are working.

    You can integrate TheHive with Cortex & Wazuh, which maintains a better security posture.

    For integration purposes, you need the API key of hive, which help us to integrate it with another software.

    Also you can create different dashboards to visualise the cases & alerts coming from SIEM tool.
    What do you dislike about the product?
    TheHive5 is not an opensource it is a paid tool you have to paid to use it.

    Also there are different opensource tool like IRIS which can be considered as competitor for TheHive.
    What problems is the product solving and how is that benefiting you?
    TheHive helps us to solve the problem of tracking down the incident and also you can assign the tasks to your teammates & track down the case.

    Also if your investigation is over, you can close this case with proper justification.

    You can also integrate tool with different SIEM, Threat Intel tool etc.
    Satykam A.

    Best Open Source Case management

    Reviewed on Jun 03, 2022
    Review provided by G2
    What do you like best about the product?
    Best part of TheHive is its integration with multiple threat intelligence tools like Cortex and MISP
    What do you dislike about the product?
    some of the module not working properly, rest all is fine
    What problems is the product solving and how is that benefiting you?
    Best for SOC team for incident response and case management
    Yash P.

    Thehive Overview

    Reviewed on Dec 08, 2021
    Review provided by G2
    What do you like best about the product?
    Easy to use and Configure. Various Integration with various threat intel tools.
    What do you dislike about the product?
    Sometimes it's the cortex module's analyzers not working properly.
    What problems is the product solving and how is that benefiting you?
    Using TheHive we get all alerts from our SIEM tool to thehive and easily manage. Immense benefits.
    Computer & Network Security

    Case Management

    Reviewed on Dec 08, 2021
    Review provided by G2
    What do you like best about the product?
    integration with cortex (threat intelligence) and misp (threat exchange)
    What do you dislike about the product?
    Looks fine nothing missing into it.
    Product looks promising
    What problems is the product solving and how is that benefiting you?
    Incident Response and Incident Handling is performed and managed very nicely.
    Civil Engineering

    Soar not a soar

    Reviewed on Oct 22, 2019
    Review provided by G2
    What do you like best about the product?
    I was looking for a SOAR system, TheHive is not a SOAR but can help analysts and SOC specialists on incident response activities
    What do you dislike about the product?
    Installation is too complicated for a beginner
    What problems is the product solving and how is that benefiting you?
    Deploy a new SOAR system
    Recommendations to others considering the product:
    Use TheHive if you are skilled with Linux OS and server CLI
    Telecommunications

    Excelent tool on Enterprise Level

    Reviewed on Oct 14, 2019
    Review provided by G2
    What do you like best about the product?
    The Alert Management and the Openness of TheHive allows it to easily integrate from small to Enterprise large installations. We are able to use it in a very big Environment with extremly complex use-cases and Operation processes and it works really great.
    It is becoming a new de-facto-Standard for SOAR Tools on enterprise Level.
    Especially the native Integration of MISP Interface is really helpfull. Addintional the New TheHiveFile-System, Multi-Tenancy, Case-, Alert- and Observable sharing are outstanding features, that makes this product to choince number 1.
    What do you dislike about the product?
    TheHive is grewing constantly and as there are always new Features you have to ensure that you can install the new updates in time to be able to constatnly increasing productivitiy.
    Sometimes it takes a little time to get reaction from the support team, especially regarding new feature requests.
    What problems is the product solving and how is that benefiting you?
    Multi-Tier OC Operations
    Julien M.

    Thank you for your feedback! If you have any specific text in an unknown language that you need translated, please provide it, and I'll be happy to assist.

    Reviewed on Sep 12, 2019
    Review provided by G2
    What do you like best about the product?
    Maintained Dockers, scalability, efficiency in CTI checks, easy to use, design, and connectivity to other tools thanks to the strong contributions from the community.
    What do you dislike about the product?
    Tags or comments are mandatory for observables. Tags for Indicators of Compromise (IOCs) (not event tags) are pushed to MISP during exports, and there should be no rotation of cases (e.g., do not delete closed cases after 2 months). Finally, analyzers and responders must be reviewed to reduce confusion between investigation and response.
    What problems is the product solving and how is that benefiting you?
    Fastup assessments, CTI investigations, sharing.
    Information Services

    Hive review

    Reviewed on May 10, 2019
    Review provided by G2
    What do you like best about the product?
    Its easy to use once you get the hang of it.ince can be. Reated quickly and assignment groups are easy to use and configure.
    What do you dislike about the product?
    It take a little time to learn it,it is missing many options that competitors offer
    What problems is the product solving and how is that benefiting you?
    Incident response and incident logging,tracking and trend analysis
    Recommendations to others considering the product:
    Hand held and mac,windows
    Eric T.

    Works great.

    Reviewed on Jan 03, 2018
    Review provided by G2
    What do you like best about the product?
    We like the fact the since implementation our downtime is very low.
    What do you dislike about the product?
    We don’t have anything at this time that we have wanted to address with anyone.
    What problems is the product solving and how is that benefiting you?
    What problems are we not solving? It’s helped us shape the IT side our what we do for companies.