TheHive is StrangeBee's incident response platform for SOC and CERT teams. See its case management features, Cortex integration and pricing tiers.
TheHive is a Security Incident Response Platform that gives security teams a shared workspace for managing cases, tasks and observables during an investigation. It began in 2016 as a free, open-source project from three former CERT-BDF analysts, and by 2018 those creators had formalized the project into a company, StrangeBee, based in Paris.
The platform is built for security operations centers, CERTs, CSIRTs and MSSPs that need to move from a raised alert to a documented, collaborative investigation quickly, with tight integration into the broader threat-intelligence ecosystem via MISP and the observable-analysis engine Cortex, both also maintained by StrangeBee.
TheHive's core is case and task management: alerts from SIEMs, email reports and other sources can be imported and triaged, then escalated into full cases broken into tasks, with reusable case templates for common incident types. Multiple analysts can work the same case at once, with a full history of changes for accountability and reporting.
Observable enrichment happens through Cortex, which runs analyzers against IPs, file hashes, domains and other indicators using external threat-intel sources and sandboxes, and through responders that can take active containment or notification actions. MISP integration lets teams pull in indicators of compromise from shared MISP events or export their own findings back out, and a library of more than 300 community-built integrations extends the platform further.
TheHive offers a free Community edition for self-hosted, on-premises deployments, covering core case management, alert triage and Cortex/MISP integration for teams that do not need advanced multi-tenancy or premium support.
Above that, TheHive Gold and Platinum are commercial annual subscriptions priced by the number of users and organizations (tenants) supported, available for on-prem or cloud deployment, and StrangeBee also sells a fully managed TheHive Cloud Platform and an MSSP license for partners. None of the paid tiers publish flat prices; StrangeBee quotes them directly based on team size and deployment needs.
It is a Security Incident Response Platform used by SOC, CERT and CSIRT teams to manage and investigate security cases.
The Community edition is free for self-hosted, on-premises use; Gold and Platinum are paid commercial subscriptions.
TheHive is the case-management platform; Cortex is the companion engine that runs analyzers and active responses against observables.
TheHive is maintained by StrangeBee, a Paris-based cybersecurity company founded in 2018 by TheHive's original creators.
Community is free and on-prem only with core features; Gold and Platinum are paid subscriptions priced by users and organizations, adding advanced automation and support.
Yes, TheHive has native integration with MISP for importing and exporting threat indicators.
Yes, both the free Community edition and the paid editions support on-premises self-hosted deployment.
Public availability of the legacy TheHive 3 and 4 open-source builds ended in 2025 as StrangeBee moved focus to TheHive 5.