← Back to connectors

TheHive connector for Okou

Connect a public HTTPS TheHive 5 instance to investigate alerts and cases, manage observables and tasks, produce reports, administer knowledge and access, and use configured Cortex or MISP integrations.

Data & infrastructure · API Key

Use TheHive in Okou

Use TheHive 5 to investigate security alerts and cases, search investigation data, manage observables and tasks, create reports, administer supported configuration, or invoke configured Cortex and MISP integrations.

Once connected, supported TheHive actions can become steps in a reusable workflow alongside the other services your team uses. Run the workflow once, on a schedule, or when an event starts it.

What you can do with TheHive

  • Create or update custom alert statuses.
  • Create or update MITRE ATT&CK catalogs and patterns.
  • Create or update case and alert comments.
  • Create or update platform branding and branding assets.
  • Read the local password-policy metadata without starting or changing an authentication session.
  • Export query results as a potentially large downloadable file through the unstable export route.
  • Create an audit stream cursor.
  • Create or update alerts, related case links, and alert attachments.

How the TheHive connector works

A connected service becomes one permissioned step in the work you hand off.

  1. 1

    Connect TheHive

    Choose API Key.

  2. 2

    Choose the work

    Use only the supported actions your workflow needs.

  3. 3

    Run it your way

    Start it once, schedule it, or attach an event trigger.

Connect TheHive securely

Use the connection method that fits your account and grant only the access the workflow needs.

  • API Key

Connector access is controlled per service and per action, so a workflow does not need broader access than the work you ask it to do.

TheHive connector questions

What can Okou do with TheHive?
Connect a public HTTPS TheHive 5 instance to investigate alerts and cases, manage observables and tasks, produce reports, administer knowledge and access, and use configured Cortex or MISP integrations. Documented actions include: Create or update custom alert statuses. Create or update MITRE ATT&CK catalogs and patterns.
How do I connect TheHive to Okou?
Connect TheHive using API Key. The connection controls which supported actions a workflow can use.
Can TheHive run in an automated workflow?
Yes. After it is connected, supported TheHive actions can run in reusable Okou workflows on demand, on a schedule, or from an event trigger.

More data & infrastructure connectors

Explore other connectors in the same product category.