TheHive MCP connector
Updated
TheHive is an open-source security incident response platform for managing alerts, cases, and observables across a security operations team. The TheHive MCP connector allows AI agents to create, update, and triage alerts, and promote them into full investigation cases. It also supports managing case details end-to-end, giving security teams a consistent way to track incidents from initial detection through resolution.
Authentication type
- API Key - Requires a static API key to be configured before the agent can connect to the service.
Uses
Use the TheHive MCP connector to perform the following actions:
- Track security alerts and escalate them into full investigation cases
- Coordinate incident response tasks across security teams in real time
- Document forensic observables and indicators of compromise for each case
- Log investigation notes and comments directly on active security cases
- Automate alert triage by promoting verified alerts into structured cases
- Monitor open cases, tasks, and logs from a single workflow
- Search historical incident data using custom queries for reporting
- Assign and update tasks to keep investigations moving forward
Example prompts
Use the following example prompts to invoke TheHive MCP connector tools from your AI assistant or Boomi Connect workflow:
Show me all open alerts in TheHive from the last 24 hours.Create a new case in TheHive for the phishing incident reported today.Promote the suspicious login alert to a case in TheHive.List all tasks assigned to the security team in TheHive.Add a comment to case number 42 in TheHive.What observables are linked to the malware case in TheHive?Update the status of alert ID 1023 in TheHive.Delete the duplicate case from TheHive.Show me all case logs added this week in TheHive.Find all high severity cases still open in TheHive.
TheHive MCP connector tools
The TheHive MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.
| Tool | Description |
|---|---|
| listAlerts | List alerts |
| createAlert | Create an alert |
| getAlert | Get an alert |
| updateAlert | Update an alert |
| deleteAlert | Delete an alert |
| promoteAlertToCase | Promote alert to case |
| listCases | List cases |
| createCase | Create a case |
| getCase | Get a case |
| updateCase | Update a case |
| deleteCase | Delete a case |
| listCaseComments | List case comments |
| createCaseComment | Create a case comment |
| updateComment | Update a comment |
| deleteComment | Delete a comment |
| listCaseObservables | List case observables |
| createCaseObservable | Create a case observable |
| getObservable | Get an observable |
| updateObservable | Update an observable |
| deleteObservable | Delete an observable |
| listCaseTasks | List case tasks |
| createCaseTask | Create a case task |
| getTask | Get a task |
| updateTask | Update a task |
| deleteTask | Delete a task |
| listTaskLogs | List task logs |
| createTaskLog | Create a task log |
| updateTaskLog | Update a task log |
| deleteTaskLog | Delete a task log |
| executeQuery | Execute a query |
| listCasePages | List case pages |
| createCasePage | Create a case page |
| getPage | Get a page |
| updatePage | Update a page |
| deletePage | Delete a page |