Skip to main content
Feedback

TheHive MCP connector

Updated 

TheHive is an open-source security incident response platform for managing alerts, cases, and observables across a security operations team. The TheHive MCP connector allows AI agents to create, update, and triage alerts, and promote them into full investigation cases. It also supports managing case details end-to-end, giving security teams a consistent way to track incidents from initial detection through resolution.

Authentication type

  • API Key - Requires a static API key to be configured before the agent can connect to the service.

Uses

Use the TheHive MCP connector to perform the following actions:

  • Track security alerts and escalate them into full investigation cases
  • Coordinate incident response tasks across security teams in real time
  • Document forensic observables and indicators of compromise for each case
  • Log investigation notes and comments directly on active security cases
  • Automate alert triage by promoting verified alerts into structured cases
  • Monitor open cases, tasks, and logs from a single workflow
  • Search historical incident data using custom queries for reporting
  • Assign and update tasks to keep investigations moving forward

Example prompts

Use the following example prompts to invoke TheHive MCP connector tools from your AI assistant or Boomi Connect workflow:

  • Show me all open alerts in TheHive from the last 24 hours.
  • Create a new case in TheHive for the phishing incident reported today.
  • Promote the suspicious login alert to a case in TheHive.
  • List all tasks assigned to the security team in TheHive.
  • Add a comment to case number 42 in TheHive.
  • What observables are linked to the malware case in TheHive?
  • Update the status of alert ID 1023 in TheHive.
  • Delete the duplicate case from TheHive.
  • Show me all case logs added this week in TheHive.
  • Find all high severity cases still open in TheHive.

TheHive MCP connector tools

The TheHive MCP connector provides the following tools. Each tool maps to a specific action you can invoke from your AI agent or automation.

ToolDescription
listAlertsList alerts
createAlertCreate an alert
getAlertGet an alert
updateAlertUpdate an alert
deleteAlertDelete an alert
promoteAlertToCasePromote alert to case
listCasesList cases
createCaseCreate a case
getCaseGet a case
updateCaseUpdate a case
deleteCaseDelete a case
listCaseCommentsList case comments
createCaseCommentCreate a case comment
updateCommentUpdate a comment
deleteCommentDelete a comment
listCaseObservablesList case observables
createCaseObservableCreate a case observable
getObservableGet an observable
updateObservableUpdate an observable
deleteObservableDelete an observable
listCaseTasksList case tasks
createCaseTaskCreate a case task
getTaskGet a task
updateTaskUpdate a task
deleteTaskDelete a task
listTaskLogsList task logs
createTaskLogCreate a task log
updateTaskLogUpdate a task log
deleteTaskLogDelete a task log
executeQueryExecute a query
listCasePagesList case pages
createCasePageCreate a case page
getPageGet a page
updatePageUpdate a page
deletePageDelete a page
On this Page