Introducing G2.ai, the future of software buying.Try now
Hostman
Sponsored
Hostman
Visit Website
Product Avatar Image
TheHive

By TheHive

4.2 out of 5 stars

How would you rate your experience with TheHive?

Hostman
Sponsored
Hostman
Visit Website
It's been two months since this profile received a new review
Leave a Review

TheHive Reviews & Product Details

Profile Status

This profile is currently managed by TheHive but has limited features.

Are you part of the TheHive team? Upgrade your plan to enhance your branding and engage with visitors to your profile!

Value at a Glance

Averages based on real user reviews.

Perceived Cost

$$$$$

TheHive Media

TheHive Demo - Case list
A view that displays a filterable cases list
TheHive Demo - Tasks list
A view showing the list of tasks of a given case
TheHive Demo - Alert list
A view showing the list of alerts received by TheHive from MISP or other third party platform
TheHive Demo - Custom dashboards
A user defined dashboard
Product Avatar Image

Have you used TheHive before?

Answer a few questions to help the TheHive community

TheHive Reviews (19)

Reviews

TheHive Reviews (19)

4.2
19 reviews

Pros & Cons

Generated from real user reviews
View All Pros and Cons
Search reviews
Filter Reviews
Clear Results
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
II
Mid-Market (51-1000 emp.)
"The Efficiency of Incident Response, with The Hive. An Extensive Evaluation"
What do you like best about TheHive?

TheHive is a great, open-source platform with good integrations using such tools as MISP and Cortex, characterizing a platform exemplary for collective work. Besides having customizable workflows, it is easy to use and scale, rendering the tool perfectly suitable for SOCs and CSIRTs in managing the peculiarities of incidents efficiently. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

New users may be daunted by the steep learning curve and complex setup in TheHive, much like MISP; definitely, dependence on community support can delay troubleshooting. Review collected by and hosted on G2.com.

Sam F.
SF
IT Security Officer
Enterprise (> 1000 emp.)
"Incident Response Platform: TheHive"
What do you like best about TheHive?

The platform plays a critical role in our incident response. It integrates with and automates many of our processes for our analysts, helping to decrease our response times.

The platform is easy to set up, maintain, and use. There is also an active Discord community for sharing information and asking questions. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

None. We've fed back any problems we've had, which've all been taken onboard and resolved. Review collected by and hosted on G2.com.

Rohan G.
RG
Mid-Market (51-1000 emp.)
"Opensource Case Management: TheHive"
What do you like best about TheHive?

TheHive is an open source which helps us to create & merge cases in which you are working.

You can integrate TheHive with Cortex & Wazuh, which maintains a better security posture.

For integration purposes, you need the API key of hive, which help us to integrate it with another software.

Also you can create different dashboards to visualise the cases & alerts coming from SIEM tool. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

TheHive5 is not an opensource it is a paid tool you have to paid to use it.

Also there are different opensource tool like IRIS which can be considered as competitor for TheHive. Review collected by and hosted on G2.com.

SA
Red Team Director
Mid-Market (51-1000 emp.)
"Best Open Source Case management"
What do you like best about TheHive?

Best part of TheHive is its integration with multiple threat intelligence tools like Cortex and MISP Review collected by and hosted on G2.com.

What do you dislike about TheHive?

some of the module not working properly, rest all is fine Review collected by and hosted on G2.com.

YP
Senior SOC ANALYST
Mid-Market (51-1000 emp.)
"Thehive Overview"
What do you like best about TheHive?

Easy to use and Configure. Various Integration with various threat intel tools. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Sometimes it's the cortex module's analyzers not working properly. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market (51-1000 emp.)
"Case Management"
What do you like best about TheHive?

integration with cortex (threat intelligence) and misp (threat exchange) Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Looks fine nothing missing into it.

Product looks promising Review collected by and hosted on G2.com.

Verified User in Telecommunications
IT
Enterprise (> 1000 emp.)
"Excelent tool on Enterprise Level"
What do you like best about TheHive?

The Alert Management and the Openness of TheHive allows it to easily integrate from small to Enterprise large installations. We are able to use it in a very big Environment with extremly complex use-cases and Operation processes and it works really great.

It is becoming a new de-facto-Standard for SOAR Tools on enterprise Level.

Especially the native Integration of MISP Interface is really helpfull. Addintional the New TheHiveFile-System, Multi-Tenancy, Case-, Alert- and Observable sharing are outstanding features, that makes this product to choince number 1. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

TheHive is grewing constantly and as there are always new Features you have to ensure that you can install the new updates in time to be able to constatnly increasing productivitiy.

Sometimes it takes a little time to get reaction from the support team, especially regarding new feature requests. Review collected by and hosted on G2.com.

Julien M.
JM
Cyber Security Analyst - CERT Gemalto
Enterprise (> 1000 emp.)
"Thank you for your feedback! If you have any specific text in an unknown language that you need translated, please provide it, and I'll be happy to assist."
What do you like best about TheHive?

Maintained Dockers, scalability, efficiency in CTI checks, easy to use, design, and connectivity to other tools thanks to the strong contributions from the community. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Tags or comments are mandatory for observables. Tags for Indicators of Compromise (IOCs) (not event tags) are pushed to MISP during exports, and there should be no rotation of cases (e.g., do not delete closed cases after 2 months). Finally, analyzers and responders must be reviewed to reduce confusion between investigation and response. Review collected by and hosted on G2.com.

Verified User in Civil Engineering
AC
Mid-Market (51-1000 emp.)
"Soar not a soar"
What do you like best about TheHive?

I was looking for a SOAR system, TheHive is not a SOAR but can help analysts and SOC specialists on incident response activities Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Installation is too complicated for a beginner Review collected by and hosted on G2.com.

Verified User in Information Services
AI
Enterprise (> 1000 emp.)
"Hive review "
What do you like best about TheHive?

Its easy to use once you get the hang of it.ince can be. Reated quickly and assignment groups are easy to use and configure. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

It take a little time to learn it,it is missing many options that competitors offer Review collected by and hosted on G2.com.

Pricing

Pricing details for this product isn’t currently available. Visit the vendor’s website to learn more.

TheHive Comparisons
Product Avatar Image
Demisto
Compare Now
Product Avatar Image
Wazuh - The Open Source Security Platform
Compare Now
Product Avatar Image
LevelBlue USM Anywhere
Compare Now
TheHive Features
Resolution Automation
Resolution Guidance
System Isolation
Incident Logs
Incident Reports
Resource Usage
Incident Alerts
Database Management
Product Avatar Image
TheHive
View Alternatives