About this integration
Run TheHive Cortex analyzers and responders, and track their jobs. Connect it to any workflow without writing code.
You can choose from 0 triggers, 6 search modules and 7 actions. The connection type is basic authentication.
How to connect
The credential form asks for API Key and Hosting.
Prefer the interactive builder form? Open it on the app page.
Enter your credentials below. WEXTL stores them encrypted and uses them only to call the API on your behalf.
| Field | Type | Help |
|---|---|---|
API KeyRequired | password | — |
HostingRequired | select | — |
Use it in workflow automation
Add Delete Analyzer as a workflow step.
Triggers, searches and actions
Explore the fields available for each Cortex trigger, search, and action — 0 triggers, 6 searchs, and 7 actions.
Searches
6 search modules let you query the app mid-run and feed the results to the next step.
- Get Analyzer
- Get Job
- Get Job Report
- List Analyzers
- List Jobs
Actions
Use 7 action modules to write data back into the app from anywhere in a run.
- Delete Analyzer
- Delete Job
- Make an API Call
- Run Analyzer
- Run Responder
Explore the fields available for each Cortex trigger, search, and action.
Searches
| Field | Type |
|---|---|
Analyzer IDRequired | choice |
| Field | Type |
|---|---|
ID | text |
Name | text |
| Field | Type |
|---|---|
Job IDRequired | choice |
| Field | Type |
|---|---|
ID | text |
Status | text |
| Field | Type |
|---|---|
Job IDRequired | choice |
| Field | Type |
|---|---|
Full | text |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
ID | text |
Name | text |
| Field | Type |
|---|---|
Data type filter | text |
Data filter | text |
Analyzer filter | text |
Limit | number |
| Field | Type |
|---|---|
ID | text |
Status | text |
| Field | Type |
|---|---|
Limit | number |
| Field | Type |
|---|---|
ID | text |
Name | text |
Actions
| Field | Type |
|---|---|
Analyzer IDRequired | choice |
| Field | Type |
|---|---|
ID | text |
| Field | Type |
|---|---|
Job IDRequired | choice |
| Field | Type |
|---|---|
ID | text |
| Field | Type |
|---|---|
URLRequired | text |
MethodRequired | choice |
Headers | array |
Header | object |
Query String | array |
Parameter | object |
Body | text |
| Field | Type |
|---|---|
Body | text |
Headers | text |
Status code | number |
| Field | Type |
|---|---|
Analyzer IDRequired | choice |
Observable dataRequired | text |
Data typeRequired | choice |
TLP | choice |
Message | text |
Analyzer parameters | text |
| Field | Type |
|---|---|
Job ID | text |
Status | text |
| Field | Type |
|---|---|
Responder IDRequired | choice |
Object typeRequired | choice |
Object IDRequired | text |
Responder parameters | text |
| Field | Type |
|---|---|
Job ID | text |
| Field | Type |
|---|---|
Analyzer IDRequired | choice |
FileRequired | text |
Data typeRequired | choice |
TLP | choice |
Message | text |
| Field | Type |
|---|---|
Job ID | text |
| Field | Type |
|---|---|
Analyzer IDRequired | choice |
Configuration | text |
Rate limit | number |
Rate unit | text |
| Field | Type |
|---|---|
ID | text |