Best Software for 2025 is now live!
Show rating breakdown
Save to My Lists
Claimed
Claimed

Top Rated TheHive Alternatives

TheHive Reviews & Product Details

TheHive Overview

What is TheHive?

A scalable, Security Incident Response Platform, tightly integrated with MISP (Malware Information Sharing Platform), designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security incidents that need to be investigated and acted upon swiftly.

TheHive Details
Languages Supported
English
Show LessShow More
Product Description

TheHive is a scalable, open source and free security incident response solution.


Seller Details
Seller
TheHive
Year Founded
2019
HQ Location
Paris, France
Twitter
@TheHive_Project
9,842 Twitter followers
LinkedIn® Page
www.linkedin.com
1 employees on LinkedIn®

Nabil A.
NA
Overview Provided by:
CEO at StrangeBee, Building TheHive

Recent TheHive Reviews

Verified User
I
Verified UserMid-Market (51-1000 emp.)
4.0 out of 5
"The Efficiency of Incident Response, with The Hive. An Extensive Evaluation"
TheHive is a great, open-source platform with good integrations using such tools as MISP and Cortex, characterizing a platform exemplary for collec...
Sam F.
SF
Sam F.Enterprise (> 1000 emp.)
5.0 out of 5
"Incident Response Platform: TheHive"
The platform plays a critical role in our incident response. It integrates with and automates many of our processes for our analysts, helping to de...
Rohan G.
RG
Rohan G.Mid-Market (51-1000 emp.)
5.0 out of 5
"Opensource Case Management: TheHive"
TheHive is an open source which helps us to create & merge cases in which you are working. You can integrate TheHive with Cortex & Wazuh, which ...
Security Badge
This seller hasn't added their security information yet. Let them know that you'd like them to add it.
1 person requested security information

TheHive Media

TheHive Demo - Case list
A view that displays a filterable cases list
TheHive Demo - Tasks list
A view showing the list of tasks of a given case
TheHive Demo - Alert list
A view showing the list of alerts received by TheHive from MISP or other third party platform
TheHive Demo - Custom dashboards
A user defined dashboard
Answer a few questions to help the TheHive community
Have you used TheHive before?
Yes

19 TheHive Reviews

4.2 out of 5
The next elements are filters and will change the displayed results once they are selected.
Search reviews
Popular Mentions
The next elements are radio elements and sort the displayed results by the item selected and will update the results displayed.
Hide FiltersMore Filters
The next elements are filters and will change the displayed results once they are selected.
The next elements are filters and will change the displayed results once they are selected.
19 TheHive Reviews
4.2 out of 5
19 TheHive Reviews
4.2 out of 5

TheHive Pros and Cons

How are these determined?Information
Pros and Cons are compiled from review feedback and grouped into themes to provide an easy-to-understand summary of user reviews.
Pros
Cons

Overall Review Sentiment for TheHiveQuestion

Time to Implement
<1 day
>12 months
Return on Investment
<6 months
48+ months
Ease of Setup
0 (Difficult)
10 (Easy)
Log In
Want to see more insights from verified reviewers?
Log in to view review sentiment.
G2 reviews are authentic and verified.
Verified User in Information Technology and Services
II
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about TheHive?

TheHive is a great, open-source platform with good integrations using such tools as MISP and Cortex, characterizing a platform exemplary for collective work. Besides having customizable workflows, it is easy to use and scale, rendering the tool perfectly suitable for SOCs and CSIRTs in managing the peculiarities of incidents efficiently. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

New users may be daunted by the steep learning curve and complex setup in TheHive, much like MISP; definitely, dependence on community support can delay troubleshooting. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

TheHive streamlines incident response by centralizing workflows and integrating well with other tools, like MISP and Cortex, thus saving time and enhancing efficiency for security teams. Review collected by and hosted on G2.com.

Sam F.
SF
IT Security Officer
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
What do you like best about TheHive?

The platform plays a critical role in our incident response. It integrates with and automates many of our processes for our analysts, helping to decrease our response times.

The platform is easy to set up, maintain, and use. There is also an active Discord community for sharing information and asking questions. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

None. We've fed back any problems we've had, which've all been taken onboard and resolved. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

The platform helps us automate our incident response processes and stores and correlates much of our data. Review collected by and hosted on G2.com.

Rohan G.
RG
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: G2 invite
Incentivized Review
What do you like best about TheHive?

TheHive is an open source which helps us to create & merge cases in which you are working.

You can integrate TheHive with Cortex & Wazuh, which maintains a better security posture.

For integration purposes, you need the API key of hive, which help us to integrate it with another software.

Also you can create different dashboards to visualise the cases & alerts coming from SIEM tool. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

TheHive5 is not an opensource it is a paid tool you have to paid to use it.

Also there are different opensource tool like IRIS which can be considered as competitor for TheHive. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

TheHive helps us to solve the problem of tracking down the incident and also you can assign the tasks to your teammates & track down the case.

Also if your investigation is over, you can close this case with proper justification.

You can also integrate tool with different SIEM, Threat Intel tool etc. Review collected by and hosted on G2.com.

SA
Red Team Director
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about TheHive?

Best part of TheHive is its integration with multiple threat intelligence tools like Cortex and MISP Review collected by and hosted on G2.com.

What do you dislike about TheHive?

some of the module not working properly, rest all is fine Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Best for SOC team for incident response and case management Review collected by and hosted on G2.com.

YP
Senior SOC ANALYST
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about TheHive?

Easy to use and Configure. Various Integration with various threat intel tools. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Sometimes it's the cortex module's analyzers not working properly. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Using TheHive we get all alerts from our SIEM tool to thehive and easily manage. Immense benefits. Review collected by and hosted on G2.com.

Verified User in Computer & Network Security
AC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: Organic
(Original )Information
What do you like best about TheHive?

integration with cortex (threat intelligence) and misp (threat exchange) Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Looks fine nothing missing into it.

Product looks promising Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Incident Response and Incident Handling is performed and managed very nicely. Review collected by and hosted on G2.com.

Verified User in Telecommunications
IT
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Verified Current User
Review source: Organic
(Original )Information
What do you like best about TheHive?

The Alert Management and the Openness of TheHive allows it to easily integrate from small to Enterprise large installations. We are able to use it in a very big Environment with extremly complex use-cases and Operation processes and it works really great.

It is becoming a new de-facto-Standard for SOAR Tools on enterprise Level.

Especially the native Integration of MISP Interface is really helpfull. Addintional the New TheHiveFile-System, Multi-Tenancy, Case-, Alert- and Observable sharing are outstanding features, that makes this product to choince number 1. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

TheHive is grewing constantly and as there are always new Features you have to ensure that you can install the new updates in time to be able to constatnly increasing productivitiy.

Sometimes it takes a little time to get reaction from the support team, especially regarding new feature requests. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Multi-Tier OC Operations Review collected by and hosted on G2.com.

Julien M.
JM
Cyber Security Analyst - CERT Gemalto
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: Organic
What do you like best about TheHive?

Maintained Dockers, scalability, efficiency in CTI checks, easy to use, design, and connectivity to other tools thanks to the strong contributions from the community. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Tags or comments mandatory for observables, IOCs' tags (I don't mean events' tags) are pushed to MISP on exports and no cases rotation (e.g : delete closed cases after 2 months).

Finally, analyzers and responders must be reviewed to be less confusing between investigation and response. Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Fastup assessments, CTI investigations, sharing. Review collected by and hosted on G2.com.

Verified User in Civil Engineering
AC
Mid-Market(51-1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about TheHive?

I was looking for a SOAR system, TheHive is not a SOAR but can help analysts and SOC specialists on incident response activities Review collected by and hosted on G2.com.

What do you dislike about TheHive?

Installation is too complicated for a beginner Review collected by and hosted on G2.com.

Recommendations to others considering TheHive:

Use TheHive if you are skilled with Linux OS and server CLI Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Deploy a new SOAR system Review collected by and hosted on G2.com.

Verified User in Information Services
AI
Enterprise(> 1000 emp.)
More Options
Validated Reviewer
Review source: G2 invite
Incentivized Review
What do you like best about TheHive?

Its easy to use once you get the hang of it.ince can be. Reated quickly and assignment groups are easy to use and configure. Review collected by and hosted on G2.com.

What do you dislike about TheHive?

It take a little time to learn it,it is missing many options that competitors offer Review collected by and hosted on G2.com.

Recommendations to others considering TheHive:

Hand held and mac,windows Review collected by and hosted on G2.com.

What problems is TheHive solving and how is that benefiting you?

Incident response and incident logging,tracking and trend analysis Review collected by and hosted on G2.com.