Overview
Features
Comprehensive MCP toolset
Provides a wide range of MCP operations for cases, alerts, observables, tasks, attachments, and related actions, enabling rich MCP-based automation and orchestration with TheHive.
Case management operations
Supports creating, updating, deleting, merging cases, promoting alerts to cases, and retrieving or listing cases through MCP tools.
Observables, alerts, and task handling
Enables creating and managing observables in alerts or cases, retrieving observables, and managing task lifecycles linked to cases and alerts.
Attachment handling
Manages case attachments with add, delete, find, and download operations to support evidence and artifact management.
Cortex integration support
Includes Cortex-related tooling such as analyzers and responder actions, and supports running observable analyzers and managing analyzer jobs.
Search, count, and retrieval capabilities
Offers find/get/list and count operations for alerts, cases, observables, tasks, and related entities to support comprehensive querying and reporting.
Dependency and deployment convenience
Relies on the TheHive client library (thehive4py) and provides multiple deployment options (Claude Desktop, uv) with environment variables HIVE_URL and HIVE_API_KEY; includes a manual install path.
Who Is This For?
- SOC analysts:Use MCP clients to manage cases, alerts, observables, and tasks within TheHive.




