Skip to content
SecArsenal
Educational and ethical use only. Only test systems you own or are explicitly authorized to test. Full disclaimer.

TheHive

Incident-response case management platform with an official demo VM

specializedbased on DebianBlue Team

TheHive has no official, structured tool listing we can auto-sync (unlike Kali, BlackArch, REMnux, and Tails). The tools below are maintained by hand and may be incomplete or outdated — check the official docs for the current tool set.

Official docs ↗Source repo ↗

Last verified September 5, 2026

TheHive is a scalable case-management platform for security incident response — organizing alerts, cases, tasks, and observables for an IR team, paired with Cortex for running enrichment/analysis jobs against those observables. It’s a defensive/blue-team platform, included here for its official downloadable demo VM rather than any offensive tooling.

Use it only in environments you own or are explicitly authorized to operate in — see the disclaimer.

Getting started

TheHive's maintainer, StrangeBee, publishes a ready-to-import OVA (currently Debian-based) bundling TheHive, Cortex, and Elasticsearch for a quick demo — explicitly for evaluation, not production, per its own documentation. It boots straight to a working instance with no setup. For real deployments, the official docs instead cover Docker-based and package-based installs of TheHive and its Cortex analyzer engine separately.