TheHive security case and alert management
TheHive is the open-source security incident response platform used by SOC teams to triage alerts, escalate to cases, and coordinate investigation. Tiny Command surfaces two triggers — Alert Created (a new alert landed in TheHive, typically from a SIEM, EDR, or other detection source) and Case Created (an analyst escalated an alert to a full case, or opened a case directly) — plus three actions: Create Alert (push a detection into TheHive from an external source — the standard sync path for tools that don't have native TheHive integrations), Create Case (open an investigation directly), List Alerts (paginated with filters). The connection uses TheHive's API key (per-user, from User Settings) plus the instance URL (self-hosted; TheHive doesn't have a managed cloud). Alert Created is the workflow trigger for SOC orchestration: when a new alert arrives, auto-enrich with threat intel from VirusTotal/AbuseIPDB, score, and either auto-resolve low-severity or escalate to a case with the right responder assigned.
No credit card required · Set up in under 2 minutes
2 real-time triggers, each backed by a webhook subscription. Events arrive within seconds and you don't have to set up polling.
Fires whenever a new alert is created in TheHive (the SOC alerting/case-management platform). Use it to enrich, route, or auto-escalate alerts to a SOAR playbook.
Fires whenever a new case is created in TheHive. Use it to broadcast new investigations to a Slack channel or kick off a Cortex analysis pipeline.
Every action accepts dynamic inputs from upstream nodes, whether that's an AI output, a form field, or a search result.
| Action | What it does | Open action |
|---|---|---|
| Create Alert | Creates a new alert in TheHive with title, description, severity, observables, and source. Common entry point for piping detections from SIEM/EDR tooling into TheHive. | |
| Create Case | Creates a new investigation case in TheHive with title, description, severity, TLP, and assigned user. Use it to promote a manual report or external ticket into a formal case. | |
| List Alerts | Lists alerts in TheHive matching the supplied filters (severity, status, source, date range). Useful for periodic alert-fatigue or aging reports. |
Clone any recipe and customize it in one click. Every recipe is fully editable.
Tiny Command counts a run the moment a trigger fires. Filtering early means only matching events spend your usage budget.
Connect TheHive once and every workflow on your account can use its triggers and actions. You don't have to re-auth per workflow.
Every TheHive field shows up in the visual picker for downstream nodes. The raw payload is there for power users, optional for everyone else.
If we missed yours, ping support. We usually reply within an hour.
Same category as TheHive, ordered by how often teams pair them. Hover the carousel to pause.
Wire it to Slack, Notion, HubSpot, Stripe, or any of the other 438 apps in our catalog. Setup takes roughly two minutes. Free to try, no credit card.