{"repo":"TheHive-Project/Cortex","free":true,"listed":false,"github":"https://github.com/TheHive-Project/Cortex","clone":"git clone https://github.com/TheHive-Project/Cortex.git","description":"Cortex: a Powerful Observable Analysis and Active Response Engine","language":"Scala","stars":1617,"topics":["response","dfir","analysis","analyzer","thehive","engine","scala","python","rest","api"],"license":"AGPL-3.0","category":"api-integrations-sdks","readme_excerpt":"Cortex tries to solve a common problem frequently encountered by SOCs, CSIRTs and security researchers in the course of threat intelligence, digital forensics and incident response: how to analyze observables they have collected, at scale , by querying a single tool instead of several? Cortex, an open source and free software, has been created by TheHive Project for this very purpose. Observables, such as IP and email addresses, URLs, domain names, files or hashes, can be analyzed one by one or in bulk mode using a Web interface. Analysts can also automate these operations thanks to the Cortex REST API. By using Cortex, you won't need to rewrite the wheel every time you'd like to use a service or a tool to analyze an observable and help you investigate the case at hand. Leverage one of the several analyzers it contains and if you are missing a tool or a service, create a suitable program easily and make it available for the whole team (or better, for the whole community) thanks to Cortex. Cortex and TheHive Along with MISP, Cortex is the perfect companion for TheHive. TheHive let you analyze tens or hundreds of observables in a few clicks by leveraging one or several Cortex instances depending on your OPSEC needs and performance requirements. Moreover, TheHive comes with a report template engine that allows you to adjust the output of Cortex analyzers to your taste instead of having to create your own JSON parsers for Cortex output. Cortex and MISP Cortex can be integrated wi","default_branch":null,"files":null,"tree":[],"storefront":"/r/TheHive-Project","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/TheHive-Project/Cortex/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}