Skip to content

TheHive & SOC automation

I integrated TheHive with Cortex, MISP, QRadar, threat intelligence platforms, email, Teams and n8n. Python scripts supported analyst reporting, SLA tracking and shift handovers.

Workflow responsibilities

Workflow Purpose
Case management Keep investigation activity and supporting context together.
Enrichment Bring threat intelligence and analyzer results into the case workflow.
Escalation Connect case activity with email and Teams notifications.
Shift reporting Summarize case status, handling times and SLA risk for handover.

In the bank SOC work, I built TheHive with Cortex and n8n and created custom escalation connectors. Daily shift reporting included case SLA calculation and breach flagging.

Bank SOC case study · Related experience · All projects