TheHive & SOC automation
I integrated TheHive with Cortex, MISP, QRadar, threat intelligence platforms, email, Teams and n8n. Python scripts supported analyst reporting, SLA tracking and shift handovers.
Workflow responsibilities
| Workflow | Purpose |
|---|---|
| Case management | Keep investigation activity and supporting context together. |
| Enrichment | Bring threat intelligence and analyzer results into the case workflow. |
| Escalation | Connect case activity with email and Teams notifications. |
| Shift reporting | Summarize case status, handling times and SLA risk for handover. |
In the bank SOC work, I built TheHive with Cortex and n8n and created custom escalation connectors. Daily shift reporting included case SLA calculation and breach flagging.