TheHive
Integrates with TheHive incident response platform to retrieve alerts and cases, promote alerts to cases, and create new cases for
TheHive MCP server provides AI assistants with direct access to TheHive incident response platform for security case management operations. Developed by Gianluca Brigandi in Rust, it exposes tools for retrieving alerts and cases, promoting alerts to cases, and creating new cases through TheHive's API using bearer token authentication. The implementation leverages the thehive-client-rs library and includes comprehensive error handling, SSL verification controls, and structured data formatting, making it valuable for security teams wanting to automate incident response workflows or integrate TheHive operations into AI-assisted security analysis and case management processes.
Source
Repository: https://github.com/gbrigandi/mcp-server-thehive
Maintain TheHive?
Let people know it's listed here — add the badge (live metrics, light/dark aware) or a plain link to your README or docs.
[TheHive on getagentictools](https://getagentictools.com/mcp/gbrigandi-mcp-server-thehive?ref=badge)