# TheHive

> Use this tool when you need to automate incident response workflows or integrate security case management into AI-assisted analysis. TheHive MCP server provides direct access to TheHive's incident response platform, allowing AI assistants to retrieve alerts and cases, promote alerts to cases, and create new cases through API interactions. It is ideal for security teams seeking to streamline case management operations and enhance security analysis with structured data formatting and secure authentication.

Canonical page: https://skillsregistry.net/skills/thehive  
JSON: https://api.skillsregistry.net/v1/skills/thehive

## Description

TheHive MCP server provides AI assistants with direct access to TheHive incident response platform for security case management operations. Developed by Gianluca Brigandi in Rust, it exposes tools for retrieving alerts and cases, promoting alerts to cases, and creating new cases through TheHive's API using bearer token authentication. The implementation leverages the thehive-client-rs library and includes comprehensive error handling, SSL verification controls, and structured data formatting, making it valuable for security teams wanting to automate incident response workflows or integrate TheHive operations into AI-assisted security analysis and case management processes.

## Trust

- **Trust score (0–1):** 0.72
- **Verification tier:** verified
- **Last scanned:** 2026-09-19

## Facts

- **Version:** 1.0.0
- **Skill type:** atomic
- **Execution layer:** mcp-remote
- **Runtime environment:** api
- **Category:** security
- **Updated:** 2026-09-19

## Source

- **Source listing:** [PulseMCP](https://www.pulsemcp.com/servers/thehive)
- **Repository:** <https://github.com/gbrigandi/mcp-server-thehive>

## Use it

Resolve this record through the SkillsRegistry MCP server (no auth, read-only):

```
claude mcp add --transport http --scope user skillsregistry https://api.skillsregistry.net/mcp
```

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "get_skill",
    "arguments": {
      "slug": "thehive"
    }
  }
}
```

REST: `GET https://api.skillsregistry.net/v1/skills/thehive` · pull for local use: `GET https://api.skillsregistry.net/v1/skills/thehive/pull`

---
SkillsRegistry indexes agent skills from public registries and GitHub. Skills we have analysed are scanned with Circle-IR and scored on six dimensions; each listing states its scan coverage. More: https://skillsregistry.net/llms.txt
