Skip to content
Cortex: Installation, operation, and user guides

Source Code: https://github.com/thehive-project/Cortex/

Website: https://www.strangebee.com


Cortex#

Cortex solves two common problems frequently encountered by Security Operations Centers (SOCs), Computer Security Incident Response Teams (CSIRTs), and security researchers during threat intelligence, digital forensics, and incident response:

  • How to analyze observables they have collected, at scale, by querying a single tool instead of several?
  • How to actively respond to threats and interact with the constituency and other teams?

Thanks to its many analyzers and its RESTful API, Cortex simplifies observable analysis, particularly when called from TheHive, a Security Incident Response Platform (SIRP).

TheHive can also use Cortex responders to perform specific actions on alerts, cases, tasks, and observables collected during an investigation: send an email to the constituents, block an IP address at the proxy level, or notify team members that an alert needs urgent attention.

Cortex includes many features:

  • Manage multiple organizations (multi-tenancy)
  • Manage users per organization and role
  • Configure per-organization analyzer and responder settings
  • Set rate limits to avoid consuming all your quotas at once
  • Cache analysis results to skip re-running an analyzer on the same observable within a set timespan (10 minutes by default, adjustable per analyzer)

Installation and configuration guides#

Cortex Installation Methods lists the available ways to install Cortex—packages, Docker, or Kubernetes—and links to the corresponding step-by-step guide for each.

All aspects of the configuration are also detailed in a dedicated section.

User guides#

The first connection to the application requires several actions.

Cortex supports different roles for users. Refer to User roles for more details.

License#

Cortex is open source, free software released under the Affero General Public License (AGPL). StrangeBee is committed to keeping Cortex free and open source over the long term.

Updates and community discussions#

StrangeBee regularly posts information, news, and updates on several communication channels:

StrangeBee Twitter account / TheHive Project Twitter account

TheHive Project Mastodon account / StrangeBee Mastodon account

blog at StrangeBee

Join the user community on Discord

Professional support#

StrangeBee Since 2018, StrangeBee has fully developed and maintained Cortex. If you need dedicated assistance, StrangeBee also provides professional services and support.