This repository is deprecated; please follow the main search page or use the ‘Related code repos’ widget on the right side of the current page.

CiscoSecureX-TheHive

Short Description:

Cisco SecureX Action Orchestrator Workflows - Casebook - TheHive sync

This Workflow creates a Case in Cisco SecureX Casebook and an associated TheHive Case, where all Observables are synced!

NOTE:
Please be aware of, that there are different regions available for SecureX:

Automated_IR_with_SecureX___TheHive

The goal is to handover Observables from SecureX to TheHive via the built-in orchestrator (SecureX Orchestration (SXO)) Workflows.

Features:

  • faster Incident Respond and handover to the SOC Team
  • easy exchange Observables from Cisco Secure platform into TheHive SIRP
  • automatic Observable enrichment into TheHive via Casebook Browser PlugIn
    • no more manually Copy & Paste action
    • no more typos by adding Observables by typing
    • automated start of Cortex Anaylzer by just adding the observables
    • completely independent, only a website is needed to extract the observables

Create both Cases and map it via a Global Variable Table inside SXO

SecureX orchestration

AO Workflow: ". . . create Casebook and sync it with TheHive 🐝"
Case Creation GIF

Sync Obseravables from SecureX Casebook to TheHive (manual task via SXO Response Action in Threat Response)

add slide about the sync

SXO Workflow: "Parse Casebooks Observables and add missing to TheHive 🧩"
Casebook_TheHive_manually_sync

Integration of Casebook Browser PlugIn to add Observables into TheHive Case (via a Cisco Casebook Case)

add slide about Casebook Integration

SXO Workflow: not needed - scheduled Workflow

Find observable(s) in page via Casebook browser plugin (for Chrome and Firefox)

Casebook_Find_observable_in_page GIF

TheHive gets the observable(s) and start the appropriate Analyzers

TheHive_Added_observables_in_case_analyzer_starts GIF

Installation

Detailed installation instructions can be found HERE

View code on GitHub

Code Exchange Community

Get help, share code, and collaborate with other developers in the Code Exchange community.View Community
Disclaimer:
Cisco provides Code Exchange for convenience and informational purposes only, with no support of any kind. This page contains information and links from third-party websites that are governed by their own separate terms. Reference to a project or contributor on this page does not imply any affiliation with or endorsement by Cisco.