MCP server · Security
TheHive MCP server
by gbrigandi
Lets your AI read security alerts and cases in TheHive, and create or promote cases for you.

This is a small helper that connects your AI assistant to TheHive, a tool that security teams use to track alerts and investigate incidents. Once it is set up, you can ask your AI about your alerts and cases in plain language instead of clicking around. It is handy for anyone who works in a security operations centre or handles incident response.
What is an MCP server? The 30-second version
On its own, your AI can only chat with you. An MCP server is a small helper program that gives your AI one new skill or a connection to one app. This helper connects your AI to TheHive, so when you ask a question about an alert or a case, the AI can go and look it up there for you. You stay in the chat, and the helper does the fetching behind the scenes.
What this MCP server does
You ask your AI something about your security alerts or cases, in normal words. The AI passes that request to this helper program running on your computer. The helper then talks to your TheHive instance using your API token, and pulls back the alerts or case details you asked about. It can also take actions, like turning an alert into a case or creating a brand new case. The AI then shows you the result right in the chat.
Click to zoomWhat you can do with it
- List recent alerts from TheHive
- Look up the full details of one alert by its ID
- List your open cases
- Look up the full details of one case by its ID
- Promote an alert into a case
- Create a new case with a title, description, severity and tags
Try asking your AI
- “Show me the last 10 alerts in TheHive”
- “Give me the details of alert ~123456”
- “List my open cases”
- “Create a case called Suspicious login attempts, severity 3, tagged phishing”
What it gives back to you
You get answers in the chat, usually as a list or a short summary. For alerts you see things like the ID, title, severity and status. For cases you see the case details, and when you create or promote one, you get back information about the new case that was made.
Before you start
What you need
- Access to a TheHive 5 instance
- A TheHive API token (a kind of password for apps; you create one in your TheHive user settings under API Keys)
- The pre-compiled program file for your system, or the ability to build it yourself
Good to know
This helper can create new cases and promote alerts into cases in your real TheHive, so check with your team before letting your AI make changes.
Install it with your AI
Add TheHive MCP server to your AI, no technical skills needed
You don't install anything by hand. You copy one prompt, paste it into an AI that can work on your computer, and it checks, installs and connects the server for you, asking you when it needs something.
Sign in to get the install prompt
Members get a ready-made prompt that lets the Claude desktop app check TheHive MCP server, install it and connect it for them, step by step. You don't need any technical skills: you copy, paste and answer a few questions. Your connected AI can also find and install any of the 4,066 MCP servers here for you.
Who it's for
Security analysts, incident responders and SOC teams who already use TheHive and want to ask their AI about alerts and cases.





