Post videos, photos, text, and documents to 10 social platforms through a single REST API call.
Coding
Soc Deploy Thehive
Try itDeploy TheHive 5 + Cortex 3 incident response platform on any Docker-ready Linux host. Automates account creation, API key generation, Cortex CSRF handling,...
What it does
Deploy TheHive + Cortex incident response platform on any Docker-ready Linux host.
The skill document
SOC Deploy: TheHive 5.4 + Cortex 3.1.8
Deploy TheHive + Cortex incident response platform on any Docker-ready Linux host.
This skill does NOT create VMs. It expects an SSH target with Docker installed. Use hyperv-create-vm or proxmox-create-vm first if you need infrastructure.
When to Use
- "deploy thehive"
- "set up thehive"
- "install thehive and cortex"
- "thehive lab"
- "incident response platform"
User Inputs
| Parameter | Default | Required |
|---|---|---|
| SSH target | - | Yes (user@host) |
| Admin password | ChangeMe123! | No |
| Org name (Cortex) | SOC | No |
| TheHive secret | (generated 40-char) | No |
Prerequisites Check
# SSH works
ssh "echo OK"
# Docker + Compose v2
ssh "docker --version && docker compose version"
# RAM check (need 4GB+ free)
ssh "free -h | grep Mem"
Execution
Single command deployment
scp scripts/setup.sh :~/
scp references/docker-compose.yml :~/thehive-cortex/docker-compose.yml
ssh "bash ~/setup.sh '' ''"
What setup.sh does (from thehive-cortex-setup-guide.md)
- Create directory + write docker-compose.yml
docker compose up -d(Cassandra + ES + TheHive + Cortex)- Poll health endpoints until all services respond:
GET :9200/_cluster/health(Elasticsearch)GET :9000/api/status(TheHive)GET :9001/api/status(Cortex)
- TheHive admin setup:
POST /api/v1/loginwithadmin@thehive.local/secretPOST /api/v1/user/admin@thehive.local/password/change(NOT PATCH)POST /api/v1/user/admin@thehive.local/key/renew-> API key
- Cortex setup (CSRF dance):
POST /api/maintenance/migratePOST /api/user(create superadmin, first-user endpoint)POST /api/login-> session cookieGET /api/user/admin-> captureCORTEX-XSRF-TOKENcookiePOST /api/organization(with CSRF cookie + header)POST /api/user(org admin, with CSRF)POST /api/user//key/renew(with CSRF) -> org keyPOST /api/user/admin/key/renew(with CSRF) -> super key
- Wire integration:
- Update docker-compose.yml: add
--cortex-hostnames cortex --cortex-keys docker compose up -d thehive(restart only TheHive)- Wait 30s for TheHive startup
- Update docker-compose.yml: add
- Verify both APIs respond with Bearer keys
- Write credentials to
~/thehive-cortex/api-keys.txt
Output to User
TheHive + Cortex deployed!
TheHive: http://:9000
Cortex: http://:9001
Credentials:
TheHive admin: admin@thehive.local /
Cortex superadmin: admin /
Cortex org admin: -admin (API key only)
API Keys:
TheHive:
Cortex superadmin:
Cortex org admin:
MCP Connection:
THEHIVE_URL=http://:9000
THEHIVE_API_KEY=
CORTEX_URL=http://:9001
CORTEX_API_KEY=
Keys saved to: ~/thehive-cortex/api-keys.txt
Critical Gotchas
See references/gotchas.md for full details:
- Cortex CSRF (biggest automation blocker): Cookie
CORTEX-XSRF-TOKEN+ headerX-CORTEX-XSRF-TOKENon ALL mutating requests. Standard Play Framework bypass headers do NOT work. After first API key, useAuthorization: Bearerto skip CSRF - TheHive password endpoint:
POST /password/changewithcurrentPassword+password. The PATCH endpoint returns 204 but silently ignores the password field - Bash
!in passwords: Useprintf '...' | curl -d @-, not direct-dwith exclamation marks - First-user one-shot: Cortex
POST /api/userwithout auth only works when zero users exist - TheHive startup delay: 15-30s after compose up (waits for Cassandra)
- Secret length: TheHive Play Framework JWT needs 32+ char secret
- Use org admin key (not superadmin) for TheHive-Cortex integration (least privilege)
API Quick Reference
See references/api-reference.md for the full endpoint list.
Timeout Strategy
Setup takes ~5-7 min (mostly waiting for services). If docker images are not cached, add ~5 min for pull. Split into:
- Turn 1:
docker compose up -d+ pull images (~5 min) - Turn 2: Account setup + API keys (~3 min)
Pairs With
hyperv-create-vm- create a Hyper-V VM, then deploy TheHive on itproxmox-create-vm- create a Proxmox LXC/VM, then deploy TheHive on itsoc-deploy-misp- deploy MISP alongside for threat intelligence
Related skills
Query Twitter/X profiles, tweets, follower events, and KOL data through the 6551 REST API.
Stores durable facts in a categorized, plain-markdown vault on disk, alongside your agent's built-in memory.
Generate and edit Draw.io, Mermaid, and Excalidraw diagrams from natural language using a structured JSON spec.
Query and manage Linear issues, projects, teams, cycles, labels, and comments through a managed OAuth GraphQL endpoint.
Trade crypto, manage a multi-chain wallet, and query an AI analyst from one CLI.
More from solomonneas
Browse all skillsEssential penetration testing command reference. Quick lookup for nmap, Metasploit, hydra, john, nikto, gobuster, and other offensive security tools. Covers...
Memory forensics with Volatility and related tools. Acquire RAM dumps, extract processes and DLLs, investigate rootkits and fileless malware, recover credent...
This skill should be used when the user asks to "run pentest commands", "scan with nmap", "use metasploit exploits", "crack passwords with hydra or john", "s...
Expert malware analysis for defensive security research. Static and dynamic analysis, sandbox triage, IOC extraction, unpacking, and malware family identific...
Knowledge card memory system with semantic search. Agents wake up fresh each session but remember everything through atomic ~350-token cards with YAML frontm...
Network traffic analysis with Wireshark and tshark. Capture packets, write display and BPF filters, follow TCP/UDP/TLS streams, detect C2 beacons, troublesho...