Solutions

What's Cortex ?
POWERFUL OBSERVABLE ANALYSIS AND ACTIVE RESPONSE ENGINE

Thanks to Cortex, observables such as IP and email addresses, URLs, domain names, files or hashes can be analyzed using a Web interface. Analysts can also automate these operations and submit large sets of observables from TheHive or through the Cortex REST API from alternative SIRP platforms, custom scripts or MISP. When used in conjunction with TheHive, Cortex facilitates the containment phase thanks to its cutting edge Active Response features.

Cortex dashboard screenshotGithubGet Started
version 5is out now !
Cortex dashboard screenshot

Features

  • Multi Tenant Environments illustration

    Create several organizations, populate them with the required users, customize the default settings for analyzers and responders and start investigating.

Multi Tenant Environments illustration

Create several organizations, populate them with the required users, customize the default settings for analyzers and responders and start investigating.

Write
tab illustration

By using Cortex, you won’t need to reinvent the wheel every time you’d like to use a service or a tool to analyze an observable, helping you investigate the case at hand or see if it contain threats before it’s too late. Leverage its very large and powerful set of analyzers or create your own analyzer or responder using any programming language supported by Linux and share them with your team or, better yet, with the whole community! Remember that you can also simultaneously query multiple MISP instances.

Run
tab illustration

Cortex is the perfect companion for TheHive. TheHive can connect to one or multiple Cortex instances. With a few clicks you can analyze tens, if not hundreds of observables at once or trigger active responses. Using TheHive’s report engine, it’s easy to parse Cortex output and display it the way you want. You can also use Cortex as a standalone product thanks to its powerful Web UI to manage multiple organizations, analyzers and configure query limits. Cortex can be interfaced with other products through its REST API or by using Cortex4py.

Execute
tab illustration

Cortex comes with more than a hundred analyzers for popular services such as VirusTotal, Joe Sandbox, DomainTools, PassiveTotal, Google Safe Browsing, Shodan and Onyphe. Identify abuse contacts, parse files in several formats such as OLE and OpenXML to detect VBA macros, generate useful information on PE, PDF files and much more. Cortex analyzers can also be queried from MISP to enrich events and extend the coverage of your investigations.

Is Cortex still open source?

How much does it cost?

What is happening to my Cortex servers?

Are there any changes to Cortex with TheHive 5?

What happens to my existing Analyzers and Responders?