PurpleLab Cortex Analyzer enhances TheHive incident responses by automating uploads and detonations of executables tied to cases. This tool streamlines SOC workflows, improving threat analysis and security outcomes.
-
Place the two files in the
/opt/Cortex-Analyzers/analyzers/
folder. -
In
PurpleLabAnalyzer.py
, replace all occurrences ofYourPurpleLabURL
with the IP address of your PurpleLab instance. -
Configure the analyzer in Cortex.