Imap2TheHive Logo

Imap2TheHive: Support for Observables

I just published a new update of my imap2thehive tool. A quick reminder: this tool is aimed to poll an IMAP mailbox and feed an instance of TheHive with processed emails. This new version is now able to extract interesting IOCs from the email body and attached HTML files. The following indicators are supported:

  • IP addresses
  • Domains
  • FQDNs
  • URLs
  • Email addresses
  • Filenames
  • Hashes (MD5, SHA1, SHA256)

To use it, add the following directive in the configuration file:

observables: true

Newly created cases will contain the IOCs found. They will be tagged with the same TLP level as the case.

The script is available here.


  1. Yes, it is possible, check out the latest version on Git.
    Attachments are selected based on their MIME type.

Leave a Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.