TheHive, Cortex and MISP is a **highly integrated**, free, open source stack used by many teams to perform CTI & DFIR related activities. In this talk we'll showcase the main features of this powerful trio and cover some automation, collaboration and response use cases.TheHive, a Security Incident Response Platform and its sidekick Cortex, a powerful observable analysis and response engine are feature-packed free, open source software, used by many teams of all sizes around the world to manage alerts and notifications from various sources (emails, SIEM, IDS/IPS, intelligence providers...), security incidents and collaborate through a field-proven workflow to handle their investigations swiftly, analyze observables at scale using more than 80 different analyzers and perform active response. TheHive & Cortex are more efficient when used alongside MISP, the *de facto* standard for threat sharing with which they are highly integrated. Thanks to MISP, TheHive & Cortex can pull events from multiple instances, search for key indicators of compromise in those instances and others and share investigation results selectively with different communities. In this talk we will introduce TheHive, Cortex and MISP to the audience, cover their main features to help automate and mature CTI and DFIR activities and provide a few use cases to demonstrate their power.