Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Average Ratings 0 Ratings

Total
ease
features
design
support

No User Reviews. Be the first to provide a review:

Write a Review

Description

THOR stands out as the most advanced and adaptable tool available for compromise assessments. When responding to incidents, teams frequently encounter a collection of compromised devices along with a larger array of potentially affected systems, making the manual examination of numerous forensic images a daunting task. With THOR, the process of forensic analysis is accelerated thanks to its impressive arsenal of over 12,000 meticulously crafted YARA signatures, 400 Sigma rules, a variety of anomaly detection protocols, and countless indicators of compromise (IOCs). This tool is designed to emphasize suspicious activities, alleviate the burden on analysts, and expedite the forensic examination process during critical moments when timely results are vital. By concentrating on areas often overlooked by traditional antivirus solutions, THOR employs an extensive signature library that encompasses a multitude of YARA and Sigma rules, IOCs, and checks for rootkits and anomalies, effectively addressing a wide range of threats. Furthermore, THOR not only identifies backdoors and tools leveraged by attackers but also captures outputs, temporary files, modifications to system configurations, and other remnants of nefarious actions, ensuring a thorough understanding of the incident landscape. The comprehensive nature of THOR makes it an invaluable asset in the realm of cybersecurity.

Description

YARA serves as a resource primarily designed for malware analysts to discover and categorize malware samples effectively. This powerful tool enables users to develop representations of various malware families or other entities by utilizing either textual or binary patterns. Each representation, known as a rule, comprises a collection of strings paired with a boolean expression that dictates its operational logic. Additionally, YARA-CI can enhance your toolkit by offering a GitHub application that facilitates continuous testing of your rules, which aids in detecting frequent errors and minimizing false positives. In essence, the specified rule directs YARA to flag any file that contains one of the three designated strings as a silent_banker, thereby streamlining the identification process. By incorporating YARA and YARA-CI, researchers can significantly improve their malware detection capabilities and overall efficiency in their work.

API Access

Has API No 

API Access

Has API No 

Screenshots View All

Screenshots View All

Integrations

Betterscan.io No 
Filigran No 
LimaCharlie No 
Mesh Yes 
Symantec Network Forensics No 
Tenzir No 
Threat.Zone No 
Uptycs No 

Integrations

Betterscan.io Yes 
Filigran Yes 
LimaCharlie Yes 
Mesh No 
Symantec Network Forensics Yes 
Tenzir Yes 
Threat.Zone Yes 
Uptycs Yes 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Pricing Details

No price information available.
Free Trial No 
Free Version No 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Deployment

Web-Based No 
On-Premises No 
iPhone App No 
iPad App No 
Android App No 
Windows Yes 
Mac Yes 
Linux Yes 
Chromebook No 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Customer Support

Business Hours No 
Live Rep (24/7) No 
Online Support Yes 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Types of Training

Training Docs Yes 
Webinars No 
Live Training (Online) No 
In Person No 

Vendor Details

Company Name

Nextron Systems

Founded

2017

Country

Germany

Website

www.nextron-systems.com/thor/

Vendor Details

Company Name

YARA

Website

virustotal.github.io/yara/

Product Features

Incident Response

Attack Behavior Analytics No 
Automated Remediation No 
Compliance Reporting No 
Forensic Data Retention No 
Incident Alerting No 
Incident Database No 
Incident Logs No 
Incident Reporting No 
Privacy Breach Reporting No 
SIEM Data Ingestion / Correlation No 
SLA Tracking / Management No 
Security Orchestration No 
Threat Intelligence No 
Timeline Analysis No 
Workflow Automation No 
Workflow Management No 

Product Features

Alternatives

ListSync Reviews

ListSync

ThorApps

Alternatives

THOR Reviews

THOR

Nextron Systems
ASGARD Management Center Reviews

ASGARD Management Center

Nextron Systems
Alisha AI SDR Reviews

Alisha AI SDR

floworks