{"id":11230,"date":"2021-11-15T17:10:23","date_gmt":"2021-11-15T16:10:23","guid":{"rendered":"https:\/\/www.nextron-systems.com\/?page_id=11230"},"modified":"2024-04-08T14:27:51","modified_gmt":"2024-04-08T12:27:51","slug":"tryhackme-for-thor-lite","status":"publish","type":"page","link":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/","title":{"rendered":"TryHackMe Room for THOR Lite"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; background_color=&#8221;#03161f&#8221; use_background_color_gradient=&#8221;on&#8221; background_color_gradient_stops=&#8221;rgba(3,22,31,0.5) 0%|#03161f 100%&#8221; background_color_gradient_overlays_image=&#8221;on&#8221; background_image=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2024\/02\/01.resized.jpg&#8221; background_position=&#8221;top_center&#8221; background_vertical_offset=&#8221;20%&#8221; custom_padding=&#8221;5%||5%||false|false&#8221; hover_enabled=&#8221;0&#8243; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; module_class=&#8221;nextron-div-bottom&#8221; admin_label=&#8221;Section&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221; sticky_enabled=&#8221;0&#8243;][et_pb_row _builder_version=&#8221;4.24.0&#8243; _module_preset=&#8221;default&#8221; custom_padding=&#8221;0px||0px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.24.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.24.0&#8243; _module_preset=&#8221;default&#8221; text_font=&#8221;|800||on|||||&#8221; text_font_size=&#8221;20px&#8221; link_text_color=&#8221;#999999&#8243; custom_margin=&#8221;||||false|false&#8221; custom_padding=&#8221;||||false|false&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><a href=\"\/trainings\"><i style=\"margin-right: 10px;\" class=\"fa-solid fa-arrow-left\"><\/i>Back to Trainings<\/a><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; header_font=&#8221;|800|||||||&#8221; header_font_size=&#8221;60px&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>TryHackMe Room for THOR Lite<\/h1>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; admin_label=&#8221;Section&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row column_structure=&#8221;2_3,1_3&#8243; _builder_version=&#8221;4.24.3&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; custom_margin=&#8221;60px||40px||false|false&#8221; sticky_enabled=&#8221;0&#8243;][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.19.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.16&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Since THOR and THOR Lite are tools written for digital forensic experts, they can be difficult to use. There is often a steep learning curve in the beginning.<\/p>\n<p>We&#8217;d like to help new users pass these first steps in a playful way by providing a TryHackMe challenge in which you analyse a compromised system using THOR Lite.<\/p>\n<p>You&#8217;ll learn how to download and run it, interpret the results, write your own signatures and include your own IOCs for a custom threat.\u00a0<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Technical requirements<\/h3>\n<p>You&#8217;ll work with a prepared virtual machine that you&#8217;re required to download during the training.<\/p>\n<ul>\n<li>VMware or VirtualBox<\/li>\n<li>13 GB download and 23 GB of disk space<\/li>\n<\/ul>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Prerequisites<\/h3>\n<p>The room is meant for first time THOR or THOR Lite users.<\/p>\n<p>Target Audience: DFIR professionals, administrators, security analysts<br \/>\nDuration: ~3 hours (without the download of the VM)[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.19.5&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_cta title=&#8221;TryHackMe Room for THOR Lite&#8221; button_url=&#8221;https:\/\/tryhackme.com\/jr\/thorlite&#8221; url_new_window=&#8221;on&#8221; button_text=&#8221;Enter Room&#8221; _builder_version=&#8221;4.24.2&#8243; _module_preset=&#8221;default&#8221; header_level=&#8221;h3&#8243; header_font_size=&#8221;22px&#8221; background_color=&#8221;#15242a&#8221; text_orientation=&#8221;left&#8221; border_width_all=&#8221;2px&#8221; border_color_all=&#8221;#009EC7&#8243; box_shadow_style=&#8221;preset1&#8243; box_shadow_vertical=&#8221;0px&#8221; box_shadow_blur=&#8221;30px&#8221; box_shadow_spread=&#8221;-10px&#8221; box_shadow_color=&#8221;#009EC7&#8243; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Free | TryHackMe account needed<\/p>\n<p>[\/et_pb_cta][et_pb_text _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Detailed learning content<\/h3>\n<ul>\n<li>THOR Lite Util<\/li>\n<li>THOR Lite Flags<\/li>\n<li>Your first scan<\/li>\n<li>Reading the HTML Report and using VirusTotal<\/li>\n<li>Adding a custom IOC<\/li>\n<li>Write your own YARA rule<\/li>\n<li>Adding another Filename IOC<\/li>\n<li>Full scan<\/li>\n<li>False Positive Filter<\/li>\n<\/ul>\n<p><a href=\"mailto:feedback@nextron-systems.com\">Please help us and send your feedback<\/a>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Back to TrainingsTryHackMe Room for THOR LiteSince THOR and THOR Lite are tools written for digital forensic experts, they can be difficult to use. There is often a steep learning curve in the beginning. We&#8217;d like to help new users pass these first steps in a playful way by providing a TryHackMe challenge in which you analyse a compromised system using THOR Lite. You&#8217;ll learn how to download and run it, interpret the results, write your own signatures and include your own IOCs for a custom threat.\u00a0Technical requirements You&#8217;ll work with a prepared virtual machine that you&#8217;re required to download during the training. VMware or VirtualBox 13 GB download and 23 GB of disk space Prerequisites The room is meant for first time THOR or THOR Lite users. Target Audience: DFIR professionals, administrators, security analysts Duration: ~3 hours (without the download of the VM)Free | TryHackMe account neededDetailed learning content THOR Lite Util THOR Lite Flags Your first scan Reading the HTML Report and using VirusTotal Adding a custom IOC Write your own YARA rule Adding another Filename IOC Full scan False Positive Filter Please help us and send your feedback<\/p>\n","protected":false},"author":4,"featured_media":0,"parent":15139,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"class_list":["post-11230","page","type-page","status-publish","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>TryHackMe Room for THOR Lite - Trainings - Nextron Systems<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/\",\"url\":\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/\",\"name\":\"TryHackMe Room for THOR Lite - Trainings - Nextron Systems\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#website\"},\"datePublished\":\"2021-11-15T16:10:23+00:00\",\"dateModified\":\"2024-04-08T12:27:51+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Trainings\",\"item\":\"https:\/\/www.nextron-systems.com\/trainings\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"TryHackMe Room for THOR Lite\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.nextron-systems.com\/#website\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"name\":\"Nextron Systems\",\"description\":\"We Detect Hackers\",\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.nextron-systems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\",\"name\":\"Nextron Systems GmbH\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"contentUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"width\":260,\"height\":260,\"caption\":\"Nextron Systems GmbH\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"TryHackMe Room for THOR Lite - Trainings - Nextron Systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/","url":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/","name":"TryHackMe Room for THOR Lite - Trainings - Nextron Systems","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/#website"},"datePublished":"2021-11-15T16:10:23+00:00","dateModified":"2024-04-08T12:27:51+00:00","breadcrumb":{"@id":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.nextron-systems.com\/trainings\/tryhackme-for-thor-lite\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Trainings","item":"https:\/\/www.nextron-systems.com\/trainings\/"},{"@type":"ListItem","position":2,"name":"TryHackMe Room for THOR Lite"}]},{"@type":"WebSite","@id":"https:\/\/www.nextron-systems.com\/#website","url":"https:\/\/www.nextron-systems.com\/","name":"Nextron Systems","description":"We Detect Hackers","publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.nextron-systems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.nextron-systems.com\/#organization","name":"Nextron Systems GmbH","url":"https:\/\/www.nextron-systems.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","contentUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","width":260,"height":260,"caption":"Nextron Systems GmbH"},"image":{"@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/pages\/11230","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/comments?post=11230"}],"version-history":[{"count":39,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/pages\/11230\/revisions"}],"predecessor-version":[{"id":21906,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/pages\/11230\/revisions\/21906"}],"up":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/pages\/15139"}],"wp:attachment":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/media?parent=11230"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}