{"id":17961,"date":"2023-11-03T15:17:30","date_gmt":"2023-11-03T14:17:30","guid":{"rendered":"https:\/\/www.nextron-systems.com\/?p=17961"},"modified":"2024-08-02T11:33:36","modified_gmt":"2024-08-02T09:33:36","slug":"integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response","status":"publish","type":"post","link":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/","title":{"rendered":"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p style=\"text-align: left;\">Digital forensics and incident response (DFIR) are critical components in the cybersecurity landscape. Evolving threats and complex cyber-attacks make it vital for organizations to have efficient and powerful tools available. If you are not already enjoying the benefits of our <a href=\"https:\/\/www.nextron-systems.com\/asgard-management-center\/\">ASGARD<\/a> platform and if your are using Velociraptor for DFIR it is worth to read on. In this blog post, we explore the integration of THOR into Velociraptor and the benefits it brings to Velociraptor users.<\/p>\n<p>If you are a technical reader and already know your way around THOR and Velocriaptor you might want to directly jump to the end of the blog.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor.png&#8221; title_text=&#8221;thor&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_heading title=&#8221;DFIR Platforms&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>If you&#8217;re content with Velociraptor for your endpoint management and wary switching your DFIR platform, we understand your concerns. Hence, we&#8217;ve crafted artifacts to integrate THOR, our endpoint scanner, into your existing Velociraptor setup. This integration allows you to leverage THOR&#8217;s robust scanning capabilities, ensuring a streamlined, efficient, and non-disruptive addition to your security infrastructure. While we consider <a href=\"https:\/\/www.nextron-systems.com\/asgard-management-center\/\">ASGARD<\/a> to be the prime solution for managing and evaluating THOR scans, this blog ensures you have a robust alternative that complements and enhances your current security measures without adopting a new platform.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_heading title=&#8221;Velociraptor &#8211; Digging Deeper!&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;||29px|||&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>&#8220;Velociraptor is an advanced digital forensic and incident response tool that enhances your visibility into your endpoints.&#8221;<\/em><br \/><a href=\"https:\/\/docs.velociraptor.app\/\">https:\/\/docs.velociraptor.app\/<\/a><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Velociraptor is a open-source digital forensic and incident response tool designed to collect, monitor and hunt within your environment. At its core is the Velociraptor Query Language (VQL), a solid framework that allows for the creation of highly customized queries. These queries can be used to collect and monitor data from single or multiple endpoints across a network. VQL queries can be packed into &#8216;Artifacts&#8217;, which are structured YAML files containing named queries for easy searching, execution and sharing with the community. These Artifacts serve as modules, each typically focused on retrieving a specific type of information from an endpoint, which simplifies forensic and monitoring tasks.<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/velo_logo.svg&#8221; title_text=&#8221;velo_logo&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_heading title=&#8221;THOR APT Scanner&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>THOR is an advanced compromise assessment tool specifically designed to detect hack tools, backdoors, and traces of hacker activities on endpoints that standard Anti-virus solutions often miss. Using over 20,000 YARA signatures and over 24 specific modules, THOR examines systems for signs of attacker tools, system manipulations, and suspicious log activities. THOR has an extensive detection rate, ensuring system stability by monitoring resources and auto-adjusting performance.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor-logo-text.svg&#8221; title_text=&#8221;thor-logo-text&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_heading title=&#8221;Supercharge Your DFIR with Integration&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>Consider a scenario where you see unusual network activity from a host within your company network. Now, where do you start?<br \/>This is where THOR shines: With its huge (offline) detection set, it is perfect to start your DFIR process. With THOR you do not need to know what you are looking for, THOR knows on its own! Use the <a href=\"https:\/\/github.com\/NextronSystems\/velociraptor-artifacts-thor\">opensource Velociraptor THOR artifact<\/a> (see below) to boost your triage while still working in your familiar Velociraptor UI, using its features for collection, monitoring and mitigation.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/notebook.png&#8221; title_text=&#8221;notebook&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h3>Velociraptor THOR Artifacts<\/h3>\n<p>We&#8217;ve created three Velociraptor <a href=\"https:\/\/github.com\/NextronSystems\/velociraptor-artifacts-thor\/tree\/master\/artifacts\">artifacts<\/a> for using and leveraging THOR:<\/p>\n<ul>\n<li><a href=\"https:\/\/github.com\/NextronSystems\/velociraptor-artifacts-thor\/blob\/master\/artifacts\/Generic.Scanner.Thor.yaml\">Generic artifact<\/a> for THOR (enterprise) forensic scanner. Works for all major operating systems and licenses endpoints on the fly.<\/li>\n<li><a href=\"https:\/\/github.com\/NextronSystems\/velociraptor-artifacts-thor\/blob\/master\/artifacts\/Generic.Scanner.ThorZIP.yaml\">Artifact<\/a> which is used best in combination with THOR Lite. Expects a ZIP file with THOR Lite (as downloaded from our servers) and a THOR Lite license. Works for all major operating systems.<\/li>\n<li><a href=\"https:\/\/github.com\/NextronSystems\/velociraptor-artifacts-thor\/blob\/master\/artifacts\/Generic.Scanner.ThorCloud.yaml\">Artifact<\/a> for our newest member in the THOR family: <a href=\"https:\/\/www.nextron-systems.com\/2023\/10\/30\/introducing-thor-cloud-lite-seamless-on-demand-security-scanning-made-easy\/\">THOR Cloud<\/a><\/li>\n<\/ul>\n<p>[\/et_pb_text][et_pb_heading title=&#8221;Get Started&#8221; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_heading][et_pb_text _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p>To get up and running with Velociraptor and THOR see the following links:<\/p>\n<ul>\n<li>Velociraptor &#8211; <a href=\"https:\/\/docs.velociraptor.app\/docs\/\">https:\/\/docs.velociraptor.app\/docs\/<\/a><\/li>\n<li>THOR:\n<ul>\n<li><a href=\"https:\/\/www.nextron-systems.com\/thor\/\">https:\/\/www.nextron-systems.com\/thor\/<\/a><\/li>\n<li><a href=\"https:\/\/www.nextron-systems.com\/thor-lite\/\">https:\/\/www.nextron-systems.com\/thor-lite\/<\/a><\/li>\n<li><a href=\"https:\/\/www.nextron-systems.com\/thor-cloud\/\">https:\/\/www.nextron-systems.com\/thor-cloud\/<\/a><\/li>\n<\/ul>\n<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.23&#8243; _module_preset=&#8221;default&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Digital forensics and incident response (DFIR) are critical components in the cybersecurity landscape. Evolving threats and complex cyber-attacks make it vital for organizations to have efficient and powerful tools available. If you are not already enjoying the benefits of our ASGARD platform and if your are using Velociraptor for DFIR it is worth to read on. In this blog post, we explore the integration of THOR into Velociraptor and the benefits it brings to Velociraptor users. If you are a technical reader and already know your way around THOR and Velocriaptor you might want to directly jump to the end of the blog.If you&#8217;re content with Velociraptor for your endpoint management and wary switching your DFIR platform, we understand your concerns. Hence, we&#8217;ve crafted artifacts to integrate THOR, our endpoint scanner, into your existing Velociraptor setup. This integration allows you to leverage THOR&#8217;s robust scanning capabilities, ensuring a streamlined, efficient, and non-disruptive addition to your security infrastructure. While we consider ASGARD to be the prime solution for managing and evaluating THOR scans, this blog ensures you have a robust alternative that complements and enhances your current security measures without adopting a new platform.&#8221;Velociraptor is an advanced digital forensic and incident [&hellip;]<\/p>\n","protected":false},"author":13,"featured_media":17974,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[749,760,87,32,556,248,264],"tags":[13,77,233,727,7,5,607,726,48],"class_list":["post-17961","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-homepage","category-recommended","category-security-monitoring","category-thor","category-thor-cloud","category-thor-lite","category-tool","tag-detection","tag-endpoint","tag-forensic","tag-integration","tag-scanner","tag-thor","tag-thor-lite","tag-velociraptor","tag-yara"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response - Nextron Systems<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\"},\"author\":{\"name\":\"Paul Hager\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/cda3539ca95e549d45316b14bea853eb\"},\"headline\":\"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response\",\"datePublished\":\"2023-11-03T14:17:30+00:00\",\"dateModified\":\"2024-08-02T09:33:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\"},\"wordCount\":1218,\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png\",\"keywords\":[\"detection\",\"endpoint\",\"Forensic\",\"Integration\",\"scanner\",\"thor\",\"THOR Lite\",\"Velociraptor\",\"YARA\"],\"articleSection\":[\"Homepage\",\"Recommended\",\"Security Monitoring\",\"THOR\",\"THOR Cloud\",\"THOR Lite\",\"Tool\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\",\"url\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\",\"name\":\"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response - Nextron Systems\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png\",\"datePublished\":\"2023-11-03T14:17:30+00:00\",\"dateModified\":\"2024-08-02T09:33:36+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage\",\"url\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png\",\"contentUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png\",\"width\":1024,\"height\":1024},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.nextron-systems.com\/#website\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"name\":\"Nextron Systems\",\"description\":\"We Detect Hackers\",\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.nextron-systems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\",\"name\":\"Nextron Systems GmbH\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"contentUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"width\":260,\"height\":260,\"caption\":\"Nextron Systems GmbH\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/cda3539ca95e549d45316b14bea853eb\",\"name\":\"Paul Hager\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/e6adba4e18061540f4e1aa40fd7aa12d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/e6adba4e18061540f4e1aa40fd7aa12d?s=96&d=mm&r=g\",\"caption\":\"Paul Hager\"},\"description\":\"Threat Researcher &amp; Detection Engineer @nextronsystems | @TUVienna Graduate\",\"sameAs\":[\"https:\/\/x.com\/pH_T__\"],\"url\":\"https:\/\/www.nextron-systems.com\/author\/paul\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response - Nextron Systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#article","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/"},"author":{"name":"Paul Hager","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/cda3539ca95e549d45316b14bea853eb"},"headline":"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response","datePublished":"2023-11-03T14:17:30+00:00","dateModified":"2024-08-02T09:33:36+00:00","mainEntityOfPage":{"@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/"},"wordCount":1218,"publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"image":{"@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage"},"thumbnailUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png","keywords":["detection","endpoint","Forensic","Integration","scanner","thor","THOR Lite","Velociraptor","YARA"],"articleSection":["Homepage","Recommended","Security Monitoring","THOR","THOR Cloud","THOR Lite","Tool"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/","url":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/","name":"Integration of THOR in Velociraptor: Supercharging Digital Forensics and Incident Response - Nextron Systems","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage"},"image":{"@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage"},"thumbnailUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png","datePublished":"2023-11-03T14:17:30+00:00","dateModified":"2024-08-02T09:33:36+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/2023\/11\/03\/integration-of-thor-in-velociraptor-supercharging-digital-forensics-and-incident-response\/#primaryimage","url":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png","contentUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2023\/10\/thor_velo1.png","width":1024,"height":1024},{"@type":"WebSite","@id":"https:\/\/www.nextron-systems.com\/#website","url":"https:\/\/www.nextron-systems.com\/","name":"Nextron Systems","description":"We Detect Hackers","publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.nextron-systems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.nextron-systems.com\/#organization","name":"Nextron Systems GmbH","url":"https:\/\/www.nextron-systems.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","contentUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","width":260,"height":260,"caption":"Nextron Systems GmbH"},"image":{"@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/cda3539ca95e549d45316b14bea853eb","name":"Paul Hager","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/e6adba4e18061540f4e1aa40fd7aa12d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/e6adba4e18061540f4e1aa40fd7aa12d?s=96&d=mm&r=g","caption":"Paul Hager"},"description":"Threat Researcher &amp; Detection Engineer @nextronsystems | @TUVienna Graduate","sameAs":["https:\/\/x.com\/pH_T__"],"url":"https:\/\/www.nextron-systems.com\/author\/paul\/"}]}},"_links":{"self":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/17961","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/users\/13"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/comments?post=17961"}],"version-history":[{"count":28,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/17961\/revisions"}],"predecessor-version":[{"id":19060,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/17961\/revisions\/19060"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/media\/17974"}],"wp:attachment":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/media?parent=17961"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/categories?post=17961"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/tags?post=17961"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}