{"id":3624,"date":"2018-07-27T13:52:26","date_gmt":"2018-07-27T11:52:26","guid":{"rendered":"http:\/\/nextron.bsk-consulting.de\/?p=3624"},"modified":"2022-03-25T14:15:04","modified_gmt":"2022-03-25T13:15:04","slug":"thor-version-8-49-0-changes","status":"publish","type":"post","link":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/","title":{"rendered":"THOR Version 8.49.0 Changes"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;3.22&#8243;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;3.25&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;3.25&#8243; custom_padding=&#8221;|||&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.4.2&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; hover_enabled=&#8221;0&#8243;]There are a few relevant changes in the upcoming THOR version 8.49.0 that we would like to announce.<\/p>\n<h2>Interpreter and Module Upgrades<\/h2>\n<p>The integrated Python interpreter will be upgraded to Version 2.7.15. We have also upgraded several modules. All our tests showed no signs of problems even with the oldest Windows version like Windows 2003 Server. (officially unsupported)<\/p>\n<p>If you encounter any issues, please let us know.<\/p>\n<h2>4th Generation License Format Support<\/h2>\n<p>THOR 8.49.0 supports the newest license format which allows us to:<\/p>\n<ul>\n<li>set a start date for the period of validity<\/li>\n<li>enable or disable certain modules and features in THOR and SPARK<br \/>\n(e.g. we could license a SPARK version that only scans endpoint logs with Sigma rules)<\/li>\n<\/ul>\n<h2>THOR-util Report Generation<\/h2>\n<p>The new included THOR-util version 1.2 allows to generate HTML reports from scan log files. It can also generate reports for a directory that contains THOR or SPARK scan logs (up to 50 per HTML report). We&#8217;ve discussed this feature in detail in a previous <a href=\"\/2018\/06\/20\/thor-util-with-html-report-generation\/\">blog post<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-3550\" src=\"\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54.png\" alt=\"\" width=\"1383\" height=\"961\" srcset=\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54.png 1383w, https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54-300x208.png 300w, https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54-768x534.png 768w, https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54-1024x712.png 1024w, https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54-1080x750.png 1080w\" sizes=\"(max-width: 1383px) 100vw, 1383px\" \/><\/p>\n<h2>Noresume Becomes the New Default<\/h2>\n<p>The Scan Resume feature has caused many problems during incident response engagements in the past. The feature activates a journal in THOR DB that tracks the state of the scan and resumes the scan automatically if it was interrupted by a user or terminated due to a system shutdown. This feature seemed to be helpful but actually caused some problems.<\/p>\n<p>THOR logs are created in &#8220;write&#8221; (w) mode, not in &#8220;append&#8221; (a) mode. When an administrator started THOR on a system, terminated the scan and then restarted it shortly after, the first part of the local log file was overwritten by the second scan. Sometimes a scan was interrupted on a system due to different reasons. When an administrator received the order to start a new scan on that system, the scan resumed the last scan and the log file and report contained only info of the resumed part of the scan.<\/p>\n<p>We therefore decided to not resume scans by default. If you still want to maintain the old behaviour, please use the new &#8220;&#8211;resume&#8221; parameter. The old &#8220;&#8211;noresume&#8221; parameter is still valid but has no effect and is marked &#8220;obsolete&#8221; in the help.<\/p>\n<h2>Analysis Cockpit Web Session<\/h2>\n<p>We&#8217;ve just recently published a <a href=\"https:\/\/www.youtube.com\/watch?v=00aGUm-hKhs\">web session<\/a> that gives an overview on our whole product portfolio and describes the features of our Analysis Cockpit in detail. (18 minutes, English language)<\/p>\n<p>The main features of the Analysis Cockpit are:<\/p>\n<ul>\n<li>THOR \/ SPARK Log Baselining<\/li>\n<li>Automatic case creation based on similarities of the events<\/li>\n<li>Filtered Forwarding of Logs to a SIEM system<\/li>\n<\/ul>\n<p><iframe loading=\"lazy\"  width=\"1080\" height=\"608\" frameborder=\"0\" allow=\"autoplay; encrypted-media\" allowfullscreen consent-original-src-_=\"https:\/\/www.youtube.com\/embed\/00aGUm-hKhs?feature=oembed\" consent-required=\"10314\" consent-by=\"services\" consent-id=\"10315\" consent-click-original-src-_=\"https:\/\/www.youtube.com\/embed\/00aGUm-hKhs?feature=oembed&amp;autoplay=1\"><\/iframe><\/p>\n<h2><\/h2>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>There are a few relevant changes in the upcoming THOR version 8.49.0 that we would like to announce. Interpreter and Module Upgrades The integrated Python interpreter will be upgraded to Version 2.7.15. We have also upgraded several modules. All our tests showed no signs of problems even with the oldest Windows version like Windows 2003 Server. (officially unsupported) If you encounter any issues, please let us know. 4th Generation License Format Support THOR 8.49.0 supports the newest license format which allows us to: set a start date for the period of validity enable or disable certain modules and features in THOR and SPARK (e.g. we could license a SPARK version that only scans endpoint logs with Sigma rules) THOR-util Report Generation The new included THOR-util version 1.2 allows to generate HTML reports from scan log files. It can also generate reports for a directory that contains THOR or SPARK scan logs (up to 50 per HTML report). We&#8217;ve discussed this feature in detail in a previous blog post. Noresume Becomes the New Default The Scan Resume feature has caused many problems during incident response engagements in the past. The feature activates a journal in THOR DB that tracks the state [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"There are a few relevant changes in the upcoming THOR version 8.49.0 that we would like to announce.\r\n<h2>Interpreter and Module Upgrades<\/h2>\r\nThe integrated Python interpreter will be upgraded to Version 2.7.15. We have also upgraded several modules. All our tests showed no signs of problems even with the oldest Windows version like Windows 2003 Server. (officially unsupported)\r\n\r\nIf you encounter any issues, please let us know.\r\n<h2>4th Generation License Format Support<\/h2>\r\nTHOR 8.49.0 supports the newest license format which allows us to:\r\n<ul>\r\n \t<li>set a start date for the period of validity<\/li>\r\n \t<li>enable or disable certain modules and features in THOR and SPARK\r\n(e.g. we could license a SPARK version that only scans endpoint logs with Sigma rules)<\/li>\r\n<\/ul>\r\n<h2>THOR-util Report Generation<\/h2>\r\nThe new included THOR-util version 1.2 allows to generate HTML reports from scan log files. It can also generate reports for a directory that contains THOR or SPARK scan logs (up to 50 per HTML report). We've discussed this feature in detail in a previous <a href=\"http:\/\/nextron.bsk-consulting.de\/2018\/06\/20\/thor-util-with-html-report-generation\/\">blog post<\/a>.\r\n\r\n<a href=\"http:\/\/nextron.bsk-consulting.de\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54.png\"><img class=\"alignnone size-full wp-image-3550\" src=\"http:\/\/nextron.bsk-consulting.de\/wp-content\/uploads\/2018\/06\/Screen-Shot-2018-06-20-at-16.27.54.png\" alt=\"\" width=\"1383\" height=\"961\" \/><\/a>\r\n<h2>Noresume Becomes the New Default<\/h2>\r\nThe Scan Resume feature has caused many problems during incident response engagements in the past. The feature activates a journal in THOR DB that tracks the state of the scan and resumes the scan automatically if it was interrupted by a user or terminated due to a system shutdown. This feature seemed to be helpful but actually caused some problems.\r\n\r\nTHOR logs are created in \"write\" (w) mode, not in \"append\" (a) mode. When an administrator started THOR on a system, terminated the scan and then restarted it shortly after, the first part of the local log file was overwritten by the second scan. Sometimes a scan was interrupted on a system due to different reasons. When an administrator received the order to start a new scan on that system, the scan resumed the last scan and the log file and report contained only info of the resumed part of the scan.\r\n\r\nWe therefore decided to not resume scans by default. If you still want to maintain the old behaviour, please use the new \"--resume\" parameter. The old \"--noresume\" parameter is still valid but has no effect and is marked \"obsolete\" in the help.\r\n<h2>Analysis Cockpit Web Session<\/h2>\r\nWe've just recently published a <a href=\"https:\/\/www.youtube.com\/watch?v=00aGUm-hKhs\">web session<\/a> that gives an overview on our whole product portfolio and describes the features of our Analysis Cockpit in detail. (18 minutes, English language)\r\n\r\nThe main features of the Analysis Cockpit are:\r\n<ul>\r\n \t<li>THOR \/ SPARK Log Baselining<\/li>\r\n \t<li>Automatic case creation based on similarities of the events<\/li>\r\n \t<li>Filtered Forwarding of Logs to a SIEM system<\/li>\r\n<\/ul>\r\n[embed]https:\/\/www.youtube.com\/watch?v=00aGUm-hKhs[\/embed]\r\n<h2><\/h2>","_et_gb_content_width":"","footnotes":""},"categories":[46,32],"tags":[],"class_list":["post-3624","post","type-post","status-publish","format-standard","hentry","category-newsletter","category-thor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>THOR Version 8.49.0 Changes - Nextron Systems<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\"},\"author\":{\"name\":\"Florian Roth\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919\"},\"headline\":\"THOR Version 8.49.0 Changes\",\"datePublished\":\"2018-07-27T11:52:26+00:00\",\"dateModified\":\"2022-03-25T13:15:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\"},\"wordCount\":509,\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"articleSection\":[\"Newsletter\",\"THOR\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\",\"url\":\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\",\"name\":\"THOR Version 8.49.0 Changes - Nextron Systems\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#website\"},\"datePublished\":\"2018-07-27T11:52:26+00:00\",\"dateModified\":\"2022-03-25T13:15:04+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.nextron-systems.com\/#website\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"name\":\"Nextron Systems\",\"description\":\"We Detect Hackers\",\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.nextron-systems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\",\"name\":\"Nextron Systems GmbH\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"contentUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"width\":260,\"height\":260,\"caption\":\"Nextron Systems GmbH\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919\",\"name\":\"Florian Roth\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g\",\"caption\":\"Florian Roth\"},\"description\":\"Florian Roth serves as the Head of Research and Development at Nextron Systems. With a background in IT security since 2000, he has delved deep into nation-state cyber attacks since 2012. Florian has developed the THOR Scanner and actively engages with the community via his Twitter handle @cyb3rops. He has contributed to open-source projects, including 'Sigma', a generic SIEM rule format, and 'LOKI', an open-source scanner. Additionally, he has shared valuable resources like a mapping of APT groups and operations and an Antivirus Event Analysis Cheat Sheet.\",\"url\":\"https:\/\/www.nextron-systems.com\/author\/florian\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"THOR Version 8.49.0 Changes - Nextron Systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/#article","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/"},"author":{"name":"Florian Roth","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919"},"headline":"THOR Version 8.49.0 Changes","datePublished":"2018-07-27T11:52:26+00:00","dateModified":"2022-03-25T13:15:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/"},"wordCount":509,"publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"articleSection":["Newsletter","THOR"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/","url":"https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/","name":"THOR Version 8.49.0 Changes - Nextron Systems","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/#website"},"datePublished":"2018-07-27T11:52:26+00:00","dateModified":"2022-03-25T13:15:04+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.nextron-systems.com\/2018\/07\/27\/thor-version-8-49-0-changes\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.nextron-systems.com\/#website","url":"https:\/\/www.nextron-systems.com\/","name":"Nextron Systems","description":"We Detect Hackers","publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.nextron-systems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.nextron-systems.com\/#organization","name":"Nextron Systems GmbH","url":"https:\/\/www.nextron-systems.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","contentUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","width":260,"height":260,"caption":"Nextron Systems GmbH"},"image":{"@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919","name":"Florian Roth","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g","caption":"Florian Roth"},"description":"Florian Roth serves as the Head of Research and Development at Nextron Systems. With a background in IT security since 2000, he has delved deep into nation-state cyber attacks since 2012. Florian has developed the THOR Scanner and actively engages with the community via his Twitter handle @cyb3rops. He has contributed to open-source projects, including 'Sigma', a generic SIEM rule format, and 'LOKI', an open-source scanner. Additionally, he has shared valuable resources like a mapping of APT groups and operations and an Antivirus Event Analysis Cheat Sheet.","url":"https:\/\/www.nextron-systems.com\/author\/florian\/"}]}},"_links":{"self":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/3624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/comments?post=3624"}],"version-history":[{"count":5,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/3624\/revisions"}],"predecessor-version":[{"id":7283,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/3624\/revisions\/7283"}],"wp:attachment":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/media?parent=3624"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/categories?post=3624"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/tags?post=3624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}