{"id":6784,"date":"2020-03-02T15:41:25","date_gmt":"2020-03-02T14:41:25","guid":{"rendered":"https:\/\/www.nextron-systems.com\/?p=5381"},"modified":"2022-03-25T14:14:58","modified_gmt":"2022-03-25T13:14:58","slug":"upcoming-asgard-version-2","status":"publish","type":"post","link":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/","title":{"rendered":"Upcoming ASGARD Version 2"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_row column_structure=&#8221;2_5,3_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<p>The last five months we&#8217;ve been working on a shiny new version of our ASGARD platform that overcomes previous limitations and includes exciting new features.<\/p>\n<p>ASGARD 2 is a completely rewritten management platform, featuring a new interface, load balancing options, a new lightweight agent, custom response playbooks and greatly improved IOC management.<\/p>\n<p>&nbsp;<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2020\/02\/Screenshot-2020-02-25-at-14.57.39-1024&#215;833.png&#8221; _builder_version=&#8221;4.4.1&#8243; hover_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<h3>Fundamental Changes<\/h3>\n<ul>\n<li><span style=\"font-size: 18px;\">Easy to use GUI and API for response functions (replaces GRR as underlying framework)<\/span><\/li>\n<li>Rewritten agents consume much less memory<\/li>\n<li>New dynamic agent load control allows to connect up to 25,000 endpoints<\/li>\n<li>Predefined and custom playbooks<\/li>\n<li>IOC management support for MISP<\/li>\n<li>Remote consoles<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_3,2_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<h3>IOC Management<\/h3>\n<p>The new IOC management allows to interface with a MISP instance and create rule sets based on filters.<\/p>\n<p>For example, you can search for and select all MISP events containing the keyword &#8220;Emotet&#8221;, create a new rule set from them and\u00a0then select this rule set to be used in a new THOR scan.\u00a0<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2020\/03\/Screenshot-2020-03-02-at-13.57.24.png&#8221; _builder_version=&#8221;4.4.1&#8243; hover_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;1_3,2_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;1_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<h3>Playbooks<\/h3>\n<p>The so-called playbooks allow you to define a set of steps that the agent executes on an end system.\u00a0<\/p>\n<p>Each playbook can have up to 16 independant steps of the types &#8220;Run Command Line&#8221;, &#8220;Download File&#8221; or &#8220;Upload File&#8221;.<\/p>\n<p>It is easy to set up new playbooks that e.g. download a certain tool to the endpoints, run it and collect the generated output.\u00a0<\/p>\n<p>Each or all results of playbook executions can be collected via GUI or API.\u00a0<span style=\"font-size: 18px;\">Playbooks can be triggered via API to allow the integration into security orchestration, automation and response (SOAR) solutions.\u00a0<\/span><\/p>\n<p>ASGARD v2 ships with a set of predefined playbooks including:\u00a0<\/p>\n<ul>\n<li>Collect system memory<\/li>\n<li>Collect file or folders<\/li>\n<li>Quarantine endpoint<\/li>\n<li>Collect triage package<\/li>\n<li>Collect process tree\u00a0<\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_3&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2020\/03\/Screenshot-2020-03-02-at-15.16.32.png&#8221; _builder_version=&#8221;4.4.1&#8243; hover_enabled=&#8221;0&#8243;][\/et_pb_image][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2020\/03\/Screenshot-2020-03-02-at-14.06.32.png&#8221; _builder_version=&#8221;4.4.1&#8243; hover_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<h3>Remote Console<\/h3>\n<p>The remote console allows you to open up a web based command line window on any attached end system. This greatly facilitates the analysis of suspicious events. Analysts can browse the remote system, review or change settings and\u00a0issue commands.<\/p>\n<p>During the session, you can select files for collection or define certain playbooks to be executed after disconnecting the command line session.<\/p>\n<p>Every session gets recorded for complete traceability.<\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_image src=&#8221;https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2020\/03\/Screenshot-2020-03-02-at-13.55.59.png&#8221; _builder_version=&#8221;4.4.1&#8243; hover_enabled=&#8221;0&#8243;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.3.4&#8243;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.3.4&#8243;][et_pb_text _builder_version=&#8221;4.3.4&#8243;]<\/p>\n<h3>Time Schedule<\/h3>\n<p>Beta customers will test drive ASGARD v2 in March and April. We expect a first release in June.<\/p>\n<p>An upgrade guide for ASGARD v1 customers will be provided.\u00a0<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The last five months we&#8217;ve been working on a shiny new version of our ASGARD platform that overcomes previous limitations and includes exciting new features. ASGARD 2 is a completely rewritten management platform, featuring a new interface, load balancing options, a new lightweight agent, custom response playbooks and greatly improved IOC management. &nbsp;Fundamental Changes Easy to use GUI and API for response functions (replaces GRR as underlying framework) Rewritten agents consume much less memory New dynamic agent load control allows to connect up to 25,000 endpoints Predefined and custom playbooks IOC management support for MISP Remote consoles IOC Management The new IOC management allows to interface with a MISP instance and create rule sets based on filters. For example, you can search for and select all MISP events containing the keyword &#8220;Emotet&#8221;, create a new rule set from them and\u00a0then select this rule set to be used in a new THOR scan.\u00a0Playbooks The so-called playbooks allow you to define a set of steps that the agent executes on an end system.\u00a0 Each playbook can have up to 16 independant steps of the types &#8220;Run Command Line&#8221;, &#8220;Download File&#8221; or &#8220;Upload File&#8221;. It is easy to set up new playbooks that [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[35,46],"tags":[76,244,66,82,119,245,246,217,117,5],"class_list":["post-6784","post","type-post","status-publish","format-standard","hentry","category-asgard-management-center","category-newsletter","tag-asgard","tag-collect-memory","tag-incident-response","tag-ioc","tag-management","tag-misp","tag-playbooks","tag-sandbox","tag-scan","tag-thor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Upcoming ASGARD Version 2 - Nextron Systems<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\"},\"author\":{\"name\":\"Florian Roth\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919\"},\"headline\":\"Upcoming ASGARD Version 2\",\"datePublished\":\"2020-03-02T14:41:25+00:00\",\"dateModified\":\"2022-03-25T13:14:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\"},\"wordCount\":694,\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"keywords\":[\"asgard\",\"collect memory\",\"incident response\",\"ioc\",\"Management\",\"MISP\",\"playbooks\",\"sandbox\",\"scan\",\"thor\"],\"articleSection\":[\"ASGARD Management Center\",\"Newsletter\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\",\"url\":\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\",\"name\":\"Upcoming ASGARD Version 2 - Nextron Systems\",\"isPartOf\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#website\"},\"datePublished\":\"2020-03-02T14:41:25+00:00\",\"dateModified\":\"2022-03-25T13:14:58+00:00\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.nextron-systems.com\/#website\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"name\":\"Nextron Systems\",\"description\":\"We Detect Hackers\",\"publisher\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.nextron-systems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.nextron-systems.com\/#organization\",\"name\":\"Nextron Systems GmbH\",\"url\":\"https:\/\/www.nextron-systems.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"contentUrl\":\"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png\",\"width\":260,\"height\":260,\"caption\":\"Nextron Systems GmbH\"},\"image\":{\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919\",\"name\":\"Florian Roth\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g\",\"caption\":\"Florian Roth\"},\"description\":\"Florian Roth serves as the Head of Research and Development at Nextron Systems. With a background in IT security since 2000, he has delved deep into nation-state cyber attacks since 2012. Florian has developed the THOR Scanner and actively engages with the community via his Twitter handle @cyb3rops. He has contributed to open-source projects, including 'Sigma', a generic SIEM rule format, and 'LOKI', an open-source scanner. Additionally, he has shared valuable resources like a mapping of APT groups and operations and an Antivirus Event Analysis Cheat Sheet.\",\"url\":\"https:\/\/www.nextron-systems.com\/author\/florian\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Upcoming ASGARD Version 2 - Nextron Systems","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/#article","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/"},"author":{"name":"Florian Roth","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919"},"headline":"Upcoming ASGARD Version 2","datePublished":"2020-03-02T14:41:25+00:00","dateModified":"2022-03-25T13:14:58+00:00","mainEntityOfPage":{"@id":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/"},"wordCount":694,"publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"keywords":["asgard","collect memory","incident response","ioc","Management","MISP","playbooks","sandbox","scan","thor"],"articleSection":["ASGARD Management Center","Newsletter"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/","url":"https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/","name":"Upcoming ASGARD Version 2 - Nextron Systems","isPartOf":{"@id":"https:\/\/www.nextron-systems.com\/#website"},"datePublished":"2020-03-02T14:41:25+00:00","dateModified":"2022-03-25T13:14:58+00:00","inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.nextron-systems.com\/2020\/03\/02\/upcoming-asgard-version-2\/"]}]},{"@type":"WebSite","@id":"https:\/\/www.nextron-systems.com\/#website","url":"https:\/\/www.nextron-systems.com\/","name":"Nextron Systems","description":"We Detect Hackers","publisher":{"@id":"https:\/\/www.nextron-systems.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.nextron-systems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.nextron-systems.com\/#organization","name":"Nextron Systems GmbH","url":"https:\/\/www.nextron-systems.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","contentUrl":"https:\/\/www.nextron-systems.com\/wp-content\/uploads\/2017\/11\/Nextron_0.2s_inv_symbol_only.png","width":260,"height":260,"caption":"Nextron Systems GmbH"},"image":{"@id":"https:\/\/www.nextron-systems.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/4fd503007d60aabaf1ae747502f36919","name":"Florian Roth","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.nextron-systems.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0dfaa838ce5d82e2e7bfa75ed3f43ae5?s=96&d=mm&r=g","caption":"Florian Roth"},"description":"Florian Roth serves as the Head of Research and Development at Nextron Systems. With a background in IT security since 2000, he has delved deep into nation-state cyber attacks since 2012. Florian has developed the THOR Scanner and actively engages with the community via his Twitter handle @cyb3rops. He has contributed to open-source projects, including 'Sigma', a generic SIEM rule format, and 'LOKI', an open-source scanner. Additionally, he has shared valuable resources like a mapping of APT groups and operations and an Antivirus Event Analysis Cheat Sheet.","url":"https:\/\/www.nextron-systems.com\/author\/florian\/"}]}},"_links":{"self":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/6784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/comments?post=6784"}],"version-history":[{"count":2,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/6784\/revisions"}],"predecessor-version":[{"id":6926,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/posts\/6784\/revisions\/6926"}],"wp:attachment":[{"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/media?parent=6784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/categories?post=6784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.nextron-systems.com\/wp-json\/wp\/v2\/tags?post=6784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}