Hot Take THOR Cloud Lite Release Session

upnorth

Level 68
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,403
2
65,358
6,699
Sweden

  • Introduction to THOR Cloud Lite
  • Overview of deployment options
  • Demonstration of the web interface, including campaign creation
  • Custom IOCs (Indicators of Compromise) setup
  • Explanation of essential settings
  • Exploration of different THOR Cloud launcher options
THOR Cloud eliminates the need for on-premise systems for licensing and scanner package downloads. With THOR Cloud, all you need is a small yet powerful tool known as the THOR Cloud launcher. Simply bring it to your endpoint or allow end users to download and execute it themselves.

This launcher serves as the core of a comprehensive on-demand forensic investigation, powered by our advanced scanner, THOR. Equipped with over 20,000 pre-built signatures designed to detect various traces of hacking activity, THOR ensures thorough analysis and identification of potential security threats.
 
Client/Endpoint:

2023-11-05_20-12-30.png
 
@upnorth are you going to provide us with your opinion of this software? :unsure:
Since I'm testing it at the moment sure I can, but just to be as clear as possible. It's a security cloud service ( work in progress ) where one download a binary file from and then execute/run that file on a machine with either Windows, Linux or MacOS. It then shows the progress in the default set browser as seen in the screenshot ( Edge on that specific system ). At the moment running as a SOS ( second opinion scanner ) on a guest VM with Windows 10.

I can not recommend this for normal home users, as for example the integration with the business/enterprise version of Microsoft 365 and Defender ATP automatic make this far out of scope. Also the upcoming features for connection with SEIM solutions such as Splunk and SENTINAL etc, should hopefully explain more.
 
Since I'm testing it at the moment sure I can, but just to be as clear as possible. It's a security cloud service ( work in progress ) where one download a binary file from and then execute/run that file on a machine with either Windows, Linux or MacOS. It then shows the progress in the default set browser as seen in the screenshot ( Edge on that specific system ). At the moment running as a SOS ( second opinion scanner ) on a guest VM with Windows 10.

I can not recommend this for normal home users, as for example the integration with the business/enterprise version of Microsoft 365 and Defender ATP automatic make this far out of scope. Also the upcoming features for connection with SEIM solutions such as Splunk and SENTINAL etc, should hopefully explain more.
good info, thanks!!
 
Latest test done with a MacBook Air as the client, browser Opera.

Opera Snapshot_2023-11-30_201849_thorcloud-lite.nextron-systems.com.png


Skärmavbild 2023-11-30 kl. 20.21.31.png


Found a possible bug as the launcher didn't execute as it should, and I was forced to manually find the correct file in the package. But in general this works fine also on macOS. The scan took around 15 minutes and the log did reveal 1 .js file that needs deeper analysis.

Will see if I'll test this later on also on Linux.
 

You may also like...