Projects

Open source tools for threat detection and security research.

33 projects

APTSimulator screenshot

APTSimulator

active

A toolset to make a system look as if it was the victim of an APT attack

apt

asgard-playbooks

active

asgard-playbooks - Python project

security

aurora-helpers

active

Helper scripts and configs to be used with Aurora Agent

security

binaryalert

active

BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

detectionmalware

Cortex-Analyzers

active

Cortex Analyzers for Nextron Products

security
evtx-baseline screenshot

evtx-baseline

active

A repository hosting example goodware evtx logs containing sample software installation and basic user interaction

go
gimphash screenshot

gimphash

active

Imphash-like calculation on Golang binaries

go

go-elasticsearch

active

Simple ElasticSearch API for Golang

apiclientelasticsearchgogo-elasticsearch

go-handle

active

Iterate over Windows Handles

windowsgo
go-ntlm-proxy-auth screenshot

go-ntlm-proxy-auth

active

Authorize to an NTLM Proxy for a HTTP(S) connection in Golang

go

go-osversion

active

Detect version of running os

go

go-priority

active

Manipulate the priority of the GO program

go

go-taskscheduler

active

Connect to Windows Task Scheduler 2.0 with Golang

windowsgo

iocs

active

Indicators of compromise from to analysis and research by Nextron Threat Research team

iocthreat-hunting

jsonlog

active

Definitions of structures used in THOR JSON logs

security

nextron-helper-scripts

active

Public tools, scripts or code snippets that can help when working with our products

security
openrelik-worker-thor-lite screenshot

openrelik-worker-thor-lite

active

openrelik-worker-thor-lite - Python project

security
postfix2thunderstorm screenshot

postfix2thunderstorm

active

Postfix 2 Thor Thunderstorm

security
ransomware-simulator screenshot

ransomware-simulator

active

Ransomware simulator written in Golang

go

scanning-containers

active

Guides and scripts for different uses cases regarding scanning containers with THOR

documentation

scanning-sql-databases

active

Guides and scripts for different uses cases regarding scanning SQL databases with THOR

documentation
simplesyslog screenshot

simplesyslog

active

Simple SYSLOG client in Go

goclient

sysmon-config

active

Sysmon configuration file template with default high-quality event tracing

security
TA-aurora screenshot

TA-aurora

active

Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR Agent Alerts into Splunk.

security

thor-microsoft-defender-guide

active

THOR Integration Guide for Microsoft Defender ATP

documentationintegration

thor-plugin

active

Plugin interface for THOR APT Scanner

scannerapt
thor2timesketch screenshot

thor2timesketch

active

thor2ts – A utility to convert THOR logs to Timesketch’s required format.

security
thunderstorm-collector screenshot

thunderstorm-collector

active

THOR Thunderstorm Collectors

security

thunderstormAPI

active

Python module to interact with THOR Thunderstorm service

pythonapi

valhallaAPI

active

Valhalla API Client

apiclient
veeam-integration screenshot

veeam-integration

active

Integration of THOR into Veeam Backup & Replication

integration

velociraptor-artifacts-thor

active

Thor Artifacts for Velociraptor

apt
yaramod screenshot

yaramod

active

Parsing of YARA rules into AST and building new rulesets in C++.

yara