Announcing the Release of ASGARD Management Center v4.0

by May 18, 2026

With ASGARD Management Center 4.0, we are releasing a major update that represents an important technological step forward. In addition to functional enhancements and new platform capabilities, this version introduces fundamental architectural changes, including API-related breaking changes, that lay the foundation for future development. Please review the “Important Upgrade Notes” section as well as the official API Migration Guide and Database Migration Guide before upgrading.

Important Upgrade Notes

ASGARD Management Center 4.0 introduces several structural and technical changes required to ensure a modern, scalable, and future-proof platform architecture. All existing installations are automatically migrated during the upgrade process.

Key changes include:

  • Migration to UUIDs as primary keys for core entities such as assets, scans, users, roles, and MISP data (previous IDs remain available for reference through dedicated legacy fields)
  • Updated API endpoints using UUIDs instead of numeric IDs
  • Configuration migration from key-value pairs to a structured YAML-based configuration
  • New version pinning-based update management for THOR and Aurora products
  • Revised endpoint license handling, automatically returning inactive licenses to the pool after 90 days
  • Playbook upload migration from tar.gz to ZIP format, including optional ZIP encryption support
  • Removal of deprecated components such as Bifrost and LogWatcher

Please review the official documentation carefully before upgrading:

Highlights

Prepared for THOR 11

ASGARD Management Center 4.0 already includes support for the upcoming THOR 11, expected to be released in 2026.

This includes revised scan flags, updated output formats, and a reworked THOR versioning and update server layout, ensuring the platform is ready for the next generation of THOR.

Official AIX Support

With version 4.0, AIX is now officially supported. This is achieved through a new ASGARD Agent for AIX and a dedicated THOR for AIX scanner, which operates under its own license type. This significantly expands platform coverage for enterprise environments.

Software Inventory

A new Software Inventory provides centralized visibility into installed software across all assets. The inventory is available in both per-asset and aggregated views and allows searching and filtering of installed software directly within asset details. This greatly improves transparency, compliance assessments, and operational oversight.

Live Event Streaming to Analysis Cockpit

ASGARD Management Center 4.0 introduces live event streaming of THOR events directly to ASGARD Analysis Cockpit. Events are forwarded in real time and become available for analysis while scans are still running. This feature can be enabled for single, group, and scheduled scans and is particularly valuable for time-critical incident response workflows.

Improved Version Pinning and Update Control

Version 4.0 introduces a more flexible version pinning system for THOR and Aurora products. Administrators can now define version constraints such as specific major or minor release branches, enabling more controlled and predictable update management across enterprise environments.

Encrypted Evidence Collection

Playbook-based evidence collection has been enhanced with support for password-protected ZIP archives.This improves the secure handling and transfer of collected forensic artifacts and investigation data.

THOR for Legacy

New license type “THOR for Legacy” has been added to support scanning older Windows and Linux systems no longer covered by standard THOR. The Asgard Management Center can now issue Legacy licenses, with full Legacy support planned for an upcoming release, in which the agent will automatically determine whether a system should be scanned using THOR or THOR Legacy and which license type is required.

Improvements

ASGARD Management Center 4.0 also includes a range of targeted improvements:

  • Internal UUID storage for MISP entities while preserving original source IDs
  • Cleaner scan views by hiding unset scan arguments
  • Improved security standards for API key storage
  • Support for assigning custom scores to hash and C2 IOCs
  • Diagnostics packages can now only be generated and downloaded by admin users

In addition, numerous backend, operational, and usability improvements have been implemented across the platform.

Bugfixes

Version 4.0 also delivers numerous bug fixes and stability improvements, including fixes related to licensing, file handling, playbooks, agents, and scan execution behavior. A complete list of resolved issues is available in the official changelog.

Conclusion

ASGARD Management Center 4.0 is a major release that combines important platform updates with new capabilities for enterprise environments.

With features such as Software Inventory, Live Event Streaming, improved version management, AIX support, and preparation for THOR 11, version 4.0 extends the Management Center’s capabilities and improves day-to-day operations for administrators and security teams.

We recommend reviewing the migration documentation carefully and planning the upgrade accordingly.

Customers will continue to receive information about future improvements, updates, and platform developments through our blog posts, changelogs, and product update announcements.

Further Information

For more details, please refer to our manual, which provides comprehensive guidance on all the new features, breaking changes, and upgrade considerations.

You can also contact our support team for further assistance.

Additional documentation, upgrade resources, and frequently asked questions can be found here:

About the author:

Avatar photo

Boris Deibel

Boris Deibel is Director Product Management & Development at Nextron Systems. In this role, he leads the development department and oversees product management for the ASGARD product family.

Subscribe to our Newsletter

Monthly news, tips and insights.

Follow Us

Upgrade Your Cyber Defense with THOR

Detect hacker activity with the advanced APT scanner THOR. Utilize signature-based detection, YARA rules, anomaly detection, and fileless attack analysis to identify and respond to sophisticated intrusions.