The difficult part begins when an AI system is allowed to change production. Over the last few weeks, I have had the same discussion several times. Public reports increasingly describe AI being used across large parts of an intrusion. The obvious question is: Where is...
New in THOR Cloud: SSO, Granular Permissions, and Account API Keys
This update adds: OIDC SSO with group-based role mapping, configurable roles and permissions, campaign-scoped access, and more secure personal and account-wide API keys. Enterprise Access Control for THOR Cloud THOR Cloud now includes a major update to identity and...
Detecting Certighost (CVE-2026-54121): Sigma Coverage Across the Full Attack Chain
Many organizations rely on Microsoft Active Directory to manage users, computers, logins, and access permissions. Domain Controllers are the central systems that enforce these decisions. In many environments, Active Directory Certificate Services is used alongside...
ASGARD Management Center 4.1: More Resilient. More Secure. Ready for THOR 11
The latest release strengthens the enterprise management platform for THOR with more resilient endpoint connectivity, enhanced platform security, and new capabilities that make enterprise-scale THOR operations even more resilient, secure, and efficient. THOR is...
Anatomy of a WHQL-Signed Windows Filtering Platform (WFP) Kernel-Resident Network Backdoor
A signed kernel driver is one of the most powerful execution primitives available on Windows. Once loaded, it operates with unrestricted access to memory, processes, filesystems, and network traffic. wskmon.sys takes full advantage of that position. Rather than acting...
From 114,000 OSS Artifacts to 100 Analyst Reviews a Day with THOR Thunderstorm
How we combined THOR Thunderstorm's rule-based detection with LLM triage to reduce 114,000 daily artifacts to about 4,600 initial model reviews and roughly 100 analyst reviews, while reserving RuneAI for analyst-initiated deep analysis. The problem: you can't afford...
New THOR Cloud Log Inspection View
Faster. Cleaner. More focused review. Reviewing large THOR scan reports can be time-consuming, especially when analysts need to quickly understand why a detection was triggered, identify the affected artifact, and separate signal from noise. To make this process...
Detecting Nimbus Manticore and their sideloading infection chains
During a recent incident, we identified a sophisticated sideloading infection chain dropping a custom implant for data exfiltration. Further analysis allowed us to attribute the activity to the Iran-nexus APT group Nimbus Manticore, also tracked as UNC1549 and Smoke...
Nextron Systems Welcomes New Majority Investor Eurazeo
A New Chapter for Nextron Systems Today marks an important milestone in the journey of Nextron Systems. When we founded the company in 2017, we shared a simple but ambitious goal: to close the visibility gaps left by traditional security tooling and help defenders...
Announcing the Release of ASGARD Management Center v4.0
With ASGARD Management Center 4.0, we are releasing a major update that represents an important technological step forward. In addition to functional enhancements and new platform capabilities, this version introduces fundamental architectural changes, including...
Nextron Systems Supports Locked Shields Cyber Defence Exercise
Nextron Systems supports teams participating in Locked Shields, one of the most advanced and large-scale live-fire cyber defence exercises. Organised by the NATO Cooperative Cyber Defence Centre of Excellence (CCDCOE), the exercise brings together multinational blue...
The AIX Blind Spot – Getting Visibility Where EDR Can’t Run
AIX is still running critical workloads in finance, manufacturing, and other industries that value stability over frequent platform churn. The uncomfortable part is that many security programs treat these systems as “special cases” - meaning they often end up outside...
RegPhantom Backdoor Threat Analysis
Executive Summary This report analyzes RegPhantom, a stealthy Windows kernel rootkit designed to give attackers code execution in kernel mode while leaving very little visible evidence behind. The malware abuses the Windows registry as a covert trigger mechanism: a...
Announcing the Release of ASGARD Analysis Cockpit v4.4
With ASGARD Analysis Cockpit 4.4, we deliver a release that clearly focuses on more efficient analysis, more precise searches, and better prioritization of relevant events. At its core, this version introduces a powerful new query language, complemented by targeted...
Free Converter Software – Convert Any System from Clean to Infected in Seconds
Over the past few months, we have analyzed many infection chains that all start in a very similar way: malicious advertisements placed on legitimate websites. These ads lure users into downloading "converter" tools that promise to convert images or documents (for...














