CISA released Thorium platform to support malware and forensic analysis
ID: 9a1f23ac-afa9-5151-a095-23d6e52d5a79
STIX ID: report--9a1f23ac-afa9-5151-a095-23d6e52d5a79
Feed Name: Security Affairs
CISA, in partnership with Sandia National Laboratories, released Thorium, an open-source, scalable platform that automates file analysis and aggregates results to support malware analysis, digital forensics, and incident response. Built on Kubernetes and ScyllaDB, Thorium can ingest over 10 million files per hour per permission group and schedule more than 1,700 jobs per second, while providing web, CLI, and REST API access. It integrates commercial, open-source, and custom tools via Docker, supports tagging and search, and enforces group-based permissions, enabling teams to streamline tool testing, malware analysis, and host forensics at scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
