logo

Thorium 101: Inside CISA’s Open Source Malware Analysis Platform

ID: 182922ea-4a88-5f6b-9aed-37136788f029

STIX ID: report--182922ea-4a88-5f6b-9aed-37136788f029

Feed Name: Pulsedive Blog

Date Published: 2025-09-10

Date Updated: 2026-04-28

Author: Pulsedive Threat Research

...
...

This blog introduces CISA’s Thorium, an open-source, scalable malware analysis and data generation platform intended to streamline triage and incident response by centralizing tools, storage, and automation. It outlines key features (static/dynamic analysis, REST APIs, multi-tenancy, tagging, full-text search), secure file handling via CaRT, a Kubernetes-based architecture (API, scaler, agent, reactor, tracing, event handler) with storage backends, and deployment options including a Minikube-based “Minithor” for testing. The post also explains roles and group permissions, file origin metadata, Images (tools) and Pipelines for automation, and the thorctl CLI for uploading/downloading files, starting reactions, and retrieving results, positioning Thorium as a customizable platform for team workflows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.