1.1. Introduction
The Analysis Cockpit is the central platform for analyzing THOR events and SIGMA matches generated by your THOR scanner.
It can be used in an environment where scans results can be automatically collected from Management Centers or environments in which THOR is executed by scripts or any other 3rd party solution. An active integration with THOR Cloud can also be used to fetch events from your Cloud tenant.
While THOR can also be seen or used as hunting solution, THOR is optimized to avoid false negatives - meaning optimized to not miss an indicator of compromise. On the other side this clearly leads to more anomalies and false positives being reported.
In a scenario where you scan your infrastructure frequently you would either be seeing the same anomalies again and again or you would need to create many rules to filter out these anomalies in order to save analysis time.
Analysis Cockpit is designed to facilitate this process and help you generate these rules automatically, so that you can set your baseline-filters after the first scan. After setting the first baseline it is now easy to focus on relevant Alerts and Warnings as only differences between the first and second scans are shown.
Furthermore, Analysis Cockpit comes with a rule-based alert forwarding and SIEM integration that makes it easy for your organization to react quickly on new incidents. For organizations or projects where a SIEM system is not available, Analysis Cockpit features a separate notification section to deal with alerts and notifications you would normally process in a SIEM system.
The following document describes requirements, the installation process and best practices to group, classify and dispatch events for further analysis.