Detection and monitoring EU-developed
ASGARD Management Center
Incident-response console that deploys agents, schedules compromise scans, manages indicators, collects evidence, and executes response playbooks across endpoints.
By Nextron Systems · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
At a glance
Recorded facts- Response workflow
- Detection and monitoring
- Developer or maintainer
- Nextron Systems
- Recorded country
- Germany
- Product model
- Commercial
- Deployment
- Self-hosted
- Software license
- Commercial license; full terms not publicly verified
- Upstream status
- Active
- Evidence class
- EU-developed
What the sources establish
Origin noteNextron's German engineering team created the THOR/ASGARD product line and remains the named steward; exact locations of all current contributors are unpublished.
Reported capabilities
- Controls endpoint scans and custom indicator checks.
- Runs response playbooks for quarantine, collection, and remote commands.
- Ships as a hardened virtual appliance.
Scope and limits
ASGARD is separately deployable and integrates THOR scanning. Vendor installer documentation requires a product-matched license; full current end-user rights were not publicly readable.
Inspect the research evidence 4 source observations
identity / capabilities / deployment
Nextron describes ASGARD as a virtual appliance with endpoint agents, IOC management and response playbooks, offered as its commercial incident-response platform.
Read sourceorigin / country
The Nextron company history traces creation of the company's scanner and response software to its German founders and identifies German stewardship.
Read sourcelicense
Nextron's current self-hosted Management Center migration guide requires customer-portal access and a valid, activated license; public full license terms were not found.
Read sourcemaintenance
Nextron’s Management Center support index dates version 4.2.1 to 29 September 2026.
Read source
This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Capabilities & integrations
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
No structured capability or integration evidence has been added for this tool in the current pass. This does not establish that a feature is unsupported. Send a documentation link.
Put the tool in context.
Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.
From Sigma rule to a tested detection