{"id":7405,"date":"2025-01-22T09:00:00","date_gmt":"2025-01-22T09:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-3701-2\/"},"modified":"2026-07-04T12:24:21","modified_gmt":"2026-07-04T12:24:21","slug":"case-study-mid-sized-manufacturer-detects-apt-after-9-months-thanks-to-thor-scan","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2025\/01\/22\/case-study-mid-sized-manufacturer-detects-apt-after-9-months-thanks-to-thor-scan\/","title":{"rendered":"Case Study: Mid-Sized Manufacturer Detects APT After 9 Months  &#8211;  Thanks to THOR Scan"},"content":{"rendered":"<p><strong>A machinery manufacturing company discovered during a routine compromise assessment with THOR that attackers had been active in their network undetected for 9 months. The case shows: EDR alone is not enough.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<p>A machinery manufacturing company discovered during a routine compromise assessment with THOR from Nextron Systems that attackers had been active in their network undetected for 9 months. The APT group had exfiltrated design data and patent information. The case shows: EDR alone is not enough  &#8211;  regular compromise assessments are indispensable.<\/p>\n<h2>Initial Situation<\/h2>\n<p>The company is a specialist machinery manufacturer with 450 employees and locations in Germany, China, and the USA. The IT infrastructure was equipped with a well-known EDR product. There were no known security incidents.<\/p>\n<p>As part of an NIS2 preparation measure, the company commissioned a service provider to conduct a compromise assessment. THOR Full was used in combination with Velociraptor for centralized control.<\/p>\n<h2>What THOR Found<\/h2>\n<p>The scan of 320 endpoints and 40 servers delivered several critical findings within 48 hours:<\/p>\n<ul>\n<li><strong>Modified Windows system files<\/strong> on three engineering workstations (YARA match with known APT toolset)<\/li>\n<li><strong>Anomalous scheduled tasks<\/strong> for persistent backdoor communication<\/li>\n<li><strong>Sigma hits<\/strong> in Windows event logs: Suspicious lateral movement patterns over 9 months<\/li>\n<li><strong>Webshell<\/strong> on an internal web server used as a pivot point<\/li>\n<\/ul>\n<h2>Why the EDR Did Not Detect the Attack<\/h2>\n<p>The attackers used Living-off-the-Land techniques (LOLBins): Legitimate Windows tools such as PowerShell, certutil, and wmic for their activities. The EDR classified these executions as normal because they frequently occurred in the context of engineering software.<\/p>\n<p>THOR, on the other hand, did not look for suspicious executions but for the artifacts left behind by the attackers: modified files, suspicious registry entries, and log traces.<\/p>\n<h2>Scope of Compromise<\/h2>\n<p>The forensic analysis revealed:<\/p>\n<ul>\n<li>Initial access via a spear-phishing email to an engineer<\/li>\n<li>Lateral movement across 5 systems over 9 months<\/li>\n<li>Exfiltration of approximately 12 GB of design data and 3 patent applications<\/li>\n<li>No destructive damage (espionage, not sabotage)<\/li>\n<\/ul>\n<h2>Lessons Learned<\/h2>\n<ul>\n<li>EDR does not detect everything  &#8211;  especially LOLBin-based APTs are often overlooked<\/li>\n<li>Regular compromise assessments (at least semi-annually) find what EDR misses<\/li>\n<li>THOR + Velociraptor is a cost-effective combination for enterprise scans<\/li>\n<li>Engineering workstations are high-value targets and require special monitoring<\/li>\n<\/ul>\n<h2>Key Facts<\/h2>\n<p><strong>Industry:<\/strong> Machinery manufacturing<\/p>\n<p><strong>Attacker dwell time:<\/strong> 9 months<\/p>\n<p><strong>Detection by:<\/strong> THOR Compromise Assessment<\/p>\n<p><strong>Exfiltrated data:<\/strong> 12 GB design data, 3 patent applications<\/p>\n<p><strong>EDR was installed but did not detect the APT<\/strong><\/p>\n<p><strong>Fact:<\/strong> Mandiant estimates the average dwell time for APT attacks in 2024 at 10 days  &#8211;  but often over 200 days for undetected compromises.<\/p>\n<p><strong>Fact:<\/strong> According to CrowdStrike, the number of state-sponsored attacker groups has more than doubled since 2020  &#8211;  to over 230 active groups worldwide.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Why didn&#8217;t the EDR detect the APT?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The attackers used Living-off-the-Land techniques  &#8211;  legitimate Windows tools like PowerShell and certutil. EDR systems often do not recognize these as suspicious when they occur in the context of normal business processes.<\/p>\n<\/details>\n<details>\n<summary><strong>How often should compromise assessments be conducted?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">At least semi-annually for companies with a high risk profile. Additionally, after any suspected incident, during acquisitions (due diligence), and as a supplement to regular penetration tests.<\/p>\n<\/details>\n<details>\n<summary><strong>Why do APT attacks remain undetected for so long?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">APT groups use so-called Living-off-the-Land techniques, where they utilize legitimate system tools like PowerShell or WMI to move within the network. Since these tools are part of normal operations, they rarely trigger alarms. Only specialized compromise assessment tools like THOR detect the subtle traces of such attacks.<\/p>\n<\/details>\n<h2>Related Articles<\/h2>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2024\/01\/15\/post_id-3683\/\">NIS2 Directive: What Companies Need to Know<\/a><\/p>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/cyber-insurance-2026-what-companies-need-to-know-before-taking-out-a-policy\/\">Cyber Insurance 2026<\/a><\/p>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2024\/03\/05\/post_id-3671\/\">Zero Trust: The 7 Most Common Mistakes<\/a><\/p>\n<h2>Related Events<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/secit-by-heise-2026-the-security-roadshow-for-admins-and-it-professionals\/\">secIT by Heise 2026: The Security Roadshow for Admins and IT Decision-Makers<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/dsin-annual-congress-2026-digital-security-in-a-connected-society\/\">DsiN Annual Congress 2026: Digital Security in the Connected Society<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/05\/cybersec-europe-2026-brussels-security-conference-at-the-heart-of-eu-regulation\/\">Cybersec Europe 2026: Brussels&#8217; Security Conference at the Heart of EU Regulation<\/a><\/li>\n<\/ul>\n<p style=\"font-weight:700;color:#e6e3da;font-size:1.05em;margin:48px 0 16px;\">More from the MBF Media Network<\/p>\n<div style=\"display:flex;flex-direction:column;gap:14px;margin-bottom:40px;\"><a href=\"https:\/\/mybusinessfuture.com\/ki-made-in-germany-935-startups-oekosystem\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#aa8ac2;\">MyBusinessFuture<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">More IT security trends on mybusinessfuture.com<\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/149-000-offene-it-stellen-wie-cios-ki-copiloten-als-fachkraeftersatz-nutzen\/\" class=\"st-net-card\" style=\"display:block;padding:16px 18px;background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;\"><span style=\"display:block;margin-bottom:6px;font-size:0.72em;font-weight:700;letter-spacing:0.06em;text-transform:uppercase;color:#d65663;\">Digital Chiefs<\/span><span style=\"display:block;color:#e6e3da;line-height:1.45;\">IT strategies for decision-makers on digital-chiefs.de<\/span><\/a><\/div>\n","protected":false},"excerpt":{"rendered":"A machinery manufacturing company discovered during a routine compromise assessment with THOR that attackers had been active in their network undetected for 9 months. The case shows: EDR alone is not enough. TL;DR A machinery manufacturing company discovered during a routine compromise assessment with THOR from Nextron Systems that attackers had been active in their [&hellip;]","protected":false},"author":55,"featured_media":3700,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"apt","_yoast_wpseo_title":"Case Study: Mid-Sized Manufacturer Detects APT After 9 Months - Thanks to THOR","_yoast_wpseo_metadesc":"APT detection in 9 months: How a mid-sized manufacturer found hidden threats with THOR Scan. Discover why EDR isn't enough\u2014run your assessment now.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-3701-2","post_id-3701"],"footnotes":""},"categories":[215],"tags":[],"class_list":["post-7405","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-case-studies"],"evm_reading_time_minutes":4,"wpml_language":"en","wpml_translation_of":3701,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7405","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7405"}],"version-history":[{"count":7,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7405\/revisions"}],"predecessor-version":[{"id":19794,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7405\/revisions\/19794"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/3700"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7405"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7405"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7405"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}