Nextron Systems
Nextron Systems GmbH is a German cybersecurity vendor that provides the THOR APT scanner, ASGARD management platform, AURORA endpoint agent, and VALHALLA detection rule feed for compromise assessment and forensic analysis, serving Fortune Global 100 enterprises, government agencies, and critical-infrastructure operators across 25+ countries.
- Company typePrivate
- Founded2017
- HeadquartersDietzenbach, Germany
- Headcount11–50
- GTM typeB2B
- OfferingSoftware
What Nextron Systems does
Nextron Systems GmbH is a Frankfurt-based cybersecurity software vendor founded in 2017 that builds detection and forensic-analysis tooling primarily for compromise assessment and incident response. Its product suite is anchored on THOR, an APT scanner that applies roughly 30,000 YARA and 2,000 Sigma detection rules to uncover tampered system files, obfuscated scripts, and post-compromise artifacts that traditional AV, EDR, and SIEM tools miss; THOR supports Windows, Linux, macOS, IBM AIX, and legacy systems where EDR cannot run. The ASGARD Management Center v4 orchestrates infrastructure-wide scans (UUID-based APIs, LDAP/AD, MDM integration, version pinning), the ASGARD Analysis Cockpit correlates IOCs and consumes sandbox reports, AURORA is a Sigma-based lightweight endpoint agent, and VALHALLA is a subscription rule feed with a claimed zero false-positive rate.
The company monetizes through per-endpoint software licenses (perpetual and subscription), the VALHALLA rule-feed subscription, cloud-delivered scanning (THOR Cloud plus a freemium THOR Cloud Lite tier), managed services (Nextron MDR via the BETTA Security acquisition in October 2025), and incident-response / forensic-analysis professional services. Distribution is enterprise field sales augmented by an authorized reseller network (secuinfra, SVA, Agilimo, Lazarus Cyber, Mjolnir Security, HVS, others), with a recent self-serve cloud motion layered on top.
Customers span Fortune Global 100 enterprises, German federal agencies (BKA, LKA, BSI), and critical-infrastructure operators; named logos include Swisscom, Infineon, Amer Sports, Fraport, TeamViewer, Mobiliar, IHK, and Schuette. Disclosed scale references 500+ organizations across 25+ countries, with 60% of revenue coming from critical-infrastructure, public-sector, and defense accounts. In May 2026 Eurazeo acquired a majority stake via its PME V fund, succeeding prior majority investor BID Equity and signaling the next phase of international scaling.
Nextron Systems firmographics
Firmographics- Name
- Nextron Systems
- Legal name
- Nextron Systems GmbH
- Website
- https://nextron-systems.com
- Company type
- Private
- Founded year
- 2017
- Operating status
- Operating
- Headcount range
- 11–50 employees
- Short description
- Nextron Systems GmbH is a German cybersecurity vendor that provides the THOR APT scanner, ASGARD management platform, AURORA endpoint agent, and VALHALLA detection rule feed for compromise assessment and forensic analysis, serving Fortune Global 100 enterprises, government agencies, and critical-infrastructure operators across 25+ countries.
- Ownership category
- akta.pro rank
Where Nextron Systems is headquartered
LocationHeadquarters
- HQ city
- Dietzenbach
- HQ country
- Germany
- HQ region
- Europe
Offices1 record
Markets served
Nextron Systems business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Technology or R&D, Personnel, Marketing or Sales, Operations, Infrastructure
Revenue model
- Software Licenses: Perpetual and subscription-based software licenses for THOR scanner, ASGARD Management Center, AURORA endpoint agent, and related products. Licenses are issued per endpoint with different tiers including standard, legacy, and AIX-specific license types.
- THOR Cloud / SaaS: Cloud-based scanning services including THOR Cloud Lite (free tier) and premium THOR Cloud subscriptions for organizations preferring cloud-delivered threat detection without on-premise infrastructure.
- Managed Services: Nextron MDR (Managed Detection and Response) service providing continuous compromise assessment and managed incident response capabilities delivered as a service.
- Professional Services: Incident response, compromise assessment, and forensic analysis services delivered by Nextron's expert team, including training on threat detection.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Freemium | Free | THOR Cloud Lite - Free tier cloud scanning |
| Subscription | Annual | Enterprise Software Licenses - Full product suite |
| Freemium | Free | THOR Lite - Free IOC and YARA Scanner |
Go-to-market motion1 record
Distribution channels4 records
Marketing channels9 records
Nextron Systems product offering
Product offeringCore offering
Nextron Systems develops and sells compromise assessment software centered on the THOR APT scanner, which applies approximately 30,000 YARA and 2,000 Sigma rules to detect tampered system files, obfuscated scripts, and forensic artifacts across Windows, Linux, macOS, AIX, and legacy platforms. The portfolio includes the ASGARD Management Center for centralized orchestration, AURORA endpoint agent, VALHALLA rule feed, cloud-hosted scanning via THOR Cloud, managed services (Nextron MDR), and incident response and forensic analysis services.
Product overview
Nextron Systems offers a unified threat detection and forensic analysis suite centered on the THOR APT Scanner. The portfolio includes multiple scanner variants (THOR APT Scanner, THOR Lite, THOR Thunderstorm, THOR Cloud, THOR Cloud Lite, THOR for Legacy/THOR for AIX), managed services (THOR Cloud, Nextron MDR), and management/orchestration platforms (ASGARD Management Center, ASGARD Analysis Cockpit). Additional products include AURORA for Sigma-based endpoint detection and VALHALLA for YARA/Sigma rule feeds. Products are available both on-premises and as cloud solutions, with ASGARD enabling scalable orchestration across millions of endpoints.
Differentiator
Problem solved
Functional benefit
Brands
- THOR: Advanced APT scanner for compromise assessment and forensic analysis
- ASGARD Management Center
- ASGARD Analysis Cockpit
- AURORA
- VALHALLA
- THOR Cloud
- THOR Lite
- THOR Thunderstorm
- Nextron MDR
Products and services
- THOR APT Scanner Advanced persistent threat scanner for compromise assessment and forensic analysis; uses high-sensitivity YARA and Sigma rules to detect traces of hacking activity, tampered system files, obfuscated scripts, and subtle forensic artifacts that evade traditional AV, EDR, and SIEM tools. Supports Windows, Linux, macOS, and AIX endpoints.
- THOR Lite Free IOC and YARA scanner for compromise assessment; provides basic threat detection capabilities for organizations to scan endpoints for indicators of compromise without licensing costs.
- THOR Thunderstorm THOR delivered as a web service for on-demand cloud-based scanning of large artifact volumes, enabling centralized results analysis and reduced on-premise infrastructure requirements.
- THOR Cloud Cloud-hosted THOR scanning service with web-based management, log inspection views, saved filters, false positive filtering, and webhook integrations for automated notifications.
- THOR Cloud Lite Free cloud-based THOR scanning service providing quick endpoint scanning with public detection rules and known indicators via web interface, without requiring on-premise infrastructure setup.
- THOR for Legacy Specialized scanner for older Windows (Windows 7, Windows Server 2008) and Linux systems not supported by standard THOR, with a dedicated AIX license type for IBM AIX 7.2 and 7.3 environments.
- ASGARD Management Center Centralized management platform for scheduling, configuring, and managing infrastructure-wide THOR and AURORA scans; features software inventory, live event streaming, version pinning, encrypted evidence collection, and Master ASGARD for multi-site orchestration. Version 4.0 introduces UUID-based entities and YAML configuration.
- ASGARD Analysis Cockpit Centralized analysis platform for IOC correlation, detailed log analysis, and seamless integration with sandbox reports; receives live event streaming from THOR scans to support real-time forensic investigation workflows.
- AURORA Endpoint Agent Custom lightweight Sigma-based endpoint agent that applies Sigma rules to system events for efficient real-time and ongoing threat detection on endpoints.
- VALHALLA Rule Feed Subscription-based YARA and Sigma threat intelligence feed providing continuously updated, handcrafted high-quality detections with a near-zero false-positive rate for extending customer detection capabilities.
- Nextron MDR (Managed Detection and Response) Managed Detection and Response service providing continuous monitoring, compromise assessment, and incident response capabilities delivered by Nextron's expert team for organizations requiring outsourced security operations.
Quantifiable outcome
- THOR scanner processes approximately 114,000 OSS artifacts daily with 100 analyst reviews per day using THOR Thunderstorm.
- +2 more outcomes
Companies that use Nextron Systems
Customer profileNamed customers8 records
Segments4 records
Ideal customer profiles4 records
Nextron Systems technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration4 records
AI capability2 records
Feature8 records
Nextron Systems partnerships and signals
Strategic signalPartnerships
Six partnerships are on record, tiered minor.
- BETTA SecurityminorNextron acquired BETTA Security to strengthen organizations' resilience against cyberattacks. The partnership was deepened at it-sa 2025 after years of successful collaboration, expanding Nextron's capabilities in managed security services.
- SecuinframinorAuthorized reseller of Nextron products in Germany, providing regional sales and support for enterprise customers.
- SVAminorAuthorized reseller of Nextron products, providing regional sales and technical integration services.
- AgilimominorAuthorized reseller providing Nextron product distribution and support in regional markets.
- Lazarus CyberminorAuthorized reseller providing Nextron cybersecurity solutions to enterprise customers.
- NATO CCDCOEminorNextron supports the NATO Cooperative Cyber Defence Centre of Excellence's Locked Shields exercise by providing THOR scanner to participating blue teams for real-time compromise assessment during live-fire cyber defense training.
Scale indicators6 records
Recent moves7 records
Expansion highlights6 records
Nextron Systems competitors and assessment
Company assessmentBroad incumbents
- SentinelOne: SentinelOne's Singularity Platform bundles EDR, XDR, and forensic investigation capabilities that overlap with Nextron's scanning and triage use cases. It is a broad enterprise incumbent competing for the same security-validations and IR-assisted deployment budgets.
- CrowdStrike: CrowdStrike Falcon OverWatch and Falcon Forensics offer managed compromise assessment and forensic investigation capabilities within the broader Falcon XDR platform. It is the dominant endpoint incumbent whose consolidation trajectory most threatens standalone scanning vendors like Nextron.
- Sophos: Sophos combines endpoint protection, XDR, and managed detection and response services aimed at mid-market and European enterprise buyers. It overlaps with Nextron's THOR-based detection content on managed endpoints and competes for the same channel-driven MSSP relationships across DACH and broader EMEA.
- Trend Micro: Trend Micro Vision One delivers XDR, threat intelligence, and incident response capabilities that overlap with Nextron's scanning-and-detection value proposition. It is a broad incumbent particularly strong in DACH and EMEA enterprise and public-sector segments, making it a frequent displacement candidate during platform consolidations.
- Palo Alto Networks: Palo Alto Cortex XDR and Unit 42 incident response services bundle compromise assessment, threat hunting, and forensic analysis into a portfolio play. It competes for the same Fortune 100 and European regulated-sector buyers, often displacing point-tool vendors during platform consolidation cycles.
Direct peers
- Kroll: Kroll's Cyber Risk practice offers incident response, compromise assessment, and digital forensic services that closely mirror Nextron's professional-services engagements. It is a credible alternative for Fortune 1000 and law firm clients seeking outsourced forensic investigation and breach response.
- Arctic Wolf: Arctic Wolf delivers managed detection and response (MDR) plus managed risk services that overlap with Nextron MDR and the ASGARD-driven scanning workflow. It is a relevant comparison for Nextron's managed-services expansion path, particularly for mid-market and enterprise customers seeking outsourced security operations.
- Group-IB: Group-IB provides threat intelligence, fraud protection, and compromise assessment/incident response services to enterprises and law enforcement globally. It competes for similar Russian/EU/APAC enterprise and government budgets and overlaps on the forensic scanning and APT detection use cases that Nextron's THOR addresses.
- Mandiant (Google Cloud): Mandiant operates the gold-standard incident response and compromise assessment services business and is now embedded within Google Cloud's security portfolio. It directly competes for the same federal, critical-infrastructure, and Fortune 100 incident-response and proactive compromise assessment engagements that Nextron targets.
- WithSecure: WithSecure (formerly F-Secure) sells Elements Endpoint Detection & Response plus a dedicated Compromise Assessment service that mirrors Nextron's THOR-led forensic scanning model. It is the closest European-headquartered direct competitor targeting mid-market and enterprise buyers with a hybrid product-plus-services approach.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Nextron Systems social profiles
Digital presenceNextron Systems compliance and trust
Trust signalCompliance1 record
Nextron Systems financial estimates
Financial estimateRevenue estimate
Valuation estimate
Nextron Systems leadership team
Management profileNumber of profiles
Profiles5 records
Nextron Systems subsidiaries and ownership
Company hierarchySubsidiaries1 record
Nextron Systems funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Nextron Systems M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Nextron Systems
What does Nextron Systems do?
Nextron Systems develops and sells compromise assessment software centered on the THOR APT scanner, which applies approximately 30,000 YARA and 2,000 Sigma rules to detect tampered system files, obfuscated scripts, and forensic artifacts across Windows, Linux, macOS, AIX, and legacy platforms. The portfolio includes the ASGARD Management Center for centralized orchestration, AURORA endpoint agent, VALHALLA rule feed, cloud-hosted scanning via THOR Cloud, managed services (Nextron MDR), and incident response and forensic analysis services.
Is Nextron Systems a public or private company?
Nextron Systems is a private company. It is classified as private equity controlled and is currently operating.
When was Nextron Systems founded?
Nextron Systems was founded in 2017. It employs 11 to 50 people.
Where is Nextron Systems based?
Nextron Systems is headquartered in Dietzenbach, Germany, in the Europe region.
How does Nextron Systems make money?
Four revenue lines are on record. Software Licenses are the primary driver. The others are THOR Cloud / SaaS, managed Services and professional Services.
Who are Nextron Systems's main competitors?
Broad incumbents on record are SentinelOne, CrowdStrike, Sophos, Trend Micro and Palo Alto Networks. Direct peers are Kroll, Arctic Wolf, Group-IB, Mandiant (Google Cloud) and WithSecure.
Does Nextron Systems have an API?
Yes. ASGARD Management Center v4.0 introduced significant API changes including migration to UUIDs instead of integer IDs for various endpoints, and version pinning for product updates. The API supports asset management, scan execution, MISP data handling, and evidence collection. Developer documentation is at knowledge.nextron-systems.com/asgard-management-center/api-breaking-changes-guide.