openapi: 3.2.0 info: title: Nextron Systems Results API version: 1.0.0 description: 'Operations tagged results across 2 of this provider''s published API definitions: nextron-systems-thunderstorm-openapi.yaml, nextron-systems-thunderstorm-openapi.yml. Each path carries the servers of the definition it was published in.' servers: - url: http://localhost:8080/api/v1 description: Local THOR instance tags: - name: Results description: Endpoints to retrieve results of asynchronous scans paths: /getAsyncResults: get: summary: Retrieve the results of an asynchronous file check description: Retrieve the results of an asynchronous file check. tags: - Results operationId: getAsyncResults parameters: - description: Sample ID name: id in: query required: true schema: $ref: '#/components/schemas/SampleId' responses: '200': description: Returns a JSON with the current status and, if applicable, the results content: application/json: schema: $ref: '#/components/schemas/AsyncResult' '400': $ref: '#/components/responses/BadRequest' '500': $ref: '#/components/responses/InternalServerError' servers: - url: http://localhost:8080/api/v1 description: Local THOR instance components: schemas: SampleId: description: Sample ID returned for an asynchronous scan request type: integer format: int64 example: 12345 ThorReport: description: THOR Report containing findings type: array items: $ref: '#/components/schemas/ThorFinding' example: - type: THOR finding meta: time: '2026-01-16T13:35:34.11133172+01:00' level: Alert module: HTTPServer scan_id: S-qkQv5yHIUHk-2 hostname: 127.0.0.1 message: Malicious file found subject: type: file path: somefile.exe exists: 'yes' extension: .exe magic_header: EXE hashes: md5: 7168892693d7716220d98883fffd848c sha1: 42acd9b554e1c843a9f8139022b560de0bf48682 sha256: 660464c473c47784d8820d3e268c0d1327ac22ce0e607dc35e858628c53f0687 first_bytes: hex: 4d5a90000300000004000000ffff0000b8000000 ascii: MZ size: 1352192 permissions: null content: type: sparse data elements: - offset: 856110 data: '>`ncrypt.dll' length: 1352192 score: 94 reasons: - type: reason summary: some YARA rule signature: score: 85 reference: - Internal Research origin: internal kind: YARA Rule date: '2023-05-12' tags: - EXE - HKTL rule_name: Some_Rule_Name description: Detects Something matched: - data: '%*s**CREDENTIAL**' offset: 918480 field: /content - data: '%*s Persist : %08x - %u - %s' offset: 919056 field: /content - data: '%*s**DOMAINKEY**' offset: 950688 field: /content - type: reason summary: Another rule signature: score: 80 reference: - Some reference origin: internal kind: YARA Rule date: '2016-02-05' tags: - T1059_001 rule_name: Another_Rule_Name description: Detects Something other matched: - data: kuhl_m_lsadump_getUsersAndSamKey ; kull_m_registry_RegOpenKeyEx SAM Accounts (0x%08x) offset: 1100540 field: /content - data: kuhl_m_lsadump_getComputerAndSyskey ; kuhl_m_lsadump_getSyskey KO offset: 1099708 field: /content reason_count: 28 context: null log_version: v3.0.0 Error: description: Error with message type: object properties: message: description: Error message describing the problem type: string required: - message ThorFinding: description: THOR Finding type: object additionalProperties: true AsyncResult: description: Result object for asynchronous scan operations type: object properties: status: description: Current status of the scan type: string example: Currently being scanned result: $ref: '#/components/schemas/ThorReport' required: - status example: result: - type: THOR finding meta: time: '2026-01-19T16:08:27.809483955+01:00' level: Warning module: HTTPServer scan_id: S-qiVIo7fm2Yk-4 hostname: 127.0.0.1 message: Suspicious file found subject: type: file path: 6700758b14fe8ac1bbcbbf3d652613d8 exists: 'yes' extension: '' magic_header: UNKNOWN hashes: md5: ffc74d5afc22d1f1c785f98154cc7bae sha1: 9603a4806528578686dc5f02b805c64414b3c91b sha256: da1d2378fbacf84d09d18a94def83cd3bfc06e89e7429ba3de57cd96a0e04a87 first_bytes: hex: 2f2a0ae8aeade8aeb0200a5b726577726974655f ascii: /* [rewrite_ size: 5369 permissions: null content: type: sparse data elements: - offset: 273 data: var _0x length: 5369 score: 79 reasons: - type: reason summary: YARA rule OBFUSC signature: score: 65 origin: internal kind: YARA Rule date: '2025-03-29' tags: - OBFUS rule_name: OBFUSC description: Detects obfuscated JavaScript code matched: - data: ''']=!![];}' offset: 3865 field: /content reason_count: 1 context: null log_version: v3.0.0 status: Sample analysis complete responses: InternalServerError: description: Unauthorized content: application/json: schema: $ref: '#/components/schemas/Error' BadRequest: description: Invalid parameters given content: application/json: schema: $ref: '#/components/schemas/Error' x-refined-from: - nextron-systems-thunderstorm-openapi.yaml - nextron-systems-thunderstorm-openapi.yml