← All cheat sheets

LOKI & THOR LITE IOC SCANNER

Plain-text reference · 4 KB. Read it, search it (Ctrl-F) or print it.

IOC and YARA-based scanners for detecting malware, hacking tools,
and indicators of compromise on endpoints.

LOKI (FREE / OPEN SOURCE)#


            

INSTALLATION#

# Download
git clone https://github.com/Neo23x0/Loki
cd Loki
pip install -r requirements.txt

# Update signatures
python3 loki-upgrader.py

BASIC USAGE#

# Full system scan
sudo python3 loki.py

# Scan specific directory
sudo python3 loki.py -p /path/to/scan

# Intense scan (slower, more thorough)
sudo python3 loki.py --intense

# Update signatures before scan
python3 loki-upgrader.py
sudo python3 loki.py

# Scan with custom YARA rules
sudo python3 loki.py --custom-yara /path/to/rules/

# Output to file
sudo python3 loki.py -l /path/to/logfile.log

OPTIONS#

-p PATH           # Scan specific path
--intense         # Deep scan (PE header analysis, etc.)
--noindicator     # Skip IOC hash checks
--noyara          # Skip YARA scanning
--nofiletype      # Skip file type checks
--noevtx          # Skip event log analysis
-l LOGFILE        # Write log to file
--csv             # CSV output
--onlyrelevant    # Only show warnings/alerts
--alldrives       # Scan all mounted drives (Windows)
--noprocscan      # Skip process scanning
--nofilescan      # Skip file scanning

DETECTION METHODS#

  File hash IOCs       # MD5/SHA1/SHA256 matching
  YARA rules           # Pattern-based malware detection
  Filename patterns    # Known malicious filenames
  File size anomalies  # Suspiciously sized system files
  C2 indicators        # Known C2 domain/IP matching
  Process anomalies    # Suspicious running processes
  Event log analysis   # Known attack event patterns
  PE header analysis   # Anomalous PE characteristics

========================================================================

THOR LITE (FREE EDITION)#


            

DOWNLOAD#

# Register at: https://www.nextron-systems.com/thor-lite/
# Download Thor Lite package

USAGE#

# Windows
thor64-lite.exe

# Linux
./thor-lite-linux-amd64

# Scan specific directory
thor64-lite.exe -p C:\Users\

# Quick scan
thor64-lite.exe --quick

# Intense scan
thor64-lite.exe --intense

# Output formats
thor64-lite.exe --json
thor64-lite.exe --csv
thor64-lite.exe -l output.log

THOR LITE vs FULL THOR#

Feature            Thor Lite    Thor (Full)
-------            ---------    -----------
YARA scanning      Yes          Yes
IOC matching       Yes          Yes
Sigma rules        No           Yes
Log analysis       Limited      Full
Process scanning   Basic        Advanced
Memory scanning    No           Yes
Registry scanning  No           Yes
Network indicators No           Yes
Reporting          Basic        HTML/JSON/Syslog
MITRE mapping      No           Yes
Licensing          Free         Commercial

========================================================================

CUSTOM YARA RULES#

# Add custom rules to signature-base/yara/ directory

rule Suspicious_PowerShell {
    meta:
        description = "Detect suspicious PowerShell patterns"
        author = "Analyst"
        severity = "high"
    strings:
        $s1 = "IEX" ascii nocase
        $s2 = "Invoke-Expression" ascii nocase
        $s3 = "DownloadString" ascii nocase
        $s4 = "-enc" ascii nocase
        $s5 = "FromBase64String" ascii nocase
    condition:
        2 of them
}

INVESTIGATION WORKFLOW#

# 1. Deploy Loki/Thor to compromised system
# 2. Update signatures
python3 loki-upgrader.py

# 3. Run scan
sudo python3 loki.py -p / --csv -l scan_results.log

# 4. Review findings
# [ALERT] = confirmed malicious
# [WARNING] = suspicious, needs investigation
# [NOTICE] = informational
# [INFO] = scan progress

# 5. Extract IOCs from findings
# 6. Search for IOCs across other systems
# 7. Remediate and re-scan

TIPS#

  - Update signatures before every scan (loki-upgrader.py)
  - --intense flag catches more but takes longer
  - Custom YARA rules extend detection capability
  - Run from USB/network share for forensic integrity
  - CSV output for bulk analysis and correlation
  - Loki is free and open-source; Thor Lite is free but closed
  - Thor (full) adds Sigma rules and memory scanning
  - Combine with YARA standalone for custom hunting
  - Process scanning catches in-memory threats
  - Scan both system drives and user profiles

Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.