LOKI & THOR LITE IOC SCANNER
IOC and YARA-based scanners for detecting malware, hacking tools, and indicators of compromise on endpoints.
LOKI (FREE / OPEN SOURCE)#
INSTALLATION#
# Download git clone https://github.com/Neo23x0/Loki cd Loki pip install -r requirements.txt # Update signatures python3 loki-upgrader.py
BASIC USAGE#
# Full system scan sudo python3 loki.py # Scan specific directory sudo python3 loki.py -p /path/to/scan # Intense scan (slower, more thorough) sudo python3 loki.py --intense # Update signatures before scan python3 loki-upgrader.py sudo python3 loki.py # Scan with custom YARA rules sudo python3 loki.py --custom-yara /path/to/rules/ # Output to file sudo python3 loki.py -l /path/to/logfile.log
OPTIONS#
-p PATH # Scan specific path --intense # Deep scan (PE header analysis, etc.) --noindicator # Skip IOC hash checks --noyara # Skip YARA scanning --nofiletype # Skip file type checks --noevtx # Skip event log analysis -l LOGFILE # Write log to file --csv # CSV output --onlyrelevant # Only show warnings/alerts --alldrives # Scan all mounted drives (Windows) --noprocscan # Skip process scanning --nofilescan # Skip file scanning
DETECTION METHODS#
File hash IOCs # MD5/SHA1/SHA256 matching YARA rules # Pattern-based malware detection Filename patterns # Known malicious filenames File size anomalies # Suspiciously sized system files C2 indicators # Known C2 domain/IP matching Process anomalies # Suspicious running processes Event log analysis # Known attack event patterns PE header analysis # Anomalous PE characteristics ========================================================================
THOR LITE (FREE EDITION)#
DOWNLOAD#
# Register at: https://www.nextron-systems.com/thor-lite/ # Download Thor Lite package
USAGE#
# Windows thor64-lite.exe # Linux ./thor-lite-linux-amd64 # Scan specific directory thor64-lite.exe -p C:\Users\ # Quick scan thor64-lite.exe --quick # Intense scan thor64-lite.exe --intense # Output formats thor64-lite.exe --json thor64-lite.exe --csv thor64-lite.exe -l output.log
THOR LITE vs FULL THOR#
Feature Thor Lite Thor (Full) ------- --------- ----------- YARA scanning Yes Yes IOC matching Yes Yes Sigma rules No Yes Log analysis Limited Full Process scanning Basic Advanced Memory scanning No Yes Registry scanning No Yes Network indicators No Yes Reporting Basic HTML/JSON/Syslog MITRE mapping No Yes Licensing Free Commercial ========================================================================
CUSTOM YARA RULES#
# Add custom rules to signature-base/yara/ directory
rule Suspicious_PowerShell {
meta:
description = "Detect suspicious PowerShell patterns"
author = "Analyst"
severity = "high"
strings:
$s1 = "IEX" ascii nocase
$s2 = "Invoke-Expression" ascii nocase
$s3 = "DownloadString" ascii nocase
$s4 = "-enc" ascii nocase
$s5 = "FromBase64String" ascii nocase
condition:
2 of them
}
INVESTIGATION WORKFLOW#
# 1. Deploy Loki/Thor to compromised system # 2. Update signatures python3 loki-upgrader.py # 3. Run scan sudo python3 loki.py -p / --csv -l scan_results.log # 4. Review findings # [ALERT] = confirmed malicious # [WARNING] = suspicious, needs investigation # [NOTICE] = informational # [INFO] = scan progress # 5. Extract IOCs from findings # 6. Search for IOCs across other systems # 7. Remediate and re-scan
TIPS#
- Update signatures before every scan (loki-upgrader.py) - --intense flag catches more but takes longer - Custom YARA rules extend detection capability - Run from USB/network share for forensic integrity - CSV output for bulk analysis and correlation - Loki is free and open-source; Thor Lite is free but closed - Thor (full) adds Sigma rules and memory scanning - Combine with YARA standalone for custom hunting - Process scanning catches in-memory threats - Scan both system drives and user profiles
LOKI & THOR LITE IOC SCANNER CHEATSHEET
=========================================
Source: https://cheatsheet.johlem.net
IOC and YARA-based scanners for detecting malware, hacking tools,
and indicators of compromise on endpoints.
LOKI (FREE / OPEN SOURCE)
============================
INSTALLATION
-------------
# Download
git clone https://github.com/Neo23x0/Loki
cd Loki
pip install -r requirements.txt
# Update signatures
python3 loki-upgrader.py
BASIC USAGE
------------
# Full system scan
sudo python3 loki.py
# Scan specific directory
sudo python3 loki.py -p /path/to/scan
# Intense scan (slower, more thorough)
sudo python3 loki.py --intense
# Update signatures before scan
python3 loki-upgrader.py
sudo python3 loki.py
# Scan with custom YARA rules
sudo python3 loki.py --custom-yara /path/to/rules/
# Output to file
sudo python3 loki.py -l /path/to/logfile.log
OPTIONS
--------
-p PATH # Scan specific path
--intense # Deep scan (PE header analysis, etc.)
--noindicator # Skip IOC hash checks
--noyara # Skip YARA scanning
--nofiletype # Skip file type checks
--noevtx # Skip event log analysis
-l LOGFILE # Write log to file
--csv # CSV output
--onlyrelevant # Only show warnings/alerts
--alldrives # Scan all mounted drives (Windows)
--noprocscan # Skip process scanning
--nofilescan # Skip file scanning
DETECTION METHODS
-------------------
File hash IOCs # MD5/SHA1/SHA256 matching
YARA rules # Pattern-based malware detection
Filename patterns # Known malicious filenames
File size anomalies # Suspiciously sized system files
C2 indicators # Known C2 domain/IP matching
Process anomalies # Suspicious running processes
Event log analysis # Known attack event patterns
PE header analysis # Anomalous PE characteristics
========================================================================
THOR LITE (FREE EDITION)
==========================
DOWNLOAD
---------
# Register at: https://www.nextron-systems.com/thor-lite/
# Download Thor Lite package
USAGE
------
# Windows
thor64-lite.exe
# Linux
./thor-lite-linux-amd64
# Scan specific directory
thor64-lite.exe -p C:\Users\
# Quick scan
thor64-lite.exe --quick
# Intense scan
thor64-lite.exe --intense
# Output formats
thor64-lite.exe --json
thor64-lite.exe --csv
thor64-lite.exe -l output.log
THOR LITE vs FULL THOR
-------------------------
Feature Thor Lite Thor (Full)
------- --------- -----------
YARA scanning Yes Yes
IOC matching Yes Yes
Sigma rules No Yes
Log analysis Limited Full
Process scanning Basic Advanced
Memory scanning No Yes
Registry scanning No Yes
Network indicators No Yes
Reporting Basic HTML/JSON/Syslog
MITRE mapping No Yes
Licensing Free Commercial
========================================================================
CUSTOM YARA RULES
===================
# Add custom rules to signature-base/yara/ directory
rule Suspicious_PowerShell {
meta:
description = "Detect suspicious PowerShell patterns"
author = "Analyst"
severity = "high"
strings:
$s1 = "IEX" ascii nocase
$s2 = "Invoke-Expression" ascii nocase
$s3 = "DownloadString" ascii nocase
$s4 = "-enc" ascii nocase
$s5 = "FromBase64String" ascii nocase
condition:
2 of them
}
INVESTIGATION WORKFLOW
------------------------
# 1. Deploy Loki/Thor to compromised system
# 2. Update signatures
python3 loki-upgrader.py
# 3. Run scan
sudo python3 loki.py -p / --csv -l scan_results.log
# 4. Review findings
# [ALERT] = confirmed malicious
# [WARNING] = suspicious, needs investigation
# [NOTICE] = informational
# [INFO] = scan progress
# 5. Extract IOCs from findings
# 6. Search for IOCs across other systems
# 7. Remediate and re-scan
TIPS
-----
- Update signatures before every scan (loki-upgrader.py)
- --intense flag catches more but takes longer
- Custom YARA rules extend detection capability
- Run from USB/network share for forensic integrity
- CSV output for bulk analysis and correlation
- Loki is free and open-source; Thor Lite is free but closed
- Thor (full) adds Sigma rules and memory scanning
- Combine with YARA standalone for custom hunting
- Process scanning catches in-memory threats
- Scan both system drives and user profiles
Defensive reference on CyberRamen. Offensive / red-team sheets live on OffensiveRamen.com.