THOR Lite
A free multi-platform IOC and YARA scanner for checking systems for signs of compromise.
These buttons open the developer's own site, repository or store listing in a new tab. wares.gg does not host downloads.
About THOR Lite
THOR Lite is the free community version of Nextron Systems' THOR compromise-assessment scanner. It includes the file system and process scan modules and a module that extracts autoruns information, and ships with the open source signature base instead of the commercial VALHALLA rule set.
It is a Go-based scanner with precompiled builds for Windows, Linux and macOS, an update utility for new versions and signatures, and support for custom IOCs and YARA rules. Output can be sent as SYSLOG or JSON over UDP or TCP. It suits incident responders and administrators checking hosts.
Strengths
- Scans files, processes and autoruns with YARA and IOC signatures
- Precompiled for Windows, Linux and macOS
- Supports custom IOCs and signatures
- SYSLOG and JSON output for log collection
Limitations
- Not open source
- Limited modules and signature set compared to the paid THOR
Details
- Pricing
- FreeFree limited version of the commercial THOR scanner.
- License
- Proprietary (Proprietary)
- Developer
- Nextron Systems
- Platforms
- Windows, macOS, Linux, Command line
- How it runs
- Downloadable app
- Works offline
- Yes
- Best suited for
- Incident responders and administrators running compromise assessments on hosts
- Categories
- Security tools
- Last verified
- Added
- Provenance
- Facts checked against the developer's own pages and store listings, 1 sources on file.
Alternatives to THOR Lite
Compare allSoftware that can replace THOR Lite for an important use case, and what changes if you switch.
YARA
Pattern-matching engine for identifying and classifying malware samples.
YARA is the open-source BSD-3-Clause pattern engine itself, so you write or supply rules and build scanning around it rather than getting a ready IOC scanner.
YARA-X
Match files against rules describing suspicious binary patterns.
YARA-X is the open-source modern rewrite of YARA, matching files against rules but without THOR Lite's IOC, process and autorun scanning.
chkrootkit
A command-line tool that checks Unix-like systems locally for signs of a rootkit.
chkrootkit is an open-source Linux and Unix command-line checker for known rootkits and trojaned binaries, rather than a multi-platform YARA and IOC scanner.
THOR Lite as an alternative
Listings that name THOR Lite as an alternative.
PE-sieve
A Windows tool that scans a running process and dumps injected or hollowed code and hooks.
THOR Lite scans files, processes and autoruns with YARA and IOC signatures across Windows, Linux and macOS, though it is not open source.
Similar software
Related functionality, not necessarily a direct replacement.
Velociraptor
Endpoint monitoring and digital forensics platform driven by a query language.
HollowsHunter
A Windows scanner that checks every running process for injected code, hollowing and other implants.
capa
Identify likely capabilities inside executable files.
Chainsaw
Search Windows forensic records for suspicious activity.
Hayabusa
Build investigation timelines from Windows event logs.