Detection and monitoring EU-developed

Loki-RS

Scans files, process memory and archives for YARA rules and indicators of compromise during endpoint triage and threat hunting.

By Florian Roth · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Detection and monitoring
Developer or maintainer
Florian Roth
Recorded country
Germany
Product model
Open source
Deployment
Desktop/CLI
Software license
GPL-3.0
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

The current Rust successor is developed by Florian Roth, whose upstream profile identifies Frankfurt, Germany; the older Python LOKI is deprecated.

Reported capabilities

  • YARA and IOC endpoint scans
  • File, process memory and archive coverage
  • Command-line and prebuilt binary use

Scope and limits

The README calls Loki-RS a side project for practical triage and experimentation and points professional support to THOR. The separate Python LOKI predecessor is officially deprecated.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    README calls Loki-RS the Rust rewrite of LOKI and describes multithreaded YARA/IOC scanning across files, process memory and ZIP archives, with CLI and prebuilt binaries.

    Read source
  2. origin / country

    Author Florian Roth self-identifies Frankfurt, Germany and Nextron Systems on his upstream profile; country is tied to the identified lead.

    Read source
  3. license

    Actual repository LICENSE contains GNU GPL version 3 text.

    Read source
  4. maintenance

    Upstream v2.13.1 release was published 2026-09-27; a release is activity, not a guarantee of efficacy.

    Read source
  5. capabilities

    README calls this a side project for triage and experimentation and points users seeking professional support to THOR.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

YARA Capability

Scans files and process memory using YARA-X, with YARA Forge Core rules as its default rule source. The project is beta; process-memory access has platform and permission limits.

Put the tool in context.

Check telemetry, field mappings, conversion and alert handling before deploying a Sigma rule. A practical detection workflow for CSIRTs and SOC teams.

From Sigma rule to a tested detection