Sigma Capability
Applies Sigma rules to Windows Eventlogs, disk log files and selected internal objects. Releases before THOR 10.7 require Sigma scanning to be explicitly enabled.
An independent tool index
for incident response teams
Malware analysis EU-developed
Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation.
By Nextron Systems · Germany
The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.
Nextron describes THOR as originating in German security engineering work and remains its named German developer and commercial steward.
THOR is a portable local scanner. Vendor manuals require host licenses and EULA acceptance; the full current EULA was not publicly readable. THOR Lite is a separate free edition, not proof of an open-source license.
identity / capabilities / deployment
The vendor's product page describes portable installation-free host and image scanning with YARA/Sigma/IOCs and reports; the page presents THOR as a commercial product.
Read sourceorigin / country
Nextron's history identifies the German origins of THOR and its current German company stewardship.
Read sourcelicense
The vendor distinguishes commercial THOR from free THOR Lite; it does not call either edition open source.
Read sourcelicense
Official THOR deployment documentation says voucher/customer downloads require EULA acceptance and a valid host license; the EULA text itself was not found on the public site.
Read sourcemaintenance
Nextron’s support index dates THOR Scanner 10.7.32 to 10 September 2026.
Read sourceThis profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.
Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.
Applies Sigma rules to Windows Eventlogs, disk log files and selected internal objects. Releases before THOR 10.7 require Sigma scanning to be explicitly enabled.
Applies bundled and custom YARA rules to files, process memory and other documented scan targets. Custom rules and scan-size limits are configurable.
Reads IOCs from STIX v2 JSON files and applies the observable types and operators listed in the manual. This is a supported subset, not full STIX model ingestion.
Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.
A malware triage workflow for suspicious files