Malware analysis EU-developed

THOR APT Scanner

Portable compromise-assessment scanner that searches live hosts or forensic images using YARA, Sigma, indicators, and anomaly checks without installation.

By Nextron Systems · Germany

EU-developed

The record identifies an EU developer or development origin. The origin note explains the evidence; current ownership and hosting are recorded separately where established.

At a glance

Recorded facts
Response workflow
Malware analysis
Developer or maintainer
Nextron Systems
Recorded country
Germany
Product model
Commercial
Deployment
Desktop/CLI
Software license
Commercial license; full terms not publicly verified
Upstream status
Active
Evidence class
EU-developed

What the sources establish

Origin note

Nextron describes THOR as originating in German security engineering work and remains its named German developer and commercial steward.

Reported capabilities

  • Scans live systems, images, registry data, and event logs.
  • Runs as a portable binary on Windows, Linux, and macOS.
  • Accepts custom YARA rules and indicators.

Scope and limits

THOR is a portable local scanner. Vendor manuals require host licenses and EULA acceptance; the full current EULA was not publicly readable. THOR Lite is a separate free edition, not proof of an open-source license.

Inspect the research evidence 5 source observations
  1. identity / capabilities / deployment

    The vendor's product page describes portable installation-free host and image scanning with YARA/Sigma/IOCs and reports; the page presents THOR as a commercial product.

    Read source
  2. origin / country

    Nextron's history identifies the German origins of THOR and its current German company stewardship.

    Read source
  3. license

    The vendor distinguishes commercial THOR from free THOR Lite; it does not call either edition open source.

    Read source
  4. license

    Official THOR deployment documentation says voucher/customer downloads require EULA acceptance and a valid host license; the EULA text itself was not found on the public site.

    Read source
  5. maintenance

    Nextron’s support index dates THOR Scanner 10.7.32 to 10 September 2026.

    Read source

This profile summarizes source material. It does not include hands-on security testing, procurement review, or an assessment of fit for your environment.

Capabilities & integrations

Tags record specific documented functions. They do not establish end-to-end interoperability; check the component, edition and version in the source.

Sigma Capability

Applies Sigma rules to Windows Eventlogs, disk log files and selected internal objects. Releases before THOR 10.7 require Sigma scanning to be explicitly enabled.

YARA Capability

Applies bundled and custom YARA rules to files, process memory and other documented scan targets. Custom rules and scan-size limits are configurable.

STIX Capability

Reads IOCs from STIX v2 JSON files and applies the observable types and operators listed in the manual. This is a supported subset, not full STIX model ingestion.

Put the tool in context.

Plan suspicious-file intake, static analysis, specialist escalation and a defensible handoff. Compare the documented roles of MWDB Core, Pandora and Karton.

A malware triage workflow for suspicious files