THOR APT scanner
thor.exe --allhds
Full APT scan of a host with THOR: thousands of YARA rules, memory modules, behavioral detection, and signature for the forensic report.
Run it in serious IRs when you need the deepest detection available in a scanner: THOR combines tens of thousands of YARA rules (from the most active vendors), memory analysis modules, behavioral detection of processes, hashes, and more—and generates a signed report suitable for the forensic report and for court. It's the go-to scanner when Loki falls short or when the case matters: with --allhds it sweeps all disks, and the memory modules hunt malware that only lives in RAM, which file scanning doesn't see. The free IR license (limited to forensic use) makes it accessible.
Don't use it for routine low-value scans: THOR is slow (a full disk scan takes hours), heavy, and the free license is limited to IR/forensic use—for daily hygiene, Loki or the AV suffice. On hosts with lots of legitimate software, the volume of low-level findings (risk indicators) is high and requires an analyst who can separate the wheat from the chaff; it's not a tool to delegate to a junior without supervision. And the usual limitation: it detects the known—an actor with custom tools can slip through; THOR reduces risk, it doesn't eliminate it.