Loki - Simple IOC and YARA Scanner
loki.exe
and loki-upgrader.exe
are a x64 binaries (better in-memory detection, changes in how SysWow64 / Sysnative gets processed etc.)the new hash IOC format, which we're using in THOR for quite some time (with an optional 2nd column), allows us to set a score for hash IOCs, e.g. this new hash IOC list for malicious/vulnerable drivers from LOLDrivers project
--allhds
and --alldrives
allow scanning all local hard drives or all drives in general including removable drives and network drives--force
to force scan a directory that has been excluded by default (e.g. /dev
, /media
, /mnt
etc.)