{"repo":"Neo23x0/Loki","free":true,"listed":false,"github":"https://github.com/Neo23x0/Loki","clone":"git clone https://github.com/Neo23x0/Loki.git","description":"Loki - Simple IOC and YARA Scanner","language":"Python","stars":3776,"topics":["python","yara","signature","scanner","ioc","otx","antivirus","hash","yara-rules","dfir"],"license":"GPL-3.0","category":"dev-tools","readme_excerpt":"I wrote a new Open Source YARA scanner called LOKI RS (Rust). LOKI (Python) is now officially deprecated. Important Note This project is now in inactive maintenance mode. This means that while I merge pull requests for bug fixes and straightforward issues, I currently lack the time to add new features or expand existing ones. For years, my focus has been on developing a more advanced scanner, THOR, which offers a range of improvements over this project. A free version, THOR Lite, is available; it's faster, more stable, and rigorously tested in our CI environments—simply a better solution. You can find a comparison of the open-source, free, and commercial scanners here. I've also begun work on a Rust-based version of LOKI called LOKI 2. However, I’m unsure when it will reach feature parity with the current LOKI release. Additionally, I created a flow chart to help you decide which scanner best meets your needs. Loki - Simple IOC and YARA Scanner Scanner for Simple Indicators of Compromise Detection is based on four detection methods: 1. File Name IOC Regex match on full file path/name 2. Yara Rule Check Yara signature match on file data and process memory 3. Hash Check Compares known malicious hashes (MD5, SHA1, SHA256) with scanned files 4. C2 Back Connect Check Compares process connection endpoints with C2 IOCs (new since version v.10) Additional Checks: 1. Regin filesystem check (via --reginfs) 2. Process anomaly check (based on Sysforensics 3. SWF decompressed scan (new si","default_branch":null,"files":null,"tree":[],"storefront":"/r/Neo23x0","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Neo23x0/Loki/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}