thor-scan/SKILL.md
Run THOR scans and propose the exact command line for Windows, Linux, or macOS. Use when the user wants to scan a host, a directory, a mounted image, or a memory dump with THOR v10/v11.
npx skillsauth add nextronsystems/thor-skill thor-scanInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Goal: produce a safe, reproducible THOR command line and minimal preflight checks.
Rules
Preflight checklist
ls or dir). This immediately tells you:
thor64.exe (Windows), thor-linux-64 (Linux), thor-macosx (macOS)thor64-lite.exe (Windows), thor-lite-linux-64 (Linux), thor-lite-macos (macOS)--lab mode, check license type first:
grep -i forensiclab *.lic - if found, --lab is available-a Filescan --intense --norescontrol --cross-platformImportant flag rules
--lab --intense together - --lab already includes intense mode--lab - requires Forensic Lab license--lab - always use the alternative flag combinationUse these references when needed
Example templates
Output format
data-ai
Troubleshoot THOR runs that are stuck, slow, failing to start, stopping early, or produce missing output. Use when the user reports freezes, long runtimes, high CPU pauses, scan aborts, or licensing/update issues.
tools
Write, package, and use THOR plugins to extend scanner functionality. THOR v11+ only.
development
--- name: thor-maintenance description: Maintain THOR installs using thor-util: update signatures, upgrade versions, download offline packs, generate reports, manage YARA-Forge. Use when the user asks about updating/upgrading/report generation. --- # THOR Maintenance Skill Rules - Be precise about thor-util verbs: - update = signatures - upgrade = program + signatures, keep config - download = full pack incl config (offline use case) - Prefer stable signatures; mention sigdev only for urg
data-ai
Interpret THOR scan results and explain what findings mean. Use when the user pastes THOR log lines, shares a log file, or asks how to triage Notices/Warnings/Alerts.