awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectMCP serverAboutHow we rankPress
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
Neo23x0 avatar

Neo23x0/Loki

0
View on GitHub↗
3,763 stars·614 forks·Python·GPL-3.0·19 viewswww.nextron-systems.com/compare-our-scanners↗

Loki

Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems.

The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte sequences and strings.

The tool covers a broad range of security operations, including digital forensics, endpoint compromise assessment, and threat hunting. Its capabilities include auditing shim caches, inspecting registry hives, monitoring network connections for command-and-control activity, and analyzing system event logs. It also features anomaly detection for rootkits and executable packers, alongside resource-throttled execution to limit CPU and memory usage during scans.

Scan results can be exported to plain text or CSV formats for external analysis.

Features

  • YARA-Based Scanning - Utilizes a specialized YARA rule engine to scan files and process memory for malicious byte sequences and strings.
  • Artifact Analyzers - Inspects disk images, memory dumps, and event logs to find traces of stealthy implants.
  • Threat Intelligence - Matches filenames, hashes, and signatures against multi-source threat intelligence feeds.
  • YARA Rule Execution - Executes YARA rules against files and process memory to identify malicious patterns.
  • Persistence Analysis - Extracts autorun entries and registry hives to identify malicious persistence mechanisms across different operating system architectures.
  • Persistence Mechanisms - Extracts autorun information to identify unauthorized programs configured for automatic startup.
  • Malicious Artifact Identification - Identifies web shells, renamed administration tools, and credential dumpers via behavioral and structural characteristics.
  • Compromise Assessments - Scans remote systems and local endpoints for persistence mechanisms, web shells, and unauthorized administrative tools.
  • Endpoint Detection and Response - Functions as a scanner for identifying malicious persistence mechanisms and unauthorized tools across remote systems.
  • File Hash Verification - Identifies known malicious files by comparing calculated file checksums against threat intelligence databases.
  • In-Memory Implant Detectors - Scans for malicious mutexes and named pipes to detect stealthy memory-resident implants.
  • Cross-Platform Evidence Scanning - Analyzes disk images, memory dumps, and registry hives to find indicators of compromise.
  • Memory Scanners - Inspects active process memory and mutexes to find malicious implants that do not exist as files on disk.
  • Remote Endpoint Triage - Deploys scanning logic and gathers evidence from multiple remote systems from a single controller using privileged access.
  • Remote Security Scanning - Executes security scans on multiple remote endpoints from a single privileged workstation.
  • Digital Forensics and Analysis - Examines disk images, memory dumps, and registry hives to find evidence of attacker tools and stealthy implants.
  • System Forensic Analysis - Inspects the filesystem for attacker toolsets and cloaked executables using signatures and hashes.
  • System Binary Analysis - Inspects system files for suspicious executable packers and signature issuers to identify hidden threats.
  • File Content Signature Matching - Searches the filesystem and active processes for known malware signatures and byte sequences.
  • Threat Hunting Workflows - Searches files, memory, and logs for known indicators of compromise and malicious patterns to identify active breaches.
  • Threat Intelligence Scanners - Matches system artifacts against known threat feeds to identify malware and hacking tools.
  • Forensic - Analyzes process memory and filesystem structures to detect rootkits and other forensic anomalies.
  • Raw Registry Hive Parsing - Parses registry hives to detect malicious persistence and unauthorized configuration changes.
  • Threat Intelligence Feeds - Imports and applies custom threat feeds and signature sets to detect current and emerging security threats.
  • Threat Intelligence Signatures - Enables the loading and integration of user-defined indicators of compromise and encrypted signature sets from threat feeds.
  • Compatibility Cache Forensics - Audits the application compatibility cache to find evidence of suspicious programs deleted from disk.
  • Threat Indicator Aggregators - Aggregates detection rules from local files, encrypted sets, and remote threat feeds into a unified scanning engine.
  • Active Connection Monitors - Monitors active network connections to detect communication with command-and-control servers.
  • Endpoint Resource Throttling - Monitors CPU and memory usage in real-time to dynamically limit scan intensity and maintain system stability.
  • System Resource Monitors - Tracks real-time memory and hardware usage to dynamically throttle scan execution.
  • CPU Usage Limiters - Caps maximum processor usage during scans to prevent system instability and resource contention.
  • Windows Event Log Analyzers - Parses Windows event logs to detect malicious activity and known filename indicators.
  • Detection and Classification - Host-based scanner for detecting known IOCs.
  • Development And Analysis Tools - Python-based IOC and YARA scanner.
  • Endpoint Protection - Scanner for indicators of compromise and incident response.
  • Forensics - Scanner for indicators of compromise.
  • IOC and Malware Scanning - Scanner for incident response and indicator detection.
  • Scanner Tools - Endpoint scanner using YARA rules and other indicators.

Star history

Star history chart for neo23x0/lokiStar history chart for neo23x0/loki

How this analysis was created: This summary and feature list are AI-generated from collected project material and can contain mistakes. Stars, license and language are imported from GitHub. Inclusion does not mean that we have tested or audited this project. Check the source documentation for any feature you depend on. Learn more on our About page.

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Projects sharing features with Loki

These projects share indexed features with Loki. Shared tags can include platform or build tooling; verify the primary use case before treating a result as a replacement.
  • velocidex/velociraptorVelocidex avatar

    Velocidex/velociraptor

    3,769View on GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    View on GitHub↗3,769
  • bypass007/emergency-response-notesBypass007 avatar

    Bypass007/Emergency-Response-Notes

    5,551View on GitHub↗

    Emergency-Response-Notes is a collection of technical reference documentation and playbooks used for performing forensic analysis, incident response, intrusion identification, and malware remediation. It serves as an incident response knowledge base and an intrusion analysis framework to help identify web shells, hidden backdoors, and persistence mechanisms used during security attacks. The project utilizes a case-study-based knowledge base to map real-world attack scenarios to specific mitigation and recovery steps. It provides a digital forensics playbook and a malware remediation guide for

    View on GitHub↗5,551
  • alexandreborges/malwoverviewalexandreborges avatar

    alexandreborges/malwoverview

    3,882View on GitHub↗

    This project is a Python command-line security tool and malware analysis framework designed for threat intelligence aggregation and incident triage. It functions as an aggregator that orchestrates queries across multiple security services and sandboxes to analyze hashes, IP addresses, and domains. The tool distinguishes itself by incorporating an intelligence layer that uses language models to provide automated risk assessments and framework mappings. It also includes specialized capabilities for extracting indicators of compromise from unstructured text, documents, and web pages, as well as

    Pythonalienvaultcvecve-search
    View on GitHub↗3,882
  • google/grrgoogle avatar

    google/grr

    5,074View on GitHub↗

    GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro

    Python
    View on GitHub↗5,074
Compare all 30 related projects→

Frequently asked questions

What does neo23x0/loki do?

Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems.

What are the main features of neo23x0/loki?

The main features of neo23x0/loki are: YARA-Based Scanning, Artifact Analyzers, Threat Intelligence, YARA Rule Execution, Persistence Analysis, Persistence Mechanisms, Malicious Artifact Identification, Compromise Assessments.

Which projects share features with neo23x0/loki?

Projects with overlapping indexed features include: velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… bypass007/emergency-response-notes — Emergency-Response-Notes is a collection of technical reference documentation and playbooks used for performing… alexandreborges/malwoverview — This project is a Python command-line security tool and malware analysis framework designed for threat intelligence… google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… ufrisk/memprocfs — MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory… blacklanternsecurity/bbot — This project is an open-source intelligence reconnaissance framework and recursive attack surface mapper. It functions…