Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Loki-RS — 🐍 High-performance, multi-threaded YARA & IOC scanner | Kitploit
Tools/GitHubGitHub/neo23x0/loki-rs
Indicator of Compromise (IOC) ManagementMemory ForensicsVulnerability AnalysisForensicsMalware AnalysisDigital ForensicsThreat IntelligenceIntrusion DetectionIncident ResponseLog Analysis
GitHub
34931203 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
neo23x0/loki-rs

Loki-RS

🐍 High-performance, multi-threaded YARA & IOC scanner

View Repository

Loki RS Logo

Loki-RS

A rewrite of Loki in Rust. High-performance, multi-threaded YARA & IOC scanner in a single binary.

Status: Beta. Works, but still under active development.

Features

  • YARA scanning of files and process memory (yara-x)
  • IOC matching (MD5/SHA1/SHA256 hashes, filename patterns, C2 indicators)
  • Multi-threaded scanning with configurable thread count
  • Archive scanning (ZIP files)
  • Interactive TUI with real-time stats and controls
  • Remote logging via syslog (UDP/TCP) (SYSLOG/JSON)
  • HTML report generation with detailed findings
  • Configurable scoring thresholds
  • Smart filtering (skips /proc, /sys, mounted drives by default)
  • Magic header detection
  • JSONL output for log ingestion

macOS process scanning

Process memory scanning on macOS is best-effort and typically requires debugging entitlements or elevated privileges. Without those, Loki-RS will still scan files but will not be able to read most process memory. Use --no-procs to skip process scanning if needed.

Linux process scanning

On Linux, Loki-RS skips device-backed and kernel-special process mappings before reading /proc/<pid>/mem. This avoids known instability with some driver-managed VMAs while preserving normal anonymous, heap/stack, and regular file-backed memory scanning. If you still hit environment-specific issues, use --no-procs to disable process scanning.

Installation

Download the pre-compiled binary for your platform from the Releases Page.

# Extract
tar -xzvf loki-linux-*.tar.gz
cd loki-linux-*

# Update signatures (recommended)
./loki-util update

# Run
sudo ./loki --help

Signatures ship with the release but get stale quickly. Run loki-util update to fetch the latest YARA-Forge Core rules.

Signatures

Loki-RS uses YARA Forge as its default signature source. Loki-RS ships and updates with the Core rule set (high accuracy, low false positives, optimized for performance). If you need broader coverage, you can swap in the Extended or Full sets from YARA Forge.

IOC files in signatures/iocs/ remain supported as optional local/custom content.

Usage

# Basic scan (TUI enabled by default)
sudo ./loki

# Scan specific folder
sudo ./loki --folder /tmp

# Disable TUI, use standard command-line output
sudo ./loki --no-tui

Common Scenarios

# Scan a mounted image (skip process scanning, use all cores)
sudo ./loki --no-procs --folder ~/image1 --threads 0

# Slow and cautious scan (lower CPU limit, single thread)
sudo ./loki --cpu-limit 60 --threads 1

# Scan and send logs to remote syslog
sudo ./loki --remote syslog-host.internal:514 --remote-proto udp

Screenshots

Loki Startup

Loki Interrup Menu

Command Line Options

Scan Target

OptionDefaultDescription
-f, --folder <PATH>/Folder to scan. Quote paths containing spaces, e.g. -f "J:\SteamLibrary\steamapps\common\SpaceCraft beta"

Scan Control

OptionDefaultDescription
--no-procsfalseSkip process memory scanning
--no-fsfalseSkip filesystem scanning
--no-archivefalseSkip scanning inside archives (ZIP)
--scan-all-drivesfalseScan all drives including mounted/network/cloud
--scan-all-filesfalseScan all files regardless of extension/type

Output Options

OptionDefaultDescription
-l, --log <FILE>autoPlain text log file
--no-logfalseDisable plaintext log output
-j, --jsonl <FILE>autoJSONL output file
--no-jsonlfalseDisable JSONL output
--no-htmlfalseDisable HTML report generation
--no-tuifalseDisable TUI, use standard command-line output
-r, --remote <HOST:PORT>noneRemote syslog destination
-p, --remote-proto <PROTO>udpRemote protocol (udp/tcp)
--remote-format <FMT>syslogRemote format (syslog/json)

Tuning

OptionDefaultDescription
--alert-level <SCORE>80Score threshold for ALERT
--warning-level <SCORE>60Score threshold for WARNING
--notice-level <SCORE>40Score threshold for NOTICE
--max-reasons <NUM>2Max match reasons to display per finding
-m, --max-file-size <BYTES>64000000Maximum file size to scan (64MB)
--yara-timeout <SECONDS>10Maximum YARA scan time for each file or process-memory buffer (minimum: 1 second)
-c, --cpu-limit <PERCENT>100CPU utilization limit (1-100)
--threads <NUM>-2Number of threads (0=all, -1=all-1, -2=all-2)

Info & Debug

OptionDefaultDescription
--version-Show version and exit
-d, --debugfalseShow debug output
--tracefalseShow verbose trace output
--show-access-errorsfalseShow file/process access errors

Excluding Files and Folders

Loki-RS provides multiple mechanisms for excluding files and folders from scans.

Built-in Automatic Exclusions

By default, Loki-RS automatically excludes:

System directories (Linux/macOS):

  • /proc, /dev, /sys/kernel/debug, /sys/kernel/slab, /sys/kernel/tracing, /sys/devices
  • /run, /var/run

Cloud storage directories (unless --scan-all-drives is used):

  • OneDrive, Dropbox, Google Drive, iCloud, Box, Nextcloud, pCloud, MEGA, Seafile, ownCloud, and others

Network and mounted drives (unless --scan-all-drives is used):

  • NFS, CIFS/SMB, SSHFS, WebDAV mounts
  • External media under /media, /volumes

Program directory:

  • Loki-RS automatically excludes its own directory to prevent scanning itself

Command-Line Exclusion Options

OptionDescription
--scan-all-drivesInclude mounted drives, network drives, and cloud storage
--scan-all-filesScan all files regardless of file type/extension (by default, only relevant file types are scanned)
-m, --max-file-size <BYTES>Skip files larger than this size (default: 64MB)
--no-procsSkip process memory scanning entirely
--no-fsSkip filesystem scanning entirely
--no-archiveSkip scanning inside archive files (ZIP)

Hash-Based False Positive Exclusions

You can exclude known good files by their hash. This is useful for whitelisting legitimate files that trigger false positives.

Setup:

  1. Create a file in signatures/iocs/ with both hash and falsepositive in the filename Example: hash-falsepositive-custom.txt

  2. Add hashes (MD5, SHA1, or SHA256) with optional descriptions:

# Format: HASH;description
d41d8cd98f00b204e9800998ecf8427e;Empty file - known good
a7f5f35426b927411fc9231b56382173;Legitimate system utility

Files matching these hashes will be silently skipped during scanning.

Filename Pattern False Positive Exclusions

When adding filename IOCs to signatures/iocs/filename-iocs.txt, you can specify a false positive exclusion regex in the third column:

# Format: REGEX;SCORE;FALSE_POSITIVE_REGEX
#
# This matches all .ps1 files, but excludes those in SysInternals directories
(?i)\\procdump(64)?\.(exe|zip);50;(?i)(SysInternals\\)

If a file matches both the main pattern AND the false positive regex, it will not be reported.

Configuration File Exclusions

Download Tool