DFIRVault

DFIR THOR Drive Scanner – Fast Forensic Scans with One Click

πŸ” THOR Drive Scanner – Fast Forensic Scans with One Click

Need to scan a mounted drive with THOR Lite? I built a no-fuss batch utility to automate it β€” THOR Drive Scanner.

https://github.com/dfirvault/Thor-scanner-menu

⚑ What It Does

This tool wraps THOR Lite into a streamlined workflow for DFIR cases:

  • Lists mounted drives by label and size

  • Validates the THOR executable path (auto or manual)

  • Asks for a case name and output folder

  • Kicks off a full scan with curated parameters

  • Drops results in 3 clean formats:

    • πŸ“„ CSV with file hashes

    • 🧾 HTML report

    • πŸ“œ Log file

  • Auto-opens the results folder when it’s done

πŸ“ Output Naming

Results follow a standard format:

  • YYYMMDD-CaseName-drive(X)_files_md5s.csv
  • YYYYMMDD-CaseName-drive(X)_thor_scan.html
  • YYYYMMDD-CaseName-drive(X)_thor_log.txt

Example:

🧰 Requirements

  • Windows

  • THOR Lite (default: C:\Tools\Thor\thor64-lite.exe)

  • Admin rights (recommended)

▢️ How to Use It

  1. Run as Administrator

  2. Select a drive

  3. Enter output location and case name

  4. Let THOR rip πŸ”₯


🎯 Version: 0.1
πŸ‘€ Author: Jacob Wilson
πŸ”— View on GitHub
πŸ“¬ dfirvault@gmail.com
🌐 dfirvault.com