Run THOR scans and propose the exact command line for Windows, Linux, or macOS. Use when the user wants to scan a host, a directory, a mounted image, or a memory dump with THOR v10/v11.
Goal: produce a safe, reproducible THOR command line and minimal preflight checks.
Rules
Preflight checklist
ls or dir). This immediately tells you:
thor64.exe (Windows), thor-linux-64 (Linux), thor-macosx (macOS)thor64-lite.exe (Windows), thor-lite-linux-64 (Linux), thor-lite-macos (macOS)--lab mode, check license type first:
grep -i forensiclab *.lic - if found, --lab is available-a Filescan --intense --norescontrol --cross-platformImportant flag rules
--lab --intense together - --lab already includes intense mode--lab - requires Forensic Lab license--lab - always use the alternative flag combinationUse these references when needed
Example templates
Output format
Edit PDFs with natural-language instructions using the nano-pdf CLI.
Control Sonos speakers (discover/status/play/volume/group).
Terminal Spotify playback/search via spogo (preferred) or spotify_player.
Capture frames or clips from RTSP/ONVIF cameras.
CLI to manage emails via IMAP/SMTP. Use `himalaya` to list, read, write, reply, forward, search, and organize emails from the terminal. Supports multiple accounts and message composition with MML (MIME Meta Language).
Monitor blogs and RSS/Atom feeds for updates using the blogwatcher CLI.
Category:tools