> For the complete documentation index, see [llms.txt](https://docs.cloudcyte.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudcyte.com/getting-started/agent-based-deployment/10.-yara-analysis-and-thor.md).

# 10. YARA Analysis & THOR

The platform is using THOR for YARA analysis. Please add your Thor license file under the Thor policy. Please go to the Rules & Policies -> Policy Management -> Policy Rules, click on the "+Policy", select SIGMA & YARA module and select Windows YARA/THOR Lite Analysis or Windows YARA/THOR Analysis.

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2FfXwpVaZD0bwhqrEcVEUf%2Fimage.png?alt=media&amp;token=abe0b900-a93f-475a-b2d5-3fff64b415e7" alt=""><figcaption></figcaption></figure>

Both Thor Lite and Thor Professional are supported. Once the license is added, please create a policy for THOR Analysis and assign the created license. The initial policy interface is configured for the recommended settings.

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2FSFJJBmXwwgrtZA9baKMx%2Fimage.png?alt=media&amp;token=6f331360-9fa7-4ad4-89ca-dced2194bff0" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2Ff6eH0MuNnXFYSeOQP6wW%2Fimage.png?alt=media&amp;token=53318863-becd-4aff-85d9-300c1fb40705" alt=""><figcaption></figcaption></figure>

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2FI7t1j7U7JAEFGcDNIFrM%2Fimage.png?alt=media&amp;token=16efdbea-dcfb-48d8-bc7e-b0b628f78e62" alt=""><figcaption></figcaption></figure>

Click on the "Save" button. Once the policy is created, please assign it to a group.

Click on the three dots and click edit.

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2FJ1atCfVYm1AFWPM9eHOW%2Fimage.png?alt=media&amp;token=bf407893-a8de-4841-8481-0e2c4ca47216" alt=""><figcaption></figcaption></figure>

Assign THOR policy to the group.

<figure><img src="https://1723175359-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-LuHp6M9xm4Gdg2pWusc%2Fuploads%2FdOhUzSFbISN0RyonxTlO%2Fimage.png?alt=media&amp;token=016face3-055b-4d51-a3b3-f0ff4d2b31a0" alt="" width="375"><figcaption></figcaption></figure>

The initial data will take 6-24 hours to be collected.
