> For the complete documentation index, see [llms.txt](https://docs.cloudcyte.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudcyte.com/getting-started/agent-based-deployment/10.-yara-analysis-and-thor.md).

# 10. YARA Analysis & THOR

The platform is using THOR for YARA analysis. Please add your Thor license file under the Thor policy. Please go to the Rules & Policies -> Policy Management -> Policy Rules, click on the "+Policy", select SIGMA & YARA module and select Windows YARA/THOR Lite Analysis or Windows YARA/THOR Analysis.

<figure><img src="/files/0ErxmIRJGita71u1BIPO" alt=""><figcaption></figcaption></figure>

Both Thor Lite and Thor Professional are supported. Once the license is added, please create a policy for THOR Analysis and assign the created license. The initial policy interface is configured for the recommended settings.

<figure><img src="/files/HqEIP6UZIoXBOlSa7CiL" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/l34P2DS0JhMzl5FYKDjt" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/BgYDdxk8VhIdVm09Rrd4" alt=""><figcaption></figcaption></figure>

Click on the "Save" button. Once the policy is created, please assign it to a group.

Click on the three dots and click edit.

<figure><img src="/files/5amsofyOC0gQihURuOWc" alt=""><figcaption></figcaption></figure>

Assign THOR policy to the group.

<figure><img src="/files/NEjFZDzkdg12rmqq0zuz" alt="" width="375"><figcaption></figcaption></figure>

The initial data will take 6-24 hours to be collected.
