THOR Object Type Reference
Source: THOR --describe-object-type all (89 object types)
This reference maps every THOR object type to its available fields, types, and required status.
Use it when writing custom Sigma rules with product: THOR.
Field naming convention:
In THOR JSON output: lowercase with underscores (e.g., run_as_user, image.path)
In Sigma rules: UPPERCASE top-level field only (e.g., RUN_AS_USER, COMMAND)
Object null-check syntax exists but was observed matching all objects in THOR v11.0.0 — verify before relying on it
⚠️ Nested sub-fields (e.g., image.path, hashes.md5) are NOT directly referenceable in Sigma rules.
THOR's Sigma backend matches on top-level fields only . The tables in each object type doc show the JSON structure for reference, but you cannot write IMAGE.PATH or IMAGE_PATH in a Sigma rule.
Standard Sigma field mappings (from tmpl-sigma.yml):
CommandLine → command | ProcessId → pid | Image → image (object)
ParentImage → parent_info (object) | User → owner | TargetFilename → path
Object Type
Fields
Sigma Service
AmCache entry
9
product: THOR, service: "AmCache entry"
web download
4
product: THOR, service: "web download"
web page visit
4
product: THOR, service: "web page visit"
Object Type
Fields
Sigma Service
KnowledgeDB entry
6
product: THOR, service: "KnowledgeDB entry"
PowerShell module analysis cache module entry
3
product: THOR, service: "PowerShell module analysis cache module entry"
SRUM Resource Usage Entry
14
product: THOR, service: "SRUM Resource Usage Entry"
THOR assessment
10
product: THOR, service: "THOR assessment"
THOR invocation information
17
product: THOR, service: "THOR invocation information"
THOR message
5
product: THOR, service: "THOR message"
TeamViewer password
3
product: THOR, service: "TeamViewer password"
TestObject
7
product: THOR, service: "TestObject"
USN entry
4
product: THOR, service: "USN entry"
Unix permissions
4
product: THOR, service: "Unix permissions"
Windows permissions
3
product: THOR, service: "Windows permissions"
eBPF program
13
product: THOR, service: "eBPF program"
end of life report
3
product: THOR, service: "end of life report"
environment variable
3
product: THOR, service: "environment variable"
event
2
product: THOR, service: "event"
hotfix summary
2
product: THOR, service: "hotfix summary"
multiChoiceA
2
product: THOR, service: "multiChoiceA"
quarantine event
6
product: THOR, service: "quarantine event"
reason
4
product: THOR, service: "reason"
registered debugger
3
product: THOR, service: "registered debugger"
rootkit
1
product: THOR, service: "rootkit"
shellbag entry
4
product: THOR, service: "shellbag entry"
sparse data
3
product: THOR, service: "sparse data"
structured data from plugin
3
product: THOR, service: "structured data from plugin"
system information
12
product: THOR, service: "system information"
Object Type
Fields
Sigma Service
Linux kernel module
15
product: THOR, service: "Linux kernel module"
WMI element
7
product: THOR, service: "WMI element"
WMI startup command
4
product: THOR, service: "WMI startup command"
Windows service
11
product: THOR, service: "Windows service"
at job
2
product: THOR, service: "at job"
autorun entry
8
product: THOR, service: "autorun entry"
cron job
4
product: THOR, service: "cron job"
init.d service
2
product: THOR, service: "init.d service"
registry scheduled task
9
product: THOR, service: "registry scheduled task"
scheduled task
13
product: THOR, service: "scheduled task"
systemd service
6
product: THOR, service: "systemd service"
Object Type
Fields
Sigma Service
MFT entry
11
product: THOR, service: "MFT entry"
file
19
product: THOR, service: "file"
file chunk
5
product: THOR, service: "file chunk"
hosts file entry
3
product: THOR, service: "hosts file entry"
jump list entry
11
product: THOR, service: "jump list entry"
prefetch info
5
product: THOR, service: "prefetch info"
shim cache
3
product: THOR, service: "shim cache"
shim cache entry
4
product: THOR, service: "shim cache entry"
shim database entry
2
product: THOR, service: "shim database entry"
user profile
4
product: THOR, service: "user profile"
Object Type
Fields
Sigma Service
antivirus exclusion
3
product: THOR, service: "antivirus exclusion"
antivirus product
5
product: THOR, service: "antivirus product"
mutex
2
product: THOR, service: "mutex"
named pipe
2
product: THOR, service: "named pipe"
pipe list
2
product: THOR, service: "pipe list"
Object Type
Fields
Sigma Service
registry key
4
product: THOR, service: "registry key"
registry value
5
product: THOR, service: "registry value"