cisagov/thorium
A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale. observed · 2026-08-28
Health v2 · maintenance only
74/100
- Activity 91
- Release rhythm 73
- Longevity 36
Flags: no_license
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 9.0
- age_days: 504
- days_rel: 181
- days_push: 57
- n_releases_24m: 9
Adoption not part of the score
1022 stars · 121 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
Thorium is a scalable, distributed file analysis and data generation platform that orchestrates arbitrary Docker, VM, or shell-based tools at scale, primarily aimed at malware analysis and cyber incident response. It provides sandboxed static and dynamic analysis, full-text search of results, tagging, and multi-tenant sharing via GUI, CLI, and RESTful API.
Use cases
- analyze malware samples at scale with docker-based tools
- orchestrate file analysis pipelines across a kubernetes cluster
- triage files during cyber incident response
- search and share analysis results across an analyst team
- run reverse engineering tools like capa and floss on uploaded binaries
- store and tag billions of samples with metadata
When to choose
- you need to run many analysis tools over large volumes of files in a scalable, multi-tenant way
- you want sandboxed static and dynamic malware analysis with encrypted file storage (CaRT)
- you need a REST API, CLI, and GUI over a shared file analysis repository
When to avoid
- you only need a simple single-machine scanner - the production deployment requires a Kubernetes cluster, block store, and S3 storage
- you need a lightweight pipeline runner without the analysis/search/sharing platform overhead
- single-node Minithor deployments are not intended for production use
Facets
application · maturity active
workflow-automation container-orchestration search-engine security api-framework cli gui file-upload analytics security developer-tools self-hosted microservices rust self-hosted cloud malware-analysis file-analysis incident-response sandboxing multi-tenant data-generation reverse-engineering-tools automation kubernetes docker linux
2 sources
- readme: https://github.com/cisagov/thorium · fetched 2026-08-28 · 0df015d57921
- homepage: https://cisagov.github.io/thorium/ · fetched 2026-08-29 · f8874bb5ad53
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| cisagov/thorium | main | 74 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem