LimaCharlie Log In
v2
v1
Deprecated
v2
Contents
x
Getting Started
Sensors
Query Console
Detection and Response
Events
Platform Management
Outputs
Add-Ons
FAQ
Powered by
LimaCharlie Extensions
12 Articles
in this category
Contributors
+ 2
Share this
Print
Share
Dark
Light
Contents
LimaCharlie Extensions
12 Articles
in this category
+ 2
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Eric Capuano
and 2 others
Share
Dark
Light
Artifact
The Artifact Extension provides low-level collection capabilities which can be configured to run automatically via Detection & Response rules, Sensor collections, or pushed via REST API. When enabled, an Artifact Collection menu will be avai...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Eric Capuano
Updated on : 01 Nov 2024
LimaCharlie CLI
LimaCharlie CLI Extension allows you to issue LimaCharlie CLI commands using extension requests. Repo - https://github.com/refractionPOINT/python-limacharlie You may use a D&R rule to trigger a LimaCharlie CLI event. For example the ...
Written by
Ross Haleliuk
,
Eric Capuano
Updated on : 15 Oct 2024
BinLib
Binary Library, or "BinLib", is a collection of executable binaries, such as EXE or ELF, files that have been observed within your environment. If enabled, this Extension helps you build your own private collection of observed executables for subs...
+ 1
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Ross Haleliuk
and 1 others
Updated on : 30 Oct 2024
Dumper
The Dumper Extension provides the ability to do dumping of several forensic artifacts on Windows hosts. It supports a single action, which is to dump. It supports multiple targets -- memory to dump the memory of the host, and mft to dump the ...
Written by
Whitney Champion
,
Eric Capuano
Updated on : 12 Nov 2024
Exfil (Event Collection)
The Exfil Extension helps manage which real-time events get sent from EDR Sensors to LimaCharlie. By default, LimaCharlie Sensors send events to the cloud based on a standard profile. This extension exposes those profiles for customization. ...
Written by
Matt Bromiley
,
Eric Capuano
Updated on : 05 Oct 2024
Infrastructure
The Infrastructure Extension allows you to perform infrastructure-as-code ( IaC ) modifications to your Organization . IaC modifications can be made in the web UI or via the LimaCharlie CLI tool . Users can create new organizations from known te...
Written by
Matt Bromiley
,
Eric Capuano
Updated on : 05 Oct 2024
Integrity
The Integrity Extension helps you manage all aspects of File or Registry Integrity Monitoring (FIM and RIM, respectively). This extension automates integrity checks of file system and registry values through pattern-based rules. Enabling the Inte...
Written by
Matt Bromiley
,
Eric Capuano
Updated on : 05 Oct 2024
Lookup Manager
The Lookup Manager Extension allows you to create, maintain & automatically refresh lookups in the Organization to then reference them in Detection & Response Rules. The saved Lookup Configurations can be managed across tenants using I...
Written by
Matt Bromiley
,
Whitney Champion
,
Eric Capuano
Updated on : 22 Oct 2024
Payload Manager
Payloads , such as scripts, pre-built binaries, or other files, can be deployed to LimaCharlie sensors for any reason necessary. One method of adding payloads to an Organization is via the web UI on the payloads screen. This is suitable for ad-h...
Written by
Matt Bromiley
,
Whitney Champion
,
Eric Capuano
Updated on : 05 Oct 2024
Reliable Tasking
The Reliable Tasking Extension enables you to task a Sensor (s) that are currently offline. The extension will automatically send the task(s) to Sensor(s) once it comes online. Enabling the Reliable Tasking Extension To enable the Reliable Task...
+ 1
Written by
Matt Bromiley
,
Ross Haleliuk
,
Whitney Champion
and 1 others
Updated on : 12 Nov 2024
Sensor Cull
The Sensor Cull Extension performs continuous cleaning of "old" Sensors that have not connected to an Organization within a set period of time. This is useful for environments with cloud deployments or VM/template-based deployments that may en...
+ 1
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Whitney Champion
and 1 others
Updated on : 05 Oct 2024
YARA Manager
The YARA manager Extension allows you to reference external YARA rules (rules maintained in GitHub, for example) to use in your YARA scans within LimaCharlie. YARA rule sources defined in the YARA manager configuration will be synced every 24 h...
Written by
Whitney Champion
,
Eric Capuano
Updated on : 05 Oct 2024