LimaCharlie Log In
v2
v1
Deprecated
v2
Contents
x
Getting Started
Sensors
Events
Query Console
Detection and Response
Platform Management
Outputs
Add-Ons
Tutorials
FAQ
Release Notes
Connecting
Powered by
LimaCharlie Extensions
15 Articles
in this category
Share this
Print
Share
Dark
Light
Contents
LimaCharlie Extensions
15 Articles
in this category
Share
Dark
Light
Artifact
The Artifact Extension provides low-level collection capabilities which can be configured to run automatically via Detection & Response rules, Sensor collections, or pushed via REST API. When enabled, an Artifact Collection menu will be avai...
Updated on : 01 Nov 2024
LimaCharlie CLI
LimaCharlie CLI Extension allows you to issue LimaCharlie CLI commands using extension requests. Repo - https://github.com/refractionPOINT/python-limacharlie You may use a D&R rule to trigger a LimaCharlie CLI event. For example the ...
Updated on : 15 Oct 2024
BinLib
Binary Library, or "BinLib", is a collection of executable binaries, such as EXE or ELF, files that have been observed within your environment. If enabled, this Extension helps you build your own private collection of observed executables for subs...
Updated on : 10 Dec 2024
Dumper
The Dumper Extension provides the ability to do dumping of several forensic artifacts on Windows hosts. It supports a single action, which is to dump. It supports multiple targets -- memory to dump the memory of the host, and mft to dump the ...
Updated on : 12 Nov 2024
Endpoint Protection
Overview The Endpoint Protection (EPP) management in LimaCharlie enables users to view the status of existing EPP solutions (including Windows Free Defender), manage parameters of the deployment and unify alerting from the deployment at scale. This...
Updated on : 28 May 2025
Exfil (Event Collection)
The Exfil Extension helps manage which real-time events get sent from EDR Sensors to LimaCharlie. By default, LimaCharlie Sensors send events to the cloud based on a standard profile. This extension exposes those profiles for customization. ...
Updated on : 02 Jan 2025
Git Sync
The Git Sync Extension is a tool that automates the management of Infrastructure-as-Code ( IaC ) configurations. It simplifies the process of deploying and managing infrastructure by synchronizing changes between a Git repository and target orga...
Updated on : 06 May 2025
Infrastructure
The Infrastructure Extension allows you to perform infrastructure-as-code ( IaC ) modifications to your Organization . IaC modifications can be made in the web UI or via the LimaCharlie CLI tool . Users can create new organizations from known te...
Updated on : 12 Feb 2025
Integrity
The Integrity Extension helps you manage all aspects of File or Registry Integrity Monitoring (FIM and RIM, respectively). This extension automates integrity checks of file system and registry values through pattern-based rules. Enabling the Inte...
Updated on : 11 Mar 2025
Lookup Manager
The Lookup Manager Extension allows you to create, maintain & automatically refresh lookups in the Organization to then reference them in Detection & Response Rules. The saved Lookup Configurations can be managed across tenants using I...
Updated on : 06 Aug 2025
Payload Manager
Payloads , such as scripts, pre-built binaries, or other files, can be deployed to LimaCharlie sensors for any reason necessary. One method of adding payloads to an Organization is via the web UI on the payloads screen. This is suitable for ad-h...
Updated on : 10 Dec 2024
Reliable Tasking
The Reliable Tasking Extension enables you to task a Sensor (s) that are currently offline. The extension will automatically send the task(s) to Sensor(s) once it comes online. Enabling the Reliable Tasking Extension To enable the Reliable Task...
Updated on : 12 Aug 2025
Sensor Cull
The Sensor Cull Extension performs continuous cleaning of "old" Sensors that have not connected to an Organization within a set period of time. This is useful for environments with cloud deployments or VM/template-based deployments that may en...
Updated on : 05 Oct 2024
Usage Alerts
The usage alerts Extension allows you to create, maintain, & automatically refresh usage alert conditions for an Organization . For example, you can create a usage alert rule that will fire a detection when artifact downloads have reached a...
Updated on : 09 Jan 2025
YARA Manager
The YARA manager Extension allows you to reference external YARA rules (rules maintained in GitHub, for example) to use in your YARA scans within LimaCharlie. YARA rule sources defined in the YARA manager configuration will be synced every 24 h...
Updated on : 31 Jul 2025