LimaCharlie Log In
v2
v1
Deprecated
v2
Contents
x
Getting Started
Sensors
Query Console
Detection and Response
Events
Platform Management
Outputs
Add-Ons
FAQ
Release Notes
Powered by
Tutorials
7 Articles
in this category
Contributors
+ 2
Share this
Print
Share
Dark
Light
Contents
Tutorials
7 Articles
in this category
+ 2
Written by
Eric Capuano
,
Matt Bromiley
,
Whitney Champion
and 2 others
Share
Dark
Light
Ingesting Defender Event Logs
The Windows Sensor can listen, alert, and automate based on various Defender events. This is done by ingesting artifacts from the Defender Event Log Source and using Detection & Response rules to take the appropriate action. A config tem...
Written by
Eric Capuano
Updated on : 01 Nov 2024
Test a New Sensor Version
Prior to rolling out a new Sensor version, we recommend testing to ensure everything works as intended within your environment. While we test Sensors before releasing them, we cannot predict every niche use case. We also recommend testing on dev ...
Written by
Matt Bromiley
,
Eric Capuano
Updated on : 05 Oct 2024
Updating Sensors to the Newest Version
LimaCharlie releases a new version of the Sensor frequently - often every few weeks. However, we give you full control over what sensor version is running in your Organization . Sensors are not updated by default. There are two methods for updat...
Written by
Matt Bromiley
,
Eric Capuano
Updated on : 05 Oct 2024
Ingesting Sysmon Event Logs
Sysmon can be a valuable addition to any defender's toolkit, given it's verbosity and generous log data. It's worth noting that LimaCharlie's native EDR capabilities mirror much of the same telemetry. However, Sysmon and LimaCharlie can be combine...
Written by
Matt Bromiley
,
Whitney Champion
,
Eric Capuano
Updated on : 05 Oct 2024
Ingesting Linux Audit Logs
One data source of common interest on Linux systems is the audit.log file. By default, this file stores entries from the Audit system, which contains information about logins, privilege escalations, and other account-related events. You can find m...
Written by
Matt Bromiley
,
Eric Capuano
,
chris botelho
Updated on : 10 Dec 2024
Ingesting Windows Event Logs
You can enable real-time Windows Event Log (WEL) ingestion using the LimaCharlie EDR Sensor . First, navigate to the Exfil Control section of LimaCharlie and ensure that WEL events are enabled for your Windows rules. Next, navigate to th...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Eric Capuano
Updated on : 30 Oct 2024
Ingesting MacOS Unified Logs
You can enable real-time MacOS Unified Logs (MUL) ingestion using the LimaCharlie EDR Sensor . First, navigate to the Exfil Control section of LimaCharlie and ensure that MUL events are enabled for your Windows rules. Next, navigate to t...
Written by
Maxime Lamothe Brassard
,
Eric Capuano
Updated on : 31 Oct 2024