LimaCharlie Log In
v1
v1
Deprecated
v2
Contents
x
Getting Started
Telemetry
Detection and Response
Platform Management
Outputs
Add-Ons
FAQ
Powered by
LimaCharlie Extensions
12 Articles
in this category
Contributors
+ 1
Share this
Print
Share
Dark
Light
Contents
LimaCharlie Extensions
12 Articles
in this category
+ 1
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Whitney Champion
and 1 others
Share
Dark
Light
Sensor Cull
The Sensor Cull extension performs continuous cleaning of "old" Sensors that have not connected to an Organization within a set period of time. This is useful for environments with cloud deployments or VM/template-based deployments that may enroll S...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Whitney Champion
Updated on : 12 Feb 2024
Artifact
The Artifact extension provides low-level collection capabilities which can be configured to run automatically via Detection & Response rules, Sensor collections, or pushed via REST API. When enabled, an Artifact Collection menu will be availabl...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
Updated on : 30 May 2024
LimaCharlie CLI
LimaCharlie CLI extension allows you to issue LimaCharlie CLI commands using extension requests. Repo - HTTPS://GITHUB.COM/REFRACTIONPOINT/PYTHON-LIMACHARLIE You may use a D&R rule to trigger a LimaCharlie CLI event. For example the foll...
Updated on : 16 Apr 2024
BinLib
Binary Library, or "BinLib", is a collection of executable binaries, such as EXE or ELF, files that have been observed within your environment. If enabled, this extension helps you build your own private collection of observed executables for subseq...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
chris botelho
Updated on : 09 Jul 2024
Dumper
The Dumper extension provides the ability to do dumping of several forensic artifacts on Windows hosts. It supports a single action, which is to dump. It supports multiple targets-- memory to dump the memory of the host, and mft to dump the MFT...
Written by
Whitney Champion
Updated on : 25 Mar 2024
Exfil
The Exfil extension helps manage which real-time events get sent from EDR Sensors to LimaCharlie. By default, LimaCharlie Sensors send events to the cloud based on a standard profile. This extension exposes those profiles for customization. The Ex...
Written by
Matt Bromiley
Updated on : 12 Feb 2024
Infrastructure
The Infrastructure extension allows you to perform infrastructure-as-code (IaC) modifications to your Organization. IaC modifications can be made in the web UI or via the LimaCharlie CLI tool . Users can create new organizations from known template...
Written by
Matt Bromiley
Updated on : 12 Feb 2024
Integrity
The Integrity extension helps you manage all aspects of File or Registry Integrity Monitoring (FIM and RIM, respectively). This extension automates integrity checks of file system and registry values through pattern-based rules. Enabling the Integr...
Written by
Matt Bromiley
Updated on : 12 Feb 2024
Lookup Manager
The Lookup Manager extension allows you to create, maintain & automatically refresh lookups in the organization to then reference them in Detection & Response Rules. The saved Lookup Configurations can be managed across tenants using Infra...
Written by
Matt Bromiley
,
Whitney Champion
Updated on : 27 Sep 2024
Payload Manager
Payloads , such as scripts, pre-built binaries, or other files, can be deployed to LimaCharlie sensors for any reason necessary. One method of adding payloads to an organization is via the web UI on the payloads screen. This is suitable for ad-ho...
Written by
Matt Bromiley
,
Whitney Champion
,
chris botelho
Updated on : 10 Dec 2024
Reliable Tasking
The Reliable Tasking extension enables you to task a Sensor(s) that are currently offline. The extension will automatically send the task(s) to Sensor(s) once it comes online. Enabling the Reliable Tasking Extension To enable the Reliable Tasking ...
Written by
Matt Bromiley
Updated on : 12 Mar 2024
YARA Manager
The YARA manager extension allows you to reference external YARA rules (rules maintained in GitHub, for example) to use in your YARA scans within LimaCharlie. YARA rule sources defined in the YARA manager configuration will be synced every 24 ho...
Written by
Whitney Champion
Updated on : 27 Aug 2024