LimaCharlie Log In
v1
v1
Deprecated
v2
Contents
x
Getting Started
Telemetry
Detection and Response
Platform Management
Outputs
Add-Ons
FAQ
Powered by
Responses
10 Articles
in this category
Contributors
Share this
Print
Share
Dark
Light
Contents
Responses
10 Articles
in this category
Written by
Whitney Champion
Share
Dark
Light
Anomalies
HIDDEN_MODULE_DETECTED Generated when a hidden_module_scan command is issued. Note that the name of the event does not confirm the presence of a hidden module. Please check the output to confirm whether a hidden module was detected. Platf...
Updated on : 14 Feb 2024
Documents
GET_DOCUMENT_REP Generated when a doc_cache_get task requests a cached document. Platforms:
Updated on : 08 Feb 2024
File and Registry Integrity Monitoring
This page contains details for events generated by File and Registry Integirty Monitoring, or "FIM", Sensor commands . FIM_ADD Response event for the fim_add sensor command. An ERROR: 0 implies the path was successfully added. Platforms:...
Updated on : 20 Dec 2023
Files and Directories
This page contains details for events generated by Files and Directories sensor commands . DIR_FINDHASH_REP Response event for the dir_find_hash sensor command. Platforms: Sample Event: { "DIRECTORY_LIST": [ {...
Written by
Whitney Champion
Updated on : 13 Feb 2024
Management
This page contains details for events generated by Management sensor commands . GET_EXFIL_EVENT_REP Response from an exfil_get sensor command. Platforms: HISTORY_DUMP_REP Response from history_dump sensor command. Does not...
Updated on : 19 Apr 2023
Memory
This page contains details for response events generated by Memory sensor commands . DEBUG_DATA_REP Response from a get_debug_data request. MEM_FIND_HANDLES_REP Response event for the mem_find_handle sensor command. Platforms: ...
Updated on : 14 Feb 2024
Mitigation
This page contains details for response events generated by Mitigation sensor commands . REJOIN_NETWORK Emitted after a sensor is allowed network connectivity again (after it was previously segregated). An error code of 0 indicates success. ...
Written by
Whitney Champion
Updated on : 14 Feb 2024
Network
NETSTAT_REP Response from a netstat command to list active network sockets. Platforms: Sample Event: { "FRIENDLY": 0, "NETWORK_ACTIVITY": [ { "DESTINATION": { "IP_ADDRESS": "0.0.0.0", "PORT":...
Written by
Whitney Champion
Updated on : 14 Feb 2024
Operating System
OS_AUTORUNS_REP Response from an os_autoruns request. Platforms: Sample Event: { "TIMESTAMP": 1456194620, "AUTORUNS": [ { "REGISTRY_KEY": "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VMware User Process", ...
Written by
Whitney Champion
Updated on : 14 Feb 2024
Registry
REGISTRY_LIST_REP This event is generated in response to the reg_list command to list keys and values in a registry key. Platforms: Sample Event: { "REGISTRY_KEY": [ "ActiveState", "ATI Technologies", "BreakP...
Updated on : 14 Feb 2024