LimaCharlie Log In
Contents
x
Getting Started
Telemetry
Detection and Response
Platform Management
Outputs
Add-Ons
FAQ
Powered by
Responses
9 Articles
in this category
Contributors
Share this
Print
Share
Dark
Light
Contents
Responses
9 Articles
in this category
Written by
Matt Bromiley
Share
Dark
Light
Documents
GET_DOCUMENT_REP Generated when a doc_cache_get task requests a cached document. Platforms:
Written by
Matt Bromiley
Updated on : 19 Apr 2023
File and Registry Integrity Monitoring
This page contains details for events generated by File and Registry Integirty Monitoring, or "FIM", Sensor commands . FIM_ADD Response event for the fim_add sensor command. Platforms: FIM_DEL Response event for the fim_del...
Written by
Matt Bromiley
Updated on : 28 Apr 2023
Files and Directories
This page contains details for events generated by Files and Directories sensor commands. DIR_FINDHASH_REP Response event for the dir_find_hash sensor command. Platforms: { "DIRECTORY_LIST": [ { "HASH...
Written by
Matt Bromiley
Updated on : 06 Jul 2023
Management
This page contains details for events generated by Management sensor commands . GET_EXFIL_EVENT_REP Response from an exfil_get sensor command. Platforms: HISTORY_DUMP_REP Response from history_dump sensor command. Does not...
Written by
Matt Bromiley
Updated on : 19 Apr 2023
Memory
This page contains details for response events generated by Memory sensor commands . DEBUG_DATA_REP Response from a get_debug_data request. MEM_FIND_HANDLES_REP Response event for the mem_find_handle sensor command. Platforms: M...
Written by
Matt Bromiley
Updated on : 28 Apr 2023
Mitigation
This page contains details for response events generated by Mitigation sensor commands . REJOIN_NETWORK Emitted after a sensor is allowed network connectivity again (after it was previously segregated). Platforms: SEGREGATE_NETW...
Written by
Matt Bromiley
Updated on : 20 Apr 2023
Network
NETSTAT_REP This event is generated in response to the netstat command to list active network sockets. Platforms: PCAP_LIST_INTERFACES_REP Response from a pcap_ifaces request.
Written by
Matt Bromiley
Updated on : 06 Jul 2023
Operating System
OS_AUTORUNS_REP Response from an Autoruns listing request. Platforms: Windows, Linux, MacOS { "TIMESTAMP": 1456194620, "AUTORUNS": [ { "REGISTRY_KEY": "Software\\Microsoft\\Windows\\CurrentVersion\\Run\\VMware User Process", ...
Written by
Matt Bromiley
Updated on : 28 Apr 2023
Registry
REGISTRY_LIST_REP This event is generated in response to the reg_list command to list keys and values in a registry key. Platforms: Windows { "REGISTRY_KEY": [ "ActiveState", "ATI Technologies", "BreakPoint", "Ca...
Written by
Matt Bromiley
Updated on : 28 Apr 2023