LimaCharlie Log In
v1
v1
Deprecated
v2
Contents
x
Getting Started
Telemetry
Detection and Response
Platform Management
Outputs
Add-Ons
FAQ
Powered by
System
8 Articles
in this category
Contributors
+ 1
Share this
Print
Share
Dark
Light
Contents
System
8 Articles
in this category
+ 1
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Whitney Champion
and 1 others
Share
Dark
Light
Drivers
DRIVER_CHANGE Generated when a Driver is changed. Platforms: { "PROCESS_ID": 0, "SVC_DISPLAY_NAME": "HbsAcq", "SVC_NAME": "HbsAcq", "SVC_STATE": 1, "SVC_TYPE": 1, "TIMESTAMP": 1517377895873 }
Written by
Matt Bromiley
Updated on : 05 Dec 2023
Files
FILE_CREATE Generated when a file is created. Platforms: { "FILE_PATH": "C:\\Users\\dev\\AppData\\Local\\Microsoft\\Windows\\WebCache\\V01tmp.log", "TIMESTAMP": 1468335271948 } FILE_DELETE Generated when a file is delete...
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
Updated on : 19 Jun 2024
Network
DNS_REQUEST Generated from DNS responses and therefore includes both the requested domain and the response from the server. If the server responds with multiple responses (as allowed by the DNS protocol) the N answers will become N DNS_REQUEST eve...
Written by
Matt Bromiley
Updated on : 05 Jun 2023
Processes
CODE_IDENTITY Unique combinations of file hash and file path. Event is emitted the first time the combination is seen, but only when the binary is executed or loaded. Therefore it's a great event to look for hashes without being overwhelmed by pro...
+ 1
Written by
Matt Bromiley
,
Maxime Lamothe Brassard
,
Whitney Champion
and 1 others
Updated on : 26 Aug 2024
Registry
General references on the Windows registry are available here and here . LimaCharlie's EDR Sensor observes the Windows Registry from kernel-mode. Registry hive naming conventions are specific to the operating system version, but may also have a...
Written by
Matt Bromiley
Updated on : 09 Apr 2024
Services
AUTORUN_CHANGE Generated when an Autorun is changed. Platforms: SERVICE_CHANGE Generated when a Service is changed. Platforms: { "PROCESS_ID": 0, "SVC_TYPE": 32, "DLL": "%SystemRoot%\\system32\\wlidsvc.dll", "S...
Written by
Matt Bromiley
Updated on : 10 Dec 2023
Users
USER_OBSERVED Generated the first time a user is observed on a host. Platforms: { "TIMESTAMP": 1479241363009, "USER_NAME": "root" }
Written by
Matt Bromiley
Updated on : 10 Dec 2023
Volumes
VOLUME_MOUNT This event is generated when a volume is mounted. Platforms: { "VOLUME_PATH": "E:", "DEVICE_NAME": "\\Device\\HarddiskVolume3" } VOLUME_UNMOUNT This event is generated when a volume is unmounted. Plat...
Written by
Matt Bromiley
Updated on : 28 Apr 2023