Sign in

LimaCharlie

@limacharlie.io
2.5K followers 19 following 249 posts

Security tools and infrastructure on-demand. Use LimaCharlie to automate and manage security operations at scale.

PostsRepliesMedia
LimaCharlie @limacharlie.io · 29/09/2026
AI Sessions in the LimaCharlie web application now run on OpenAI, Google Gemini, and OpenRouter models, in addition to Claude. Connect your own credentials and pick a provider per session profile. The session behaves the same no matter which model is doing the work. limacharlie.io/blog/ai-sess...
000
LimaCharlie @limacharlie.io · 25/09/2026
SECNAP walks through what happens when an AI agent gets the first look at a multi-alert incident. This live attack simulation shows where their AI agents handled tier one and tier two triage end to end before a human analyst reviewed and approved the response. www.youtube.com/watch?v=izQC...
000
LimaCharlie @limacharlie.io · 23/09/2026
Rules that work well for smaller customers can break down the moment a much larger customer comes on board. Our infrastructure lets Soteria manage customization at scale, storing detection rules and configurations in GitHub and deploying changes across tenants. www.youtube.com/watch?v=kt7K...
000
LimaCharlie @limacharlie.io · 22/09/2026
In Grid we can set up multi-agent workflows with one agent collecting data, another analyzing it, and a third handling mitigation. See what's driving MSSPs to adopt AI, how infrastructure-level AI differs from advisory tools, and how to keep humans in the loop: www.youtube.com/watch?v=nY5Y...
000
LimaCharlie @limacharlie.io · 21/09/2026
AI agents in the SOC can take real action, which means access control isn't optional. In a recent webinar, we explain why role-based access controls are what make autonomous AI safe to deploy: agents only get the permissions you configure, nothing more. www.youtube.com/watch?v=nY5Y...
011
LimaCharlie @limacharlie.io · 18/09/2026
Paul Ihme, co-founder of Soteria, sat down with us to talk through the tuning work that came with scaling their client base, how Soteria structures detection rules across customer environments, and the build versus buy decision that shaped their whole MDR practice. www.youtube.com/watch?v=kt7K...
000
LimaCharlie @limacharlie.io · 14/09/2026
Get a practical roadmap for moving AI in the MSSP SOC from pilots to production. We'll cover where AI delivers value first, what your telemetry needs to look like before AI can help, and how to keep humans in control with approval workflows and full audit trails. limacharlie.io/webinars/fro...
000
LimaCharlie @limacharlie.io · 10/09/2026
LimaCharlie Cloud Security is our CNAPP for AWS, GCP, and Azure. What makes it different starts with how it's built: every page pulls from the same underlying security graph, instead of treating each area as its own silo. That model powers the entire platform: www.youtube.com/watch?v=kY41...
lc.pub
LimaCharlie Cloud Security: CNAPP Walkthrough
Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
000
LimaCharlie @limacharlie.io · 09/09/2026
Without control over the infrastructure underneath, AI in the SOC can advise, but every action still runs through a human. Next week we'll lay out a roadmap for moving AI in the MSSP SOC from pilots to production. Join the session: limacharlie.io/webinars/fro...
000
LimaCharlie @limacharlie.io · 02/09/2026
Our CNAPP, LimaCharlie Cloud Security, is built directly on the same detection and response engine as the rest of the platform. Every finding it produces lands in your tenant's event stream as a native event, the moment it's produced, alongside endpoint telemetry and everything else you ingest.
000
LimaCharlie @limacharlie.io · 31/08/2026
In a live attack simulation on LimaCharlie, SECNAP's AI agent investigated a sandboxed host and passed findings for human analyst review. This is what human oversight looks like: every agent action stays visible to the analyst before anything reaches the customer www.youtube.com/watch?v=izQC...
010
LimaCharlie @limacharlie.io · 26/08/2026
The gap between running a breach simulation and selling it as a recurring managed service is mostly a capacity problem. Grid closes it. Define a kill chain, point at a tenant, and it runs daily across every client, evaluates coverage, and feeds gaps back to your workflow automatically.
010
LimaCharlie @limacharlie.io · 24/08/2026
Tune in Wed. to see how SECNAP built a full agentic MDR platform on top of LimaCharlie. We will walk through the customer portal, the SOC dashboard, and a live attack simulation showing how AI agents handle triage before a human reviews/approves the response. limacharlie.io/webinars/ins...
011
LimaCharlie @limacharlie.io · 21/08/2026
Cloud Security is built directly inside LimaCharlie, so every finding lands in the same detection and response engine already running endpoint fleets and telemetry for security teams and MSSPs. There's no separate SKU and no integration project. Free trial: app.limacharlie.io/onboard?purp...
000
LimaCharlie @limacharlie.io · 19/08/2026
Build a complete detection pipeline with Claude Code today at 10am PT. We'll walk through: ingesting a cloud log source, authoring a detection rule and validating it against historical telemetry, deploying an EDR agent, and shipping a custom dashboard app. limacharlie.io/webinars/hea...
010
LimaCharlie @limacharlie.io · 17/08/2026
This Wed. we'll run a hands-on session where you'll connect Claude Code directly to Grid in a live environment. Ingest a cloud log source, author a detection rule and validate it against historical telemetry, deploy an EDR agent, and ship a custom dashboard app. limacharlie.io/webinars/hea...
010
LimaCharlie @limacharlie.io · 12/08/2026
LimaCharlie Cloud Security is now available - a CNAPP for GCP, AWS, and Azure at $150 per org/month. Every finding it produces is a native event in the same detection and response engine that already runs endpoint fleets, ingests telemetry, and executes response. app.limacharlie.io/onboard?purp...
000
LimaCharlie @limacharlie.io · 11/08/2026
By the end of our upcoming workshop, you'll have a working detection pipeline built, a cloud log source ingested, and a custom dashboard app shipped, all with Claude Code connected directly to Grid. No prior LimaCharlie experience needed. Seats are limited: limacharlie.io/webinars/hea...
000
LimaCharlie @limacharlie.io · 10/08/2026
Our recent Cloud Security launch gives Claude Code API access to CNAPP findings the same way it already has access to endpoint telemetry. Once that access exists, capability stops being the limit. Start a free 14-day trial: app.limacharlie.io/onboard?purp...
010
LimaCharlie @limacharlie.io · 30/07/2026
LimaCharlie is now in Claude's official MCP connector directory. That means anyone using Claude can connect it directly to their LimaCharlie org with no custom integration work, just add the connector and go. claude.ai/directory/co...
010
LimaCharlie @limacharlie.io · 30/07/2026
Next week at Black Hat, LimaCharlie, @bhinfosecurity.bsky.social, and @digitaldefenseinstitute.com are hosting a free, hands-on workshop. Most sessions send you home with notes. This one sends you home with working AI agents. 12-6pm at the Mandalay Bay Horizon Suite. luma.com/black-hat-he...
020
LimaCharlie @limacharlie.io · 29/07/2026
LimaCharlie Cloud Security covers posture management, identity and entitlement analysis, attack-path analysis, and AI security posture management across GCP, AWS, and Azure. $150 per org per month with a free 14-day trial on up to two cloud providers. app.limacharlie.io/onboard?purp...
011
LimaCharlie @limacharlie.io · 28/07/2026
A CNAPP with a $20,000 entry floor might be fine for one enterprise. Put it on 200 client proposals and it collapses for MSSPs. LimaCharlie Cloud Security was built for the other side of it: a complete CNAPP covering GCP, AWS, and Azure for $150 per org per month. app.limacharlie.io/onboard?purp...
000
LimaCharlie @limacharlie.io · 27/07/2026
Grid tracks what your AI operators are actually doing: automation rate, analyst hours freed, and cost per case, broken down by model, rules, and agent. Max covers cost profiling, our ROI dashboard, repetitive review work, cross-tenant operations, and audit trails: www.youtube.com/watch?v=Iihp...
011
LimaCharlie @limacharlie.io · 24/07/2026
CLUE and Databricks' triage agents converged on the same architecture independently. Both systems also end where response begins. An agent investigates and hands the finding to a human. Grid by LimaCharlie is built differently on both counts. Full breakdown: limacharlie.io/blog/agentic...
000
LimaCharlie @limacharlie.io · 20/07/2026
Our 101 workshop is this week! Work directly inside the platform deploying EDR agents, analyzing telemetry to surface IoCs, and writing D&R rules across the spectrum from malware to APTs. We also cover threat intelligence integration and YARA rule creation. limacharlie.wistia.com/live/events/...
lc.pub
LimaCharlie 101: EDR deployment, detection rules, and threat intelligence
This workshop will cover the basics of the LimaCharlie SecOps platform. You will learn how to deploy EDR agents, gather additional telemetry and write detection and response rules, and integrate threa...
001
LimaCharlie @limacharlie.io · 17/07/2026
Most AI security products are black boxes. You see the output. You don't see what the agent did to get there. With Grid, every action an AI operator takes is logged, auditable, and inspectable through the same API surface that created it. See it for yourself: www.youtube.com/watch?v=Iihp...
000
LimaCharlie @limacharlie.io · 15/07/2026
Most AI in security workshops end with a pitch. This one ends with something you built. We're hosting a free hands-on lab at Black Hat with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com. 6 hours. Real infrastructure. @whit.zip @eric.zip @nynir.bsky.social luma.com/black-hat-he...
022
LimaCharlie @limacharlie.io · 13/07/2026
Our 101 virtual workshop is next Wed. covering everything from EDR deployment to automated threat response. Work directly inside the platform, deploying EDR agents, analyzing telemetry to surface IoCs, and writing D&R rules across the threat spectrum. limacharlie.wistia.com/live/events/...
010
LimaCharlie @limacharlie.io · 02/07/2026
Our LimaCharlie 101 session on July 22nd covers the full arc, from agent deployment to automated response. You'll deploy EDR agents, write detection and response rules, and bring threat intelligence into your workflow live, in real time, on the platform. limacharlie.wistia.com/live/events/...
000
LimaCharlie @limacharlie.io · 30/06/2026
We're partnering with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com for a free Black Hat workshop. Spend the afternoon with @eric.zip and @whit.zip working through detection engineering, adversary analysis, and IR on real telemetry, every action auditable. luma.com/black-hat-he...
174
LimaCharlie @limacharlie.io · 26/06/2026
Not every malware sample deserves analyst time. If it isn't packed, isn't encrypted, and doesn't have anything novel in it, Claude Code can handle the analysis. In a recent workshop, Chris Botelho builds out that workflow start to finish. Training access: training.limacharlie.io/courses/cc6c...
000
LimaCharlie @limacharlie.io · 24/06/2026
No slides. No vendor pitch. Just six hours of hands-on building at Black Hat with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com. > Multi-agent hunting pipelines > Detection engineering on live infrastructure > Adversary analysis and IR with real telemetry luma.com/black-hat-he...
000
LimaCharlie @limacharlie.io · 24/06/2026
Demo today: Grid by LimaCharlie reducing service delivery costs in a real environment > Grid connects to your existing stack and handles repetitive review work > Every decision is logged with a full audit trail > Cost reduction starts on day one and scales limacharlie.wistia.com/live/events/...
000
LimaCharlie @limacharlie.io · 22/06/2026
Most MSSPs treat analyst review time as a fixed cost. Approval queues get absorbed into the service and nobody bills it back. Grid handles that work automatically, across your existing stack, with a full audit trail. Join us for a live demo: limacharlie.wistia.com/live/events/...
000
LimaCharlie @limacharlie.io · 16/06/2026
The second you install our plugin in Claude Code, it knows everything about the platform and can act directly. > Generate a MITRE ATT&CK coverage report > Query telemetry across your environment > Write/deploy detection rules > Deploy sensors to new systems training.limacharlie.io/courses/e29e...
000
LimaCharlie @limacharlie.io · 09/06/2026
This week, Defender Fridays ends where it began — with creator @eric.zip, joining us for a final conversation on how he's actually using AI in the SOC. 100+ sessions. A community that showed up every single week. Over two years of defenders showing up for defenders. Thank you for being part of it.
021
LimaCharlie @limacharlie.io · 04/06/2026
Tomorrow, Carlo Anez, Founder at IgniteCyber Academy and DEF CON Training Instructor, joins us for a conversation on AI-assisted SOC training. They'll dig into building blue team skills using open-source labs, MITRE ATT&CK, and real-world defender workflows. info.limacharlie.io/defender-fri...
010
LimaCharlie @limacharlie.io · 03/06/2026
Most MSSPs run compliance the same way: manual audits, spreadsheets, repeat. We're showing how our compliance tooling changes the workflow. Run gap analysis, get continuous control classification, and produce structured audit evidence without the overhead. limacharlie.wistia.com/live/events/...
000
LimaCharlie @limacharlie.io · 27/05/2026
Today's session is live walking through a full dashboard build with Claude Code. > Fetch real-time data from LC API endpoints > Use Claude Code to generate and refine dashboard code > Package and deploy your dashboard as a self-contained application limacharlie.wistia.com/live/events/...
000
LimaCharlie @limacharlie.io · 26/05/2026
Our API-first architecture gave us an advantage when AI arrived. Because every platform function is exposed through the API, Claude Code can be taught everything it needs to operate your SOC, how to write detections, query telemetry, deploy sensors, and more. Learn more: limacharlie.io
000
LimaCharlie @limacharlie.io · 15/05/2026
Today on Defender Fridays, we're joined by Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, for a conversation on how analysts use cognitive reasoning in investigations. Tune in live: info.limacharlie.io/defender-fri...
000
LimaCharlie @limacharlie.io · 14/05/2026
Our next workshop is focused on building custom, stand-alone dashboard applications with Claude Code. This session walks through pulling real-time data from the API, generating frontend/backend code, and packaging the result as a self-contained application. limacharlie.wistia.com/live/events/...
011
LimaCharlie @limacharlie.io · 12/05/2026
The reason AI agents work differently in LimaCharlie comes down to how the platform was built. Because every capability was built to be accessed programmatically, achieving full AI parity through the MCP and CLI was a natural next step. A human analyst and an LLM now operate with the same access.
000
LimaCharlie @limacharlie.io · 08/05/2026
@eric.zip connected Claude Code to LimaCharlie and ran a live Cobalt Strike investigation. Every step was logged, auditable, and human-authorized. The ASW gives AI agents full platform access. For MSSPs, that means scaling operations without scaling headcount. limacharlie.io/blog/when-cl...
252
LimaCharlie @limacharlie.io · 06/05/2026
Today: Analyzing Real Malware with Claude Code and LimaCharlie. > Analyze an unknown binary and extract indicators > Use Claude Code to accelerate interpretation of configuration details and behaviors > Write and tune detection rules against runtime behavior limacharlie.wistia.com/live/events/...
020
LimaCharlie @limacharlie.io · 30/04/2026
Tomorrow, Ken Westin, Senior Solutions Engineer at LimaCharlie, joins Defender Fridays to share his AI story: a deliberate journey that deepened his sense of what the technology is truly capable of. Join us live: info.limacharlie.io/defender-fri...
000
LimaCharlie @limacharlie.io · 30/04/2026
Treat Claude Code like a junior analyst, not an autonomous agent. In our AI SecOps Workshop, attendees used Claude Code to deploy EDR agents to EC2 instances, pull in CloudTrail logs, and push detection rules from our partner Soteria, all from the terminal. www.youtube.com/watch?v=II_e...
000
LimaCharlie @limacharlie.io · 28/04/2026
On May 6th, we're hosting a hands-on malware analysis workshop with Claude Code. You will extract indicators using the LCRE tool, execute the sample in a sandboxed VM, and use what they observe to write and validate detection rules based on runtime behavior. limacharlie.wistia.com/live/events/...
010
LimaCharlie @limacharlie.io · 23/04/2026
Tomorrow on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems. info.limacharlie.io/defender-fri...
000