LimaCharlie
@limacharlie
Security tools and infrastructure on-demand. Use LimaCharlie to automate and manage security operations at scale.
Most AI security products are black boxes. You see the output. You don't see what the agent did to get there. With Grid, every action an AI operator takes is logged, auditable, and inspectable through the same API surface that created it. See it for yourself: www.youtube.com/watch?v=Iihp...
Most AI in security workshops end with a pitch. This one ends with something you built. We're hosting a free hands-on lab at Black Hat with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com. 6 hours. Real infrastructure. @whit.zip @eric.zip @nynir.bsky.social luma.com/black-hat-he...
Our 101 virtual workshop is next Wed. covering everything from EDR deployment to automated threat response. Work directly inside the platform, deploying EDR agents, analyzing telemetry to surface IoCs, and writing D&R rules across the threat spectrum. limacharlie.wistia.com/live/events/...
Not every malware sample deserves analyst time. If it isn't packed, isn't encrypted, and doesn't have anything novel in it, Claude Code can handle the analysis. In a recent workshop, Chris Botelho builds out that workflow start to finish. Training access: training.limacharlie.io/courses/cc6c...
Demo today: Grid by LimaCharlie reducing service delivery costs in a real environment > Grid connects to your existing stack and handles repetitive review work > Every decision is logged with a full audit trail > Cost reduction starts on day one and scales limacharlie.wistia.com/live/events/...
The second you install our plugin in Claude Code, it knows everything about the platform and can act directly. > Generate a MITRE ATT&CK coverage report > Query telemetry across your environment > Write/deploy detection rules > Deploy sensors to new systems training.limacharlie.io/courses/e29e...
This week, Defender Fridays ends where it began — with creator @eric.zip, joining us for a final conversation on how he's actually using AI in the SOC. 100+ sessions. A community that showed up every single week. Over two years of defenders showing up for defenders. Thank you for being part of it.
Tomorrow, Carlo Anez, Founder at IgniteCyber Academy and DEF CON Training Instructor, joins us for a conversation on AI-assisted SOC training. They'll dig into building blue team skills using open-source labs, MITRE ATT&CK, and real-world defender workflows. info.limacharlie.io/defender-fri...
Most MSSPs run compliance the same way: manual audits, spreadsheets, repeat. We're showing how our compliance tooling changes the workflow. Run gap analysis, get continuous control classification, and produce structured audit evidence without the overhead. limacharlie.wistia.com/live/events/...
Today's session is live walking through a full dashboard build with Claude Code. > Fetch real-time data from LC API endpoints > Use Claude Code to generate and refine dashboard code > Package and deploy your dashboard as a self-contained application limacharlie.wistia.com/live/events/...
Our API-first architecture gave us an advantage when AI arrived. Because every platform function is exposed through the API, Claude Code can be taught everything it needs to operate your SOC, how to write detections, query telemetry, deploy sensors, and more. Learn more: limacharlie.io
Today on Defender Fridays, we're joined by Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, for a conversation on how analysts use cognitive reasoning in investigations. Tune in live: info.limacharlie.io/defender-fri...
Our next workshop is focused on building custom, stand-alone dashboard applications with Claude Code. This session walks through pulling real-time data from the API, generating frontend/backend code, and packaging the result as a self-contained application. limacharlie.wistia.com/live/events/...
The reason AI agents work differently in LimaCharlie comes down to how the platform was built. Because every capability was built to be accessed programmatically, achieving full AI parity through the MCP and CLI was a natural next step. A human analyst and an LLM now operate with the same access.
@eric.zip connected Claude Code to LimaCharlie and ran a live Cobalt Strike investigation. Every step was logged, auditable, and human-authorized. The ASW gives AI agents full platform access. For MSSPs, that means scaling operations without scaling headcount. limacharlie.io/blog/when-cl...
Today: Analyzing Real Malware with Claude Code and LimaCharlie. > Analyze an unknown binary and extract indicators > Use Claude Code to accelerate interpretation of configuration details and behaviors > Write and tune detection rules against runtime behavior limacharlie.wistia.com/live/events/...
Tomorrow, Ken Westin, Senior Solutions Engineer at LimaCharlie, joins Defender Fridays to share his AI story: a deliberate journey that deepened his sense of what the technology is truly capable of. Join us live: info.limacharlie.io/defender-fri...
Treat Claude Code like a junior analyst, not an autonomous agent. In our AI SecOps Workshop, attendees used Claude Code to deploy EDR agents to EC2 instances, pull in CloudTrail logs, and push detection rules from our partner Soteria, all from the terminal. www.youtube.com/watch?v=II_e...
Tomorrow on Defender Fridays, Katherine McNamara, Cybersecurity Technical Solutions Architect at Cisco, joins us to discuss how AI and ML adoption in enterprise infrastructure has expanded the attack surface for AI-driven systems. info.limacharlie.io/defender-fri...
Most AI SecOps vendors ship a fixed platform: the architecture, the workflows, the pricing model. Our position has always been the opposite. Build the capabilities and the value first, then give operators the freedom to modify, assemble, and build on top of them however their operation requires.
Tomorrow, Jeff McJunkin, Founder of Rogue Valley Information Security, joins Defender Fridays to talk AI-powered code scanning for vulnerabilities. He'll walk through real examples including using AI to find privilege escalation bugs in the Linux kernel. info.limacharlie.io/defender-fri...
Tomorrow's workshop covers how to use Claude Code to deploy agents, write detections, and surface cloud issues before escalation. Learn how to handle all of it using natural language, turning reactive cloud security tasks into proactive workflows. limacharlie.wistia.com/live/events/...
How do you know your AI agents are actually correct? Tomorrow, Dylan Williams of Spectrum Security joins Defender Fridays to dig into that exact problem: self-evaluating agents, trajectory analysis, and what improvement looks like in production. info.limacharlie.io/defender-fri...
Today we're showing what running a SOC on Claude Code looks like in production. We will be walking through live demos inside the Agentic SecOps Workspace: > Detection triage end-to-end > Composable agent stacking > The lc-agents repo limacharlie.wistia.com/live/events/... #ai #cybersecurity
Josh Neil, Co-founder of Alpha Level, joins Defender Fridays today to talk AI in the SOC. A more sophisticated industry understanding is unfolding, tune in and be part of it. info.limacharlie.io/defender-fri... #secops #ai #defenders
If you're at RSAC this week, we'd love to connect! Where to find us: > Visit Booth #1268 in the South Expo Hall for a TRON VR experience and a hands-on demo! > Join us for a happy hour tomorrow with our friends at Alpha Level. RSVP: luma.com/rsac-speakea... #RSAC #cybersecurity #secops
Andrew Cook, CTO of Recon InfoSec, joins Defender Fridays today to talk about what it means to build a strong security team and why hiring builders is always a good bet. Tune in live at 10:30am PT / 1:30pm ET: info.limacharlie.io/defender-fri... #defenders #secops #infosec
LimaCharlie's refreshed docs are fully open and structured for AI readability. No login, no subscription. LLMs and coding assistants can traverse it directly, which means agents building on the platform have accurate, accessible context without a human having to paste it in. docs.limacharlie.io
We're co-hosting a speakeasy social with our friends at Alpha Level at RSA next week. Wednesday, March 25 from 6-9PM at Bourbon & Branch, a genuine speakeasy that ran illegally through Prohibition, just blocks from Moscone. luma.com/rsac-speakea... #RSAC #cybersecurity #infosec
The first AI SecOps Workshop session is tomorrow! > Draft D&R rules from threat intelligence or observed behaviors > Tune existing rules using alert data to reduce false positives > Validate new and modified rules against simulated data limacharlie.wistia.com/live/events/... #claudecode #ai