← All use cases

Endpoint Detection & Response (EDR)

LimaCharlie streams verbose endpoint telemetry to the cloud over a semi-persistent TLS connection, which means detection and response happen in real time rather than on a scan cycle. Response actions execute on the endpoint within 100 milliseconds of the triggering behavior.

How it runs on LimaCharlie
01

Deploy

Install sensors across Windows, macOS, Linux, and ChromeOS. Endpoints report in within seconds and stream telemetry continuously.

02

Detect

Write detection and response rules in a YAML syntax that supports stateful, multi-step logic, so you can catch behavior chains rather than single events. Turn on managed and open-source rulesets, including Sigma, SOC Prime, and Soteria, with one click, and run YARA rules fleet-wide.

03

Respond

Kill process trees, trigger memory dumps, isolate endpoints from the network, and run remediation scripts, all from the same rules that detect the behavior.

04

Extend

Ingest telemetry from an existing EDR and run LimaCharlie's detection engine on top of it. Teams migrating between endpoint vendors or covering mixed fleets keep one detection layer across everything.

Proof

When Black Hills Information Security moved off its previous stack, endpoint CPU load dropped from 70 percent to between 2 and 4 percent, and cost per endpoint was cut in half.

Threat huntingWindows event log monitoringSOAR / automation
DOCSSensor deploymentDOCSDetection logic operatorsBLOGDetection Engineering with LimaCharlie and Claude Code

Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.

Start freeBook a demo