Windows Event Log Monitoring
The LimaCharlie sensor ingests Windows Event Logs directly and in real time, with no collectors or forwarding infrastructure to build. WEL data arrives as structured JSON, gets indexed against common indicators of compromise, and runs through the same detection engine as everything else.
Collect
Sensors stream WEL data as events occur. There is no forwarder tier to deploy, patch, or scale.
Detect
Because events arrive as JSON, writing custom detection rules against specific Windows events is the same exercise as writing any other rule. IOC indexing runs automatically on ingest.
Import history
Pull historical event logs from disk into the platform, so an investigation can reach back before the sensor was installed.
Respond
Detections on WEL data trigger the full range of response actions on the same endpoint, from process kills to network isolation.
Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.
Start freeBook a demo