LimaCharlie is now in Claude's official MCP connector directory. That means anyone using Claude can connect it directly to their LimaCharlie org with no custom integration work, just add the connector and go. claude.ai/directory/co...
LimaCharlie
@limacharlie.io
Security tools and infrastructure on-demand. Use LimaCharlie to automate and manage security operations at scale.
Next week at Black Hat, LimaCharlie, @bhinfosecurity.bsky.social, and @digitaldefenseinstitute.com are hosting a free, hands-on workshop. Most sessions send you home with notes. This one sends you home with working AI agents. 12-6pm at the Mandalay Bay Horizon Suite. luma.com/black-hat-he...
LimaCharlie Cloud Security covers posture management, identity and entitlement analysis, attack-path analysis, and AI security posture management across GCP, AWS, and Azure. $150 per org per month with a free 14-day trial on up to two cloud providers. app.limacharlie.io/onboard?purp...
A CNAPP with a $20,000 entry floor might be fine for one enterprise. Put it on 200 client proposals and it collapses for MSSPs. LimaCharlie Cloud Security was built for the other side of it: a complete CNAPP covering GCP, AWS, and Azure for $150 per org per month. app.limacharlie.io/onboard?purp...
Grid tracks what your AI operators are actually doing: automation rate, analyst hours freed, and cost per case, broken down by model, rules, and agent. Max covers cost profiling, our ROI dashboard, repetitive review work, cross-tenant operations, and audit trails: www.youtube.com/watch?v=Iihp...
CLUE and Databricks' triage agents converged on the same architecture independently. Both systems also end where response begins. An agent investigates and hands the finding to a human. Grid by LimaCharlie is built differently on both counts. Full breakdown: limacharlie.io/blog/agentic...
The gap between running a breach simulation and selling it as a managed service is a capacity problem. Grid closes it. Define a kill chain, point it at a tenant, and it runs daily across every client, evaluates coverage and feeds gaps to your workflow automatically. limacharlie.io/webinars?wch...
Our 101 workshop is this week! Work directly inside the platform deploying EDR agents, analyzing telemetry to surface IoCs, and writing D&R rules across the spectrum from malware to APTs. We also cover threat intelligence integration and YARA rule creation. limacharlie.wistia.com/live/events/...
LimaCharlie 101: EDR deployment, detection rules, and threat intelligence
This workshop will cover the basics of the LimaCharlie SecOps platform. You will learn how to deploy EDR agents, gather additional telemetry and write detection and response rules, and integrate threa...
lc.pub
Most AI security products are black boxes. You see the output. You don't see what the agent did to get there. With Grid, every action an AI operator takes is logged, auditable, and inspectable through the same API surface that created it. See it for yourself: www.youtube.com/watch?v=Iihp...
Most AI in security workshops end with a pitch. This one ends with something you built. We're hosting a free hands-on lab at Black Hat with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com. 6 hours. Real infrastructure. @whit.zip @eric.zip @nynir.bsky.social luma.com/black-hat-he...
Our 101 virtual workshop is next Wed. covering everything from EDR deployment to automated threat response. Work directly inside the platform, deploying EDR agents, analyzing telemetry to surface IoCs, and writing D&R rules across the threat spectrum. limacharlie.wistia.com/live/events/...
Our LimaCharlie 101 session on July 22nd covers the full arc, from agent deployment to automated response. You'll deploy EDR agents, write detection and response rules, and bring threat intelligence into your workflow live, in real time, on the platform. limacharlie.wistia.com/live/events/...
We're partnering with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com for a free Black Hat workshop. Spend the afternoon with @eric.zip and @whit.zip working through detection engineering, adversary analysis, and IR on real telemetry, every action auditable. luma.com/black-hat-he...
Not every malware sample deserves analyst time. If it isn't packed, isn't encrypted, and doesn't have anything novel in it, Claude Code can handle the analysis. In a recent workshop, Chris Botelho builds out that workflow start to finish. Training access: training.limacharlie.io/courses/cc6c...
No slides. No vendor pitch. Just six hours of hands-on building at Black Hat with @bhinfosecurity.bsky.social and @digitaldefenseinstitute.com. > Multi-agent hunting pipelines > Detection engineering on live infrastructure > Adversary analysis and IR with real telemetry luma.com/black-hat-he...
Demo today: Grid by LimaCharlie reducing service delivery costs in a real environment > Grid connects to your existing stack and handles repetitive review work > Every decision is logged with a full audit trail > Cost reduction starts on day one and scales limacharlie.wistia.com/live/events/...
Most MSSPs treat analyst review time as a fixed cost. Approval queues get absorbed into the service and nobody bills it back. Grid handles that work automatically, across your existing stack, with a full audit trail. Join us for a live demo: limacharlie.wistia.com/live/events/...
The second you install our plugin in Claude Code, it knows everything about the platform and can act directly. > Generate a MITRE ATT&CK coverage report > Query telemetry across your environment > Write/deploy detection rules > Deploy sensors to new systems training.limacharlie.io/courses/e29e...
This week, Defender Fridays ends where it began — with creator @eric.zip, joining us for a final conversation on how he's actually using AI in the SOC. 100+ sessions. A community that showed up every single week. Over two years of defenders showing up for defenders. Thank you for being part of it.
Tomorrow, Carlo Anez, Founder at IgniteCyber Academy and DEF CON Training Instructor, joins us for a conversation on AI-assisted SOC training. They'll dig into building blue team skills using open-source labs, MITRE ATT&CK, and real-world defender workflows. info.limacharlie.io/defender-fri...
Most MSSPs run compliance the same way: manual audits, spreadsheets, repeat. We're showing how our compliance tooling changes the workflow. Run gap analysis, get continuous control classification, and produce structured audit evidence without the overhead. limacharlie.wistia.com/live/events/...
Today's session is live walking through a full dashboard build with Claude Code. > Fetch real-time data from LC API endpoints > Use Claude Code to generate and refine dashboard code > Package and deploy your dashboard as a self-contained application limacharlie.wistia.com/live/events/...
Our API-first architecture gave us an advantage when AI arrived. Because every platform function is exposed through the API, Claude Code can be taught everything it needs to operate your SOC, how to write detections, query telemetry, deploy sensors, and more. Learn more: limacharlie.io
Today on Defender Fridays, we're joined by Chris Sanders, Founder at Applied Network Defense and the Rural Technology Fund, for a conversation on how analysts use cognitive reasoning in investigations. Tune in live: info.limacharlie.io/defender-fri...
Our next workshop is focused on building custom, stand-alone dashboard applications with Claude Code. This session walks through pulling real-time data from the API, generating frontend/backend code, and packaging the result as a self-contained application. limacharlie.wistia.com/live/events/...
The reason AI agents work differently in LimaCharlie comes down to how the platform was built. Because every capability was built to be accessed programmatically, achieving full AI parity through the MCP and CLI was a natural next step. A human analyst and an LLM now operate with the same access.
@eric.zip connected Claude Code to LimaCharlie and ran a live Cobalt Strike investigation. Every step was logged, auditable, and human-authorized. The ASW gives AI agents full platform access. For MSSPs, that means scaling operations without scaling headcount. limacharlie.io/blog/when-cl...
Today: Analyzing Real Malware with Claude Code and LimaCharlie. > Analyze an unknown binary and extract indicators > Use Claude Code to accelerate interpretation of configuration details and behaviors > Write and tune detection rules against runtime behavior limacharlie.wistia.com/live/events/...
Tomorrow, Ken Westin, Senior Solutions Engineer at LimaCharlie, joins Defender Fridays to share his AI story: a deliberate journey that deepened his sense of what the technology is truly capable of. Join us live: info.limacharlie.io/defender-fri...
Treat Claude Code like a junior analyst, not an autonomous agent. In our AI SecOps Workshop, attendees used Claude Code to deploy EDR agents to EC2 instances, pull in CloudTrail logs, and push detection rules from our partner Soteria, all from the terminal. www.youtube.com/watch?v=II_e...