Using the Responder Sweep Tool

Опубликовано: 19 Май 2026
на канале: LimaCharlie
205
1

The responder - or sweep sensor functionality - is designed for incident responders or any one else trying to get the ground truth on a box.

With one click of a button you can get list of processes and modules, a list of any unsigned binary code, autoruns, services, drivers, network connections, which sockets are listening on which ports and what is active on the network. It will also look for hidden modules or any indicators that are new to your organization.

It is an easy and effective way to start an investigation.

----------------------------------
General Links
----------------------------------

Website: https://limacharlie.io

Documentation: https://doc.limacharlie.io/

Free Education: https://edu.limacharlie.io/

----------------------------------
Course Playlists
----------------------------------

Basic Detection & Response:    • Basic Detection & Response  

Advanced Detection & Response:    • Advanced Detection & Response  

Secure Access Service Edge:    • Playlist  

Leveraging Community Resources:    • Leveraging the CLI & SDK  

Setting up An MSSP:    • Setting Up An MSSP with LimaCharlie  

Using the CLI & SDK:    • Leveraging the CLI & SDK  

Ingesting Log Files & Artifacts:    • Ingesting and Processing Artifacts (Window...  

Zeek Network Monitoring:    • Network Artifacts & Zeek  

Incident Response:    • DFIR  

Real-time Windows Event Logs:    • Ingesting Windows Event Logs  

Responding to HAFNIUM:    • HAFNIUM  

The Add-on Marketplace:    • Add-on Marketplace  

----------------------------------
Social Media
----------------------------------

Community Slack Channel: https://slack.limacharlie.io/

Twitter:   / limacharlieio  

Reddit:   / limacharlieio  

LinkedIn:   / limacharlieio  

YouTube:    / limacharlieio  

Github: https://github.com/refractionPOINT