The responder - or sweep sensor functionality - is designed for incident responders or any one else trying to get the ground truth on a box.
With one click of a button you can get list of processes and modules, a list of any unsigned binary code, autoruns, services, drivers, network connections, which sockets are listening on which ports and what is active on the network. It will also look for hidden modules or any indicators that are new to your organization.
It is an easy and effective way to start an investigation.
----------------------------------
General Links
----------------------------------
Website: https://limacharlie.io
Documentation: https://doc.limacharlie.io/
Free Education: https://edu.limacharlie.io/
----------------------------------
Course Playlists
----------------------------------
Basic Detection & Response: • Basic Detection & Response
Advanced Detection & Response: • Advanced Detection & Response
Secure Access Service Edge: • Playlist
Leveraging Community Resources: • Leveraging the CLI & SDK
Setting up An MSSP: • Setting Up An MSSP with LimaCharlie
Using the CLI & SDK: • Leveraging the CLI & SDK
Ingesting Log Files & Artifacts: • Ingesting and Processing Artifacts (Window...
Zeek Network Monitoring: • Network Artifacts & Zeek
Incident Response: • DFIR
Real-time Windows Event Logs: • Ingesting Windows Event Logs
Responding to HAFNIUM: • HAFNIUM
The Add-on Marketplace: • Add-on Marketplace
----------------------------------
Social Media
----------------------------------
Community Slack Channel: https://slack.limacharlie.io/
Twitter: / limacharlieio
Reddit: / limacharlieio
LinkedIn: / limacharlieio
YouTube: / limacharlieio
Github: https://github.com/refractionPOINT