In this video series, Maxime Lamothe-Brassard talks about leveraging open source resources to get up and running with threat coverage quickly using LimaCharlie. He walks through how to use Alien Vault’s Open Threat Exchange (OTX), Virus Total’s free tier API, curated collections of Sigma and YARA rules, and how to consume any threat feed of IP addresses or hashes. As well as talking about LimaCharlie’s curated Marketplace where people generating specialized intelligence can potentially sell access to their information.
In this video Maxime talks about how LimaCharlie can be used to leverage VirusTotal to check file hashes, including their free tier.
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content. Any user can select a file from their computer using their browser and send it to VirusTotal. VirusTotal offers a number of file submission methods, including the primary public web interface, desktop uploaders, browser extensions and a programmatic API. The web interface has the highest scanning priority among the publicly available submission methods. Submissions may be scripted in any programming language using the HTTP-based public API.
Learn more here: https://support.virustotal.com/hc/en-...
---
LimaCharlie provides an XDR capability along with all of the tools and infrastructure needed for an MSSP or SOC - including software defined secure networking. It is a highly scalable cloud-based solution that delivers everything on-demand using a SaaS model. All features can be accessed through the web application or programmatically via the API. Use a turnkey solution or develop your own. LimaCharlie can integrate with existing security pipelines and replace expensive vendors. Let us show you how.
----------------------------------
General Links
----------------------------------
Website: https://limacharlie.io
Documentation: https://doc.limacharlie.io/
Free Education: https://edu.limacharlie.io/
----------------------------------
Course Playlists
----------------------------------
Basic Detection & Response: • Basic Detection & Response
Advanced Detection & Response: • Advanced Detection & Response
Secure Access Service Edge: • Playlist
Leveraging Community Resources: • Leveraging the CLI & SDK
Setting up An MSSP: • Setting Up An MSSP with LimaCharlie
Using the CLI & SDK: • Leveraging the CLI & SDK
Ingesting Log Files & Artifacts: • Ingesting and Processing Artifacts (Window...
Zeek Network Monitoring: • Network Artifacts & Zeek
Incident Response: • DFIR
Real-time Windows Event Logs: • Ingesting Windows Event Logs
Responding to HAFNIUM: • HAFNIUM
The Add-on Marketplace: • Add-on Marketplace
----------------------------------
Social Media
----------------------------------
Community Slack Channel: https://slack.limacharlie.io/
Twitter: / limacharlieio
Reddit: / limacharlieio
LinkedIn: / limacharlieio
YouTube: / limacharlieio
Github: https://github.com/refractionPOINT