← All use cases

Threat Hunting

Every event, detection, and log ingested into LimaCharlie stays online and searchable for one year at no extra cost. Hunts run against real history instead of whatever survived a retention policy.

How a hunt runs on LimaCharlie
01

Scope

Start from a hypothesis, a threat intel report, or a new IOC. The full year of retained telemetry across the fleet is the hunting ground.

02

Hunt

Query telemetry with LCQL, LimaCharlie's query language, and pivot from any hit to every endpoint where the same indicator appears. Historical hunts run out of band, so they never compete with live detection.

03

Convert

Turn a confirmed finding directly into a detection and response rule. The gap between “we found it once” and “we catch it every time” is a few lines of YAML.

04

Repeat

Re-run hunts as intelligence evolves. Because the data is already retained and indexed, yesterday's hunt against today's IOCs costs a query, not a data restore.

EDRCyber threat intelligenceIncident response
DOCSLCQL query examplesDOCSDetection & response examplesWEBINARThreat Hunting for macOS

Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.

Start freeBook a demo