Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Building a bot takes five minutes. What it stands on took eight years. Introducing LimaCharlie Bots.

Co-founder and CCO We shipped bots in the LimaCharlie AI Terminal. You can create one in a few minutes: give it a role, pick a profile if you want one, and open a chat. I said this during our September Build Log demo and I'll repeat it here, because everything else in this post follows from it. The bot is the easy part.

How Soteria scaled its MDR practice on LimaCharlie

Soteria started as a consulting and advisory firm focused on penetration testing and incident response. Co-founder and managing principal Paul Ihme describes the company's growth from there as organic, expanding into virtual CISO work, offensive security, managed detection and response, and Microsoft 365 security products.

Why LimaCharlie's AI Sessions works with any model

Co-founder and COO I have been using AI coding tools since the beginning. Back around 2022, I built a RAG system that would return links to relevant documentation when users made a search request. Initially, I wanted the AI to answer the user's question directly, but at the time it would hallucinate so much that I didn't trust the output enough to put it in front of users. Instead, I had the AI return static links to the relevant documentation.

Run LimaCharlie AI Sessions on the model you choose

Co-founder and COO AI Sessions in the LimaCharlie web application now run on OpenAI, Google Gemini, and OpenRouter models in addition to Claude. Connect your own credentials, pick a provider per session profile, and the session behaves the same way regardless of which model is doing the work. Sessions run on Claude by default. Beyond that, you can connect any of the following with your own credentials.

Threat Hunting to Detection Engineering, Part 2: Validating Rules Against Live Malware with Claude and LimaCharlie

Senior Solutions Engineer In Part 1, we looked at how to use Claude to analyze an unknown binary given a basic Linux system. Analysis is only half of the job, though, and while we can reasonably assume that our rules will work, especially for high-fidelity indicators such as hashes and IPs, rules looking for behaviors get more challenging to build and validate.

The teams building their own agentic SOC already wrote the spec

Co-founder and COO Over the past eight months, security teams at Databricks, Salesforce, WRITER, Box, and Coinbase have published detailed accounts of building their own agentic security operations. None of them coordinated, and all of them arrived at the same architecture. Part of what made the surge possible is tooling. Agentic coding tools like Claude Code turned practitioners with deep systems knowledge into builders, and security teams were among the first to act on it.

Announcing LimaCharlie Cloud Security: a CNAPP built on the detection and response engine you already run

Co-founder and COO When a cloud security tool finds an over-permissioned identity, the finding goes into a dashboard. When your EDR sees that same identity's credential used on an endpoint, that goes into a different system. Connecting the two is your job, and it usually costs you an export pipeline, a pile of webhooks, and a SOAR license. For service providers the problem compounds.

What Headless Actually Means for Security Operations

Co-founder and COO LimaCharlie founder Maxime Lamothe-Brassard joined Alex Hurtado on the Detection Dispatch podcast to talk about the shift happening across the industry: security capabilities moving out from behind the UI. When every platform function is reachable through an API or CLI, both humans and AI agents can do the work without logging into a console. The episode covers what headless means in practice, how to govern agents in production, and where automation actually pays off.

What Is a Headless SOC?

Co-founder and COO Agentic SOC architecture, explained: how API-driven security operations work when AI agents are the primary operators. Most security operations centers are built around a dashboard. The dashboard is how analysts see what is happening, take action, respond to alerts, and manage cases. This design choice made sense when humans were the only operators in the environment.