Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why LimaCharlie's AI Sessions works with any model

Co-founder and COO I have been using AI coding tools since the beginning. Back around 2022, I built a RAG system that would return links to relevant documentation when users made a search request. Initially, I wanted the AI to answer the user's question directly, but at the time it would hallucinate so much that I didn't trust the output enough to put it in front of users. Instead, I had the AI return static links to the relevant documentation.

Run LimaCharlie AI Sessions on the model you choose

Co-founder and COO AI Sessions in the LimaCharlie web application now run on OpenAI, Google Gemini, and OpenRouter models in addition to Claude. Connect your own credentials, pick a provider per session profile, and the session behaves the same way regardless of which model is doing the work. Sessions run on Claude by default. Beyond that, you can connect any of the following with your own credentials.

Threat Hunting to Detection Engineering, Part 2: Validating Rules Against Live Malware with Claude and LimaCharlie

Senior Solutions Engineer In Part 1, we looked at how to use Claude to analyze an unknown binary given a basic Linux system. Analysis is only half of the job, though, and while we can reasonably assume that our rules will work, especially for high-fidelity indicators such as hashes and IPs, rules looking for behaviors get more challenging to build and validate.

The teams building their own agentic SOC already wrote the spec

Co-founder and COO Over the past eight months, security teams at Databricks, Salesforce, WRITER, Box, and Coinbase have published detailed accounts of building their own agentic security operations. None of them coordinated, and all of them arrived at the same architecture. Part of what made the surge possible is tooling. Agentic coding tools like Claude Code turned practitioners with deep systems knowledge into builders, and security teams were among the first to act on it.

Announcing LimaCharlie Cloud Security: a CNAPP built on the detection and response engine you already run

Co-founder and COO When a cloud security tool finds an over-permissioned identity, the finding goes into a dashboard. When your EDR sees that same identity's credential used on an endpoint, that goes into a different system. Connecting the two is your job, and it usually costs you an export pipeline, a pile of webhooks, and a SOAR license. For service providers the problem compounds.

What Headless Actually Means for Security Operations

Co-founder and COO LimaCharlie founder Maxime Lamothe-Brassard joined Alex Hurtado on the Detection Dispatch podcast to talk about the shift happening across the industry: security capabilities moving out from behind the UI. When every platform function is reachable through an API or CLI, both humans and AI agents can do the work without logging into a console. The episode covers what headless means in practice, how to govern agents in production, and where automation actually pays off.

What Is a Headless SOC?

Co-founder and COO Agentic SOC architecture, explained: how API-driven security operations work when AI agents are the primary operators. Most security operations centers are built around a dashboard. The dashboard is how analysts see what is happening, take action, respond to alerts, and manage cases. This design choice made sense when humans were the only operators in the environment.

Compliance mapping, automated audit evidence, and gap analysis in one toolkit

Co-founder and COO If you're running an MSSP or preparing for an audit, lc-compliance automatically documents relevant compliance evidence directly into your case records as they're created. Service providers work in a regulated environment, and already know compliance is a grind. Audits produce a pile of evidence requests. Your team pulls logs, traces detections back to controls, and writes documentation that no one reads until the QSA asks for it. Then you do it again next year.

Building SecOps that improve with every frontier AI release

CEO Maxime Lamothe-Brassard made an observation after the RSA conference that security vendors don't typically say out loud: "The frontier models are just better than anything people roll their own. There's no secret sauce these vendors are offering that is better than the latest frontier model release." That's a pointed claim that carries a significant implication buyers may not have fully considered.