Mountain View, CA, USA
2018
  |  By Chris Luft
Soteria started as a consulting and advisory firm focused on penetration testing and incident response. Co-founder and managing principal Paul Ihme describes the company's growth from there as organic, expanding into virtual CISO work, offensive security, managed detection and response, and Microsoft 365 security products.
  |  By LimaCharlie
Co-founder and COO I have been using AI coding tools since the beginning. Back around 2022, I built a RAG system that would return links to relevant documentation when users made a search request. Initially, I wanted the AI to answer the user's question directly, but at the time it would hallucinate so much that I didn't trust the output enough to put it in front of users. Instead, I had the AI return static links to the relevant documentation.
  |  By LimaCharlie
Co-founder and COO AI Sessions in the LimaCharlie web application now run on OpenAI, Google Gemini, and OpenRouter models in addition to Claude. Connect your own credentials, pick a provider per session profile, and the session behaves the same way regardless of which model is doing the work. Sessions run on Claude by default. Beyond that, you can connect any of the following with your own credentials.
  |  By LimaCharlie
Senior Solutions Engineer In Part 1, we looked at how to use Claude to analyze an unknown binary given a basic Linux system. Analysis is only half of the job, though, and while we can reasonably assume that our rules will work, especially for high-fidelity indicators such as hashes and IPs, rules looking for behaviors get more challenging to build and validate.
  |  By LimaCharlie
Co-founder and COO Over the past eight months, security teams at Databricks, Salesforce, WRITER, Box, and Coinbase have published detailed accounts of building their own agentic security operations. None of them coordinated, and all of them arrived at the same architecture. Part of what made the surge possible is tooling. Agentic coding tools like Claude Code turned practitioners with deep systems knowledge into builders, and security teams were among the first to act on it.
  |  By LimaCharlie
Co-founder and COO When a cloud security tool finds an over-permissioned identity, the finding goes into a dashboard. When your EDR sees that same identity's credential used on an endpoint, that goes into a different system. Connecting the two is your job, and it usually costs you an export pipeline, a pile of webhooks, and a SOAR license. For service providers the problem compounds.
  |  By LimaCharlie
Co-founder and COO LimaCharlie founder Maxime Lamothe-Brassard joined Alex Hurtado on the Detection Dispatch podcast to talk about the shift happening across the industry: security capabilities moving out from behind the UI. When every platform function is reachable through an API or CLI, both humans and AI agents can do the work without logging into a console. The episode covers what headless means in practice, how to govern agents in production, and where automation actually pays off.
  |  By LimaCharlie
Co-founder and COO Two credible engineering organizations have now documented internal agentic triage builds. The results validate the architecture. The build details explain why service providers need a different way to get it.
  |  By LimaCharlie
Co-founder and COO Agentic SOC architecture, explained: how API-driven security operations work when AI agents are the primary operators. Most security operations centers are built around a dashboard. The dashboard is how analysts see what is happening, take action, respond to alerts, and manage cases. This design choice made sense when humans were the only operators in the environment.
  |  By LimaCharlie
Co-founder and COO If you're running an MSSP or preparing for an audit, lc-compliance automatically documents relevant compliance evidence directly into your case records as they're created. Service providers work in a regulated environment, and already know compliance is a grind. Audits produce a pile of evidence requests. Your team pulls logs, traces detections back to controls, and writes documentation that no one reads until the QSA asks for it. Then you do it again next year.
  |  By LimaCharlie
Intel Chat with Matt Bromiley and Chris Luft. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.
  |  By LimaCharlie
By the end of this hands-on workshop, you will have deployed a working detection pipeline, ingested a cloud log source, and shipped a bespoke dashboard app, all using Claude Code integrated with Grid by LimaCharlie. Along the way, you will see how Grid compresses the traditional SIEM/EDR/SOAR stack into a single automated workspace. We go well beyond standard EDR and SIEM use cases. What to expect.
  |  By LimaCharlie
Joshua Strickland from SECNAP shows how his team built a full agentic MDR platform on top of LimaCharlie. SECNAP layers its own customer portal and SOC workflows directly on LimaCharlie's API, giving AI agents the same access to telemetry and response actions as a human analyst. Joshua will walk you through the customer portal, the SOC dashboard, and a live attack simulation on a sandboxed machine, including how AI agents handle tier one and tier two triage with Sonnet and Opus, and how a human analyst reviews and approves response actions before anything ships.
  |  By LimaCharlie
By the end of this hands-on workshop, you will have deployed a working detection pipeline, ingested a cloud log source, and shipped a bespoke dashboard app, all using Claude Code integrated with Grid by LimaCharlie. Along the way, you will see how Grid compresses the traditional SIEM/EDR/SOAR stack into a single automated workspace. We go well beyond standard EDR and SIEM use cases. What to expect.
  |  By LimaCharlie
Today we're speaking with Christopher Crowley, cybersecurity consultant through Montance and Senior Instructor with the SANS Institute, about the value of cybersecurity operations — how to measure it, how to express it to the business, and how AI is changing the work of the SOC.
  |  By LimaCharlie
Intel Chat with Matt Bromiley and Chris Luft — recorded in person at Black Hat USA in Las Vegas, day two. No prep doc, no script: just what Matt and Chris were actually hearing on the floor. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly. Subscribe wherever you listen.
  |  By LimaCharlie
Intel Chat with Matt Bromiley and Chris Luft. Matt and Chris break down four stories from the week in threat intel: Plus: Google Threat Intelligence Group retires APT/FIN nomenclature for new threat-actor names, and where to find Chris and Matt at Black Hat. Stories covered: Chapters: The Cybersecurity Defenders Podcast — a podcast about cybersecurity and the people that keep the internet safe. New episodes drop weekly.
  |  By LimaCharlie
The most pleasant agentic AI system is the least secure one. That's the trap Rob van der Veer, Chief AI Officer at Software Improvement Group, lays out clearly: the agent that never says "permission denied" is the agent everyone loves to use. It always works. So we open up all the privileges just to keep it that way. He says we should do the contrary.
  |  By LimaCharlie
Today we're speaking with Rob van der Veer, Chief AI Officer at Software Improvement Group, about how organizations can build trustworthy AI in an era of rapidly evolving technology and regulation — AI security, threat modeling, international standards, and the new challenges posed by agentic AI.
  |  By LimaCharlie
A walkthrough of Cloud Security in LimaCharlie — CNAPP capability built into the SecOps Cloud Platform. Connect your cloud and SaaS providers (AWS, GCP, Azure, Okta, Google Workspace, GitHub, Cloudflare, Anthropic, and even other LimaCharlie orgs) and everything is normalized into a single security graph: identities, permissions, workloads, and data. The engine reasons over that graph to surface attack paths — evidence-backed chains an attacker could actually walk — instead of isolated checkbox findings.

LimaCharlie gives security teams full control over how they manage their security infrastructure. Get full visibility into your coverage, build what you want, control your data, get the security capabilities you need, for however long you need them, and pay only for what you use.

LimaCharlie Sensors enable organizations to collect relevant security telemetry, logs and artifacts in real-time from any source and process that data at wire speed using a universal detection, response and automation engine. Use signature based detections, your favourite threat feed or subscribe to curated detection rules.

An engineering approach to cybersecurity:

  • Endpoint detection & response: Respond to threats at wire speed and create powerful automations. Leverage solutions custom designed for your environment and control your security posture without having to rely on external vendors.
  • Software-defined networking: Secure and monitor network access to your endpoints by providing advanced instrumented Zero Trust VPN access. LimaCharlie’s Secure Access Service Edge (SASE) makes secure remote networking easy and affordable.
  • Windows Event Log monitoring: Gain the ability to capture and analyze Windows Event Logs (WEL) in real-time. Ingested WEL are indexed along common indicators of compromise and run through the Detection & Response engine.
  • File & registry integrity monitoring: LimaCharlie's File & Registry Integrity Monitoring capability allows you to monitor specific file path patterns and registry patterns for changes.
  • Monitoring cloud deployments: Secure your cloud using LimaCharlie’s advanced Sensor technology. Run in a VM, Docker, or as a privileged container in Kubernetes. Optimize your costs with fine-grained event collection control, autoscaling and automated sensor culling.
  • YARA scanning at scale: Various YARA scanning methods are available. Run a scan on any given endpoint or continuously across the entire fleet in a way that does not impact performance. Pull YARA signatures from Github repositories and other sources, both private and public.
  • Cutting edge detections: Leverage the work of best-in-class professionals with an unparalleled cost efficiency. Subscribe to threat feeds and curated detection rules. Easily write your own custom rules and apply them instantly to your entire fleet.
  • Log and artifact monitoring: Ingest logs, or any file type, from any source and run them through the detection, automation and response engine. One year of full telemetry storage included - not just detections or select entries, but all endpoint, network, and external logs telemetry.

Detect and respond on everything.