Journal IJCRT UGC-CARE, UGCCARE( ISSN: 2320-2882 ) | UGC Approved Journal | UGC Journal | UGC CARE Journal | UGC-CARE list, New UGC-CARE Reference List, UGC CARE Journals, International Peer Reviewed Journal and Refereed Journal, ugc approved journal, UGC CARE, UGC CARE list, UGC CARE list of Journal, UGCCARE, care journal list, UGC-CARE list, New UGC-CARE Reference List, New ugc care journal list, Research Journal, Research Journal Publication, Research Paper, Low cost research journal, Free of cost paper publication in Research Journal, High impact factor journal, Journal, Research paper journal, UGC CARE journal, UGC CARE Journals, ugc care list of journal, ugc approved list, ugc approved list of journal, Follow ugc approved journal, UGC CARE Journal, ugc approved list of journal, ugc care journal, UGC CARE list, UGC-CARE, care journal, UGC-CARE list, Journal publication, ISSN approved, Research journal, research paper, research paper publication, research journal publication, high impact factor, free publication, index journal, publish paper, publish Research paper, low cost publication, ugc approved journal, UGC CARE, ugc approved list of journal, ugc care journal, UGC CARE list, UGCCARE, care journal, UGC-CARE list, New UGC-CARE Reference List, UGC CARE Journals, ugc care list of journal, ugc care list 2020, ugc care approved journal, ugc care list 2020, new ugc approved journal in 2020, ugc care list 2021, ugc approved journal in 2021, Scopus, web of Science.
How start New Journal & software Book & Thesis Publications

INTERNATIONAL JOURNAL OF CREATIVE RESEARCH THOUGHTS - IJCRT (IJCRT.ORG)

International Peer Reviewed & Refereed Journals, Open Access Journal

IJCRT Peer-Reviewed (Refereed) Journal as Per New UGC Rules.

ISSN Approved Journal No: 2320-2882 | Impact factor: 7.97 | ESTD Year: 2013

Call For Paper - Volume 14 | Issue 3 | Month- March 2026

Scholarly open access journals, Peer-reviewed, and Refereed Journals, Impact factor 7.97 (Calculate by google scholar and Semantic Scholar | AI-Powered Research Tool) , Multidisciplinary, Monthly, Indexing in all major database & Metadata, Citation Generator, Digital Object Identifier(CrossRef DOI)

Submit Your Paper
Login to Author Home
Communication Guidelines

WhatsApp Contact
Click Here

  Published Paper Details:

  Paper Title

Cyber Security Threat Detection and Response using LimaCharlie EDR Tool

  Authors

  Mohammed Abdul Aziz,  G. Praveen Babu

  Keywords

EDR - Endpoint Detection and Response, SSH - Secure Shell, VM - Virtual Machine, Ubuntu Linux, Windows.

  Abstract


This study has been undertaken to investigate a real time threat detection and response to a ransomware attack. For this, two different virtual machines i.e. Linux and Windows are setup, in which Linux will be an attacker and Windows will be the victim. In this paper, the victim will be able to detect the threat posed by the attacker and also respond to the attack by blocking it. The Sliver C2 payload will be delivered through SSH client on Linux VM towards Windows VM. On Windows VM, Lima Charlie EDR (Endpoint Detection & Response) software tool is used for log monitoring, threat detection and threat response. Then, Volume Shadow Copier software is employed to retrieve the system from the attack. This paper is divided into multiple modules in order to increase efficiency of execution of the attack. Firstly, organize all the tools and software's required for this setup. In the next module, the advanced Log monitoring is performed to detect any anomaly which is helpful to detect the threats. Then in the final module, the threat response is performed by blocking the attack after detecting it in the earlier module. For blocking an attack, craft a D&R rule to respond to the adversarial attack. So, in a ransomware attack the first criteria is that the Volume Shadow Copies will have to be deleted. This event will trigger the D&R rule due to which the attack will be blocked, and the ransomware payload will be terminated in this case.

  IJCRT's Publication Details

  Unique Identification Number - IJCRT2408339

  Paper ID - 267577

  Page Number(s) - d121-d134

  Pubished in - Volume 12 | Issue 8 | August 2024

  DOI (Digital Object Identifier) -    http://doi.one/10.1729/Journal.41227

  Publisher Name - IJCRT | www.ijcrt.org | ISSN : 2320-2882

  E-ISSN Number - 2320-2882

  Cite this article

  Mohammed Abdul Aziz,  G. Praveen Babu,   "Cyber Security Threat Detection and Response using LimaCharlie EDR Tool", International Journal of Creative Research Thoughts (IJCRT), ISSN:2320-2882, Volume.12, Issue 8, pp.d121-d134, August 2024, Available at :http://www.ijcrt.org/papers/IJCRT2408339.pdf

  Share this article

  Article Preview

  Indexing Partners

indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
Call For Paper March 2026
Indexing Partner
ISSN and 7.97 Impact Factor Details


ISSN
ISSN
ISSN: 2320-2882
Impact Factor: 7.97 and ISSN APPROVED
Journal Starting Year (ESTD) : 2013
ISSN
ISSN and 7.97 Impact Factor Details


ISSN
ISSN
ISSN: 2320-2882
Impact Factor: 7.97 and ISSN APPROVED
Journal Starting Year (ESTD) : 2013
ISSN
DOI Details

Providing A digital object identifier by DOI.org How to get DOI?
For Reviewer /Referral (RMS) Earn 500 per paper
Our Social Link
Open Access
This material is Open Knowledge
This material is Open Data
This material is Open Content
Indexing Partner

Scholarly open access journals, Peer-reviewed, and Refereed Journals, Impact factor 7.97 (Calculate by google scholar and Semantic Scholar | AI-Powered Research Tool) , Multidisciplinary, Monthly, Indexing in all major database & Metadata, Citation Generator, Digital Object Identifier(DOI)

indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer
indexer