test-limacharlie-edr

Deploy a temporary LimaCharlie EDR sensor on Linux and macOS hosts for testing.

29|3|Updated Dec 21, 2025
One-click install
npx skills add https://github.com/refractionPOINT/lc-ai --skill test-limacharlie-edr
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: test-limacharlie-edr
Source: https://github.com/refractionPOINT/lc-ai/tree/main/marketplace/plugins/lc-essentials/skills/test-limacharlie-edr
Command: npx skills add https://github.com/refractionPOINT/lc-ai --skill test-limacharlie-edr

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This skill deploys a temporary LimaCharlie EDR sensor on a local host for development, testing, and validation of detections in a controlled environment.

Core Features & Use Cases

  • Phase 1: Create or locate a "Test EDR" installation key
  • Phase 2: Download the appropriate sensor, install, and run in the background
  • Phase 3: Verify sensor connection and view ingested data

Quick Start

Select an org, obtain or create a Test EDR installation key, then deploy the test sensor on your machine.

Frequently Asked Questions about test-limacharlie-edr

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I deploy a temporary EDR sensor for testing on Linux or Mac?

Deploy a temporary EDR sensor by selecting your org, obtaining or creating a Test EDR installation key, then running the Skill to download platform-specific binaries and launch the sensor in the background with root privileges on your x64 or arm64 host.

Can I test D&R rules locally before deploying them to production?

Yes. Deploy a temporary LimaCharlie EDR sensor on your local machine to test detection and response rules in a controlled environment, validate sensor behavior, and iterate before production deployment.

What platforms and architectures does the test sensor support?

The test sensor runs on Linux and Mac OS hosts with x64 and arm64 architectures, enabling development and quick validation across common development and testing environments.

Does the sensor clean up automatically after testing?

Yes. The temporary sensor automatically cleans up when stopped, removing binaries and configuration from the unique temporary directory without manual cleanup steps required.

What do I need before deploying the test sensor?

You need an org in LimaCharlie, a Test EDR installation key (created or reused), root or sudo access on your Linux or Mac host, and an active internet connection to download sensor binaries.