Sandfly 2.7.0 – Mitre ATT&CK Tags, Enhanced Linux Stealth Rootkit De-Cloaking and SCTP Backdoor Detection

Product Update
August 04, 2020

Sandfly 2.7.0 is now out and features some significant upgrades. Sandfly modules now are tagged with Mitre ATT&CK categories and tactics. We are able to completely decloak even more hidden processes…

Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available

Product Update
June 02, 2020

We are pleased to announce the release of the Sandfly Splunk app. This new app is available on Splunkbase . Sandfly users can now combine the powerful search and analysis features of Splunk, with…

Sandfly 2.6.0 – Elasticsearch Replication, Linux Docker Container Security Scanning, Hidden Process De-Cloaking and More

Product Update
April 13, 2020

Sandfly 2.6.0 has been released and now has the ability to use external Elasticsearch databases. This new feature allows you to use Elasticsearch’s Kibana and other tools to analyze and display…

Sandfly 2.5.2 – Scheduling Priority, Detecting Command Line Web Servers, Port Scanners and Kernel Thread Masquerading

Product Update
March 25, 2020

Sandfly 2.5.2 has been released and now allows you to set the priority of scans on remote hosts to limit processor impacts. It also expands coverage for command line web server detection, flags more…

Sandfly 2.5.0 – Higher Performance, SSH Key Certificates and More Linux Forensics

Product Update
February 17, 2020

Sandfly 2.5.0 has been released and features a 5-10X boost in investigation speed, lower CPU impacts during investigations and support for SSH key certificates. Of course, we’ve added more agentless…

Sandfly 2.4.0 – Splunk Support, Reconnaissance, Process Injection Detection and Containers

Product Update
January 12, 2020

Sandfly 2.4.0 has been released with major new features. We have boosted our Linux intrusion detection and incident response signatures to over 700. We have also begun building out the ability to…