News
Sandfly 2.8.2 – Over 1,000 Linux Compromise Detection Modules and More
Sandfly 2.8.2 is here and features many upgrades including over 1,000 compromise detection and incident response modules for Linux. This update features: User password entry decoder to search for…
Sandfly 2.8.0 – Agentless Active Attack Response for Linux
Sandfly 2.8.0 is released and features a major new upgrade allowing users to automatically respond to detected Linux attacks agentlessly. In addition to this we have made large performance upgrades…
Sandfly 2.7.2 – Performance Update
Sandfly 2.7.2 has been released. This is a bug fix release to address a performance issue. In the last release Sandfly introduced more extensive process decloaking for stealth rootkits. The technique…
Sandfly 2.7.0 – Mitre ATT&CK Tags, Enhanced Linux Stealth Rootkit De-Cloaking and SCTP Backdoor Detection
Sandfly 2.7.0 is now out and features some significant upgrades. Sandfly modules now are tagged with Mitre ATT&CK categories and tactics. We are able to completely decloak even more hidden processes…
Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available
We are pleased to announce the release of the Sandfly Splunk app. This new app is available on Splunkbase. Sandfly users can now combine the powerful search and analysis features of Splunk, with…
Sandfly 2.6.0 – Elasticsearch Replication, Linux Docker Container Security Scanning, Hidden Process De-Cloaking and More
Sandfly 2.6.0 has been released and now has the ability to use external Elasticsearch databases. This new feature allows you to use Elasticsearch’s Kibana and other tools to analyze and display…