News

Sandfly 2.4.0 – Splunk Support, Reconnaissance, Process Injection Detection and Containers

Product Update
January 12, 2020

Sandfly 2.4.0 has been released with major new features. We have boosted our Linux intrusion detection and incident response signatures to over 700. We have also begun building out the ability to…

Sandfly 2.3.2 – Linux Packet Sniffer Detection and Faster Process Forensics

Product Update
November 11, 2019

Sandfly 2.3.2 has been released. It includes new capabilities to detect a variety of Linux network packet sniffers, plus has internal optimizations that have improved process forensic performance up…

Sandfly 2.3 – Performance Updates, Elasticsearch 7 Support and More

Product Update
October 29, 2019

Sandfly 2.3 is now released. This version features many changes to improve performance, updates the custom Sandfly syntax, eliminates false alarms and migrates to Elasticsearch 7. Performance…

Sandfly 2.2 – Enhanced Web Shell Detection, Linux Anti-Forensics and More

Product Update
September 02, 2019

Sandfly 2.2 has now been released. This update adds new capabilities around web shell detection, Linux anti-forensics detection, plus much more. A small sample of some of the new Linux threats we…

Sandfly 2.1 Released

Product Update
August 05, 2019

Sandfly 2.1 has been released. We have expanded MIPS and ARM CPU coverage for embedded Linux devices, boosted our bindshell backdoor coverage and added in new sniffer and rogue sudo user detection as…

Sandfly 2.0 Released – Write Your Own Sandflies

Product Update
July 02, 2019

Sandfly 2.0 is here. Sandfly 2.0 brings powerful new capabilities for agentless compromise detection and incident response for Linux. This includes our new feature to write your own agentless custom…