1 min read
Linux Default User Password Attack Detection and Forensics
03 December 2024 Videos
Sandfly Security - Agentless Linux EDR and Incident Response Updated on September 29, 2026
09 December 2024
Default Linux users with SSH authorized keys are a way for attackers to hide backdoor accounts that can avoid detection for some time. In this video we discuss and demonstrate the threat, why it's used, and how to find it with command line tools and automatic discovery with Sandfly, the agentless Linux EDR platform.
Sandfly is able to find this and many other types of Linux attacks without deploying any endpoint agents. Get your free license today or contact us for more information.
1 min read
03 December 2024 Videos
1 min read
Publication date: 05 December 2024
1 min read
Sandfly Blog Christchurch Hacker Con Linux Digital Forensics Video 18 April 2018 Presentations