1 min read
Linux Process Running from /dev/shm RAM Disk Attack
Publication Date: 19 December 2024
Sandfly Security - Agentless Linux EDR and Incident Response Updated on September 29, 2026
Publication Date :19 December 2024
Malware on Linux will often delete the on-disk binary to evade detection with traditional anti-virus and file integrity monitoring tools. In this video we will discuss the threat and how to find it with Sandfly's agentless Linux EDR. We'll then show you how to investigate it with command line forensics and recover the running process binary for analysis.
Sandfly is able to find this and many other types of Linux attacks without deploying any endpoint agents. Get your free license today or contact us for more information.
1 min read
Publication Date: 19 December 2024
1 min read
Sandfly Blog Default User SSH Authorized Key Risks on Linux 09 December 2024 Videos
1 min read
Publication Date : January 2026