1 min read
Linux EDR nologin Shell Rename Backdoor Attack Detection and Forensics
Publication Date: 04 December 2024
Sandfly Security - Agentless Linux EDR and Incident Response September 28, 2026
03 December 2024
Linux ships with default users disabled. But, attackers can activate these accounts to allow backdoor access that can hide for a long time. In this video we discuss this threat, how to find it with command line forensics, and what impacts it can have.
Find out if your systems have default user access, plus thousands of other attack traces instantly. Sandfly's agentless EDR for Linux deploys rapidly without any endpoint agents. Get a free license today to try it out.
1 min read
Publication Date: 04 December 2024
1 min read
Sandfly Blog Default User SSH Authorized Key Risks on Linux 09 December 2024 Videos
1 min read
02 December 2024