<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Sandfly Blog</title>
    <link>https://sandflysecurity.com/blog</link>
    <description>Linux security and forensic articles. Learn about Linux forensics and agentless security with Sandfly.</description>
    <language>en</language>
    <pubDate>Mon, 28 Sep 2026 21:55:24 GMT</pubDate>
    <dc:date>2026-09-28T21:55:24Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>Why You Should Be Searching for Linux Anti-Forensics</title>
      <link>https://sandflysecurity.com/blog/why-you-should-be-searching-for-linux-anti-forensics</link>
      <description>&lt;p&gt;&lt;span style="color: #ffffff;"&gt;Publication Date: 09 February 2019&lt;/span&gt;&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;span style="color: #ffffff;"&gt;Publication Date: 09 February 2019&lt;/span&gt;&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fwhy-you-should-be-searching-for-linux-anti-forensics&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Videos</category>
      <category>Rootkits</category>
      <category>Malware</category>
      <category>Linux Security</category>
      <category>Linux Forensics</category>
      <pubDate>Mon, 28 Sep 2026 19:21:06 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/why-you-should-be-searching-for-linux-anti-forensics</guid>
      <dc:date>2026-09-28T19:21:06Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
    <item>
      <title>Christchurch Hacker Con Linux Digital Forensics Video</title>
      <link>https://sandflysecurity.com/blog/christchurch-hacker-con-linux-digital-forensics-video</link>
      <description>&lt;p&gt;Publication Date: 18 April 2018&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 18 April 2018&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fchristchurch-hacker-con-linux-digital-forensics-video&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Linux Security</category>
      <category>Linux Forensics</category>
      <category>Presentations</category>
      <pubDate>Mon, 28 Sep 2026 19:20:45 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/christchurch-hacker-con-linux-digital-forensics-video</guid>
      <dc:date>2026-09-28T19:20:45Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
    <item>
      <title>Using Elasticsearch and Kibana to Investigate Suspicious Linux Activity with Sandfly</title>
      <link>https://sandflysecurity.com/blog/using-elasticsearch-and-kibana-to-investigate-suspicious-linux-activity-with-sandfly</link>
      <description>&lt;p&gt;Publication Date: 27 May 2020&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 27 May 2020&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fusing-elasticsearch-and-kibana-to-investigate-suspicious-linux-activity-with-sandfly&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Videos</category>
      <category>Linux Security</category>
      <category>Presentations</category>
      <pubDate>Mon, 28 Sep 2026 19:20:17 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/using-elasticsearch-and-kibana-to-investigate-suspicious-linux-activity-with-sandfly</guid>
      <dc:date>2026-09-28T19:20:17Z</dc:date>
      <dc:creator>Craig Rowland, Founder and CEO, Sandfly Security</dc:creator>
    </item>
    <item>
      <title>Immutable File Attack Persistence on Linux</title>
      <link>https://sandflysecurity.com/blog/immutable-file-attack-persistence-on-linux</link>
      <description>&lt;p&gt;Publication Date: 20 January 2025&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 20 January 2025&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fimmutable-file-attack-persistence-on-linux&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Videos</category>
      <category>Linux Forensics</category>
      <category>Education</category>
      <pubDate>Mon, 28 Sep 2026 19:19:49 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/immutable-file-attack-persistence-on-linux</guid>
      <dc:date>2026-09-28T19:19:49Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
    <item>
      <title>Linux Forensics Tools | Intrusion Detection, Threat Hunting &amp; Malware Detect Linux Commands Cheat Sheet</title>
      <link>https://sandflysecurity.com/blog/compromised-linux-cheat-sheet</link>
      <description>&lt;p&gt;Publication Date: 20 May 2021&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 20 May 2021&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fcompromised-linux-cheat-sheet&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Rootkits</category>
      <category>Malware</category>
      <category>Linux Security</category>
      <category>Linux Forensics</category>
      <category>Manufacturing</category>
      <pubDate>Mon, 28 Sep 2026 19:18:59 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/compromised-linux-cheat-sheet</guid>
      <dc:date>2026-09-28T19:18:59Z</dc:date>
      <dc:creator>Craig Rowland, Founder and CEO, Sandfly Security</dc:creator>
    </item>
    <item>
      <title>How Linux Malware Works, From Simple to Sophisticated</title>
      <link>https://sandflysecurity.com/blog/how-linux-malware-works-from-simple-to-sophisticated</link>
      <description>&lt;p&gt;Publication Date: 17 June 2026&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 17 June 2026&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fhow-linux-malware-works-from-simple-to-sophisticated&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Videos</category>
      <category>Malware</category>
      <category>Linux Security</category>
      <category>Presentations</category>
      <category>Webinar</category>
      <pubDate>Mon, 28 Sep 2026 19:18:18 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/how-linux-malware-works-from-simple-to-sophisticated</guid>
      <dc:date>2026-09-28T19:18:18Z</dc:date>
      <dc:creator>Craig Rowland, Founder and CEO, Sandfly Security</dc:creator>
    </item>
    <item>
      <title>Why You Must Monitor Linux for Signs of Intruders</title>
      <link>https://sandflysecurity.com/blog/why-you-must-monitor-linux-for-signs-of-intruders</link>
      <description>&lt;p&gt;Publication Date: 20 February 2019&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Publication Date: 20 February 2019&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fwhy-you-must-monitor-linux-for-signs-of-intruders&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Rootkits</category>
      <category>Malware</category>
      <category>Linux Security</category>
      <category>Linux Forensics</category>
      <pubDate>Mon, 28 Sep 2026 19:17:48 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/why-you-must-monitor-linux-for-signs-of-intruders</guid>
      <dc:date>2026-09-28T19:17:48Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
    <item>
      <title>SSH Key Compromise Risks and Countermeasures</title>
      <link>https://sandflysecurity.com/blog/ssh-key-compromise-risks-and-countermeasures</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/ssh-key-compromise-risks-and-countermeasures" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1687819717-ssh-find-private-keys-annotated.png" alt="SSH Key Compromise Risks and Countermeasures" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 26 June 2023&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/ssh-key-compromise-risks-and-countermeasures" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1687819717-ssh-find-private-keys-annotated.png" alt="SSH Key Compromise Risks and Countermeasures" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 26 June 2023&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fssh-key-compromise-risks-and-countermeasures&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Videos</category>
      <category>Malware</category>
      <category>Linux Security</category>
      <category>Linux Forensics</category>
      <category>Education</category>
      <pubDate>Mon, 28 Sep 2026 19:11:59 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/ssh-key-compromise-risks-and-countermeasures</guid>
      <dc:date>2026-09-28T19:11:59Z</dc:date>
      <dc:creator>Craig Rowland, Founder and CEO, Sandfly Security</dc:creator>
    </item>
    <item>
      <title>Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available</title>
      <link>https://sandflysecurity.com/blog/lunk-app-for-sandfly-agentless-intrusion-detection-for-linux-now-available</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/lunk-app-for-sandfly-agentless-intrusion-detection-for-linux-now-available" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1635216296-splunk-sandfly-dashboard-1.png" alt="Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 02 June 2020&lt;br&gt;&lt;br&gt;We are pleased to announce the release of the Sandfly Splunk app. This &lt;a href="https://splunkbase.splunk.com/app/5015/"&gt;new app is available on Splunkbase&lt;/a&gt;. Sandfly users can now combine the powerful search and analysis features of Splunk, with Sandfly’s leading agentless security and visibility into Linux.&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/lunk-app-for-sandfly-agentless-intrusion-detection-for-linux-now-available" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1635216296-splunk-sandfly-dashboard-1.png" alt="Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 02 June 2020&lt;br&gt;&lt;br&gt;We are pleased to announce the release of the Sandfly Splunk app. This &lt;a href="https://splunkbase.splunk.com/app/5015/"&gt;new app is available on Splunkbase&lt;/a&gt;. Sandfly users can now combine the powerful search and analysis features of Splunk, with Sandfly’s leading agentless security and visibility into Linux.&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Flunk-app-for-sandfly-agentless-intrusion-detection-for-linux-now-available&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Product Update</category>
      <category>Linux Security</category>
      <pubDate>Mon, 28 Sep 2026 19:11:58 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/lunk-app-for-sandfly-agentless-intrusion-detection-for-linux-now-available</guid>
      <dc:date>2026-09-28T19:11:58Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
    <item>
      <title>Sandfly 5.6 - Automatic Drift Detection</title>
      <link>https://sandflysecurity.com/blog/sandfly-5-6-automatic-drift-detection</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/sandfly-5-6-automatic-drift-detection" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1768949771-5-6-thumbnail-alt-web.png" alt="Sandfly 5.6 - Automatic Drift Detection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 21 January 2026&lt;/p&gt;</description>
      <content:encoded>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://sandflysecurity.com/blog/sandfly-5-6-automatic-drift-detection" title="" class="hs-featured-image-link"&gt; &lt;img src="https://www.datocms-assets.com/56687/1768949771-5-6-thumbnail-alt-web.png" alt="Sandfly 5.6 - Automatic Drift Detection" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;p&gt;Publication Date: 21 January 2026&lt;/p&gt;  
&lt;img src="https://track-ap1.hubspot.com/__ptq.gif?a=442867139&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fsandflysecurity.com%2Fblog%2Fsandfly-5-6-automatic-drift-detection&amp;amp;bu=https%253A%252F%252Fsandflysecurity.com%252Fblog&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>News</category>
      <category>Product Update</category>
      <category>Linux Security</category>
      <pubDate>Mon, 28 Sep 2026 19:11:56 GMT</pubDate>
      <guid>https://sandflysecurity.com/blog/sandfly-5-6-automatic-drift-detection</guid>
      <dc:date>2026-09-28T19:11:56Z</dc:date>
      <dc:creator>Sandfly Security - Agentless Linux EDR and Incident Response</dc:creator>
    </item>
  </channel>
</rss>
