News

Sandfly 2.1 Released

Product Update
August 05, 2019

Sandfly 2.1 has been released. We have expanded MIPS and ARM CPU coverage for embedded Linux devices, boosted our bindshell backdoor coverage and added in new sniffer and rogue sudo user detection as…

Sandfly 2.0 Released – Write Your Own Sandflies

Product Update
July 02, 2019

Sandfly 2.0 is here. Sandfly 2.0 brings powerful new capabilities for agentless compromise detection and incident response for Linux. This includes our new feature to write your own agentless custom…

Ninjas on Rooftops – A Better Approach to Linux Threat Hunting

Product Update
February 11, 2019

Intrusion detection thought for the day: Someone trying to hide is a signature. In this video, Sandfly founder Craig Rowland discusses why hunting for hiding tactics vs. specific exploit signatures…

Sandfly 1.6.1 – Host ID Updates and Other Fixes

Product Update
February 07, 2019

Sandfly 1.6.1 is released and has some Install Simplified The install procedure for Sandfly has been greatly simplified. You now need to run one script on the server and enter some basic information…

Sandfly 1.6.0 – 200 Sandflies!

Product Update
January 09, 2019

Sandfly 1.6.0 is now available. We now have 200 sandfly checks covering a wide range of Linux rootkit, malware and intrusion detection. Our agentless approach is fast and extensive in investigating…

Sandfly 1.5.0 Released – Enhanced Linux Process Forensics, Rootkit and Network Sniffer Hunting

Product Update
November 26, 2018

Sandfly 1.5.0 has been released with many new detection methods for Linux rootkits, malware and suspicious activity. The latest update expands on our already thorough intrusion detection and threat…