An international automobile manufacturer operating critical manufacturing systems that manage just-in-time global assembly line operations alongside corporate infrastructure. Security solutions must deliver threat visibility without disrupting production.
The customer's Security Operations Center (SOC) had almost no Linux visibility, leaving teams with blind spots in detection and triage that a Windows-heavy toolset couldn’t address. Agent-based EDR systems introduced performance and stability risks that threatened production lines. The SOC team also lacked deep Linux expertise and had no visibility into password security. They wanted visibility without the drama of endpoint agents.
Approximately 1,600 Linux servers distributed across nearly 20 North American facilities supporting corporate and production line systems. Linux runs production operations, including automated guided vehicles (AGVs) moving inventory autonomously between assembly lines.
During competitive testing, an agent-based solution crashed test servers twice, exhibited progressive memory growth, and sustained 80% CPU usage - proving that the customer's concerns about production impact were well-founded.
The customer selected Sandfly's agentless Linux EDR after competitive testing that included performance monitoring and customer-designed test cases. Sandfly was the only option that met the requirements for detection coverage and no performance impact. The agentless architecture provided comprehensive Linux visibility without endpoint agents, and enabled rollout across touch-averse manufacturing servers where agent-based tools require extensive change control approval.
Sandfly's infrastructure was stood up in minutes. The customer leveraged existing Ansible automation to create accounts and deploy SSH keys across the fleet. Tag-based grouping enabled efficient baseline and whitelist development. Sandfly integrated into SOC workflows through JSON alerts to Microsoft Sentinel. Human-readable descriptions enabled the Windows-heavy SOC team to act on Linux alerts without deep Linux expertise, no custom tooling, and minimal ongoing maintenance. Upgrades, certificate renewals, and whitelisting are all handled through built-in automation.
The team plans to expand Sandfly coverage to embedded Linux devices supporting vision-based quality assurance in manufacturing facilities.
"A refreshingly pleasant experience to manage - not just the deployment, but upgrades and day-two operations." — Senior Security Engineer, Automotive Manufacturer