Sandfly Blog

Sandfly 2.5.2 – Scheduling Priority, Detecting Command Line Web Servers, Port Scanners and Kernel Thread Masquerading

Sandfly 2.5.2 has been released and now allows you to set the priority of scans on remote hosts to limit processor impacts. It also expands coverage for command line web server detection, flags more port …

READ MORESandfly 2.5.2 – Scheduling Priority, Detecting Command Line Web Servers, Port Scanners and Kernel Thread Masquerading

Sandfly 2.5.0 – Higher Performance, SSH Key Certificates and More Linux Forensics

Sandfly 2.5.0 has been released and features a 5-10X boost in investigation speed, lower CPU impacts during investigations and support for SSH key certificates. Of course, we’ve added more agentless Linux intrusion detection and threat …

READ MORESandfly 2.5.0 – Higher Performance, SSH Key Certificates and More Linux Forensics

Sandfly Filescan Open Source File Entropy Scanner for Linux

We’re releasing an open source tool today called sandfly-filescan. Sandfly-filescan allows Linux admins and incident responders to quickly scan for compressed or encrypted executable files often linked to malware. sandfly-filescan is a utility to quickly …

READ MORESandfly Filescan Open Source File Entropy Scanner for Linux