Blog

Linux Stealth Rootkit Process Decloaking Tool – sandfly-processdecloak

August 17, 2020

Linux Forensics, Rootkits

We have released a new tool called designed to decloak hidden processes from two common and easily deployed Linux Loadable Kernel Module…

Sandfly 2.7.0 – Mitre ATT&CK Tags, Enhanced Linux Stealth Rootkit De-Cloaking and SCTP Backdoor Detection

August 05, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.7.0 is now out and features some significant upgrades. Sandfly modules now are tagged with Mitre ATT&CK categories and tactics. We…

Detecting Linux memfd_create() Fileless Malware with Command Line Forensics

July 09, 2020

Computer Forensics, Forensics, Linux Forensics, Sandfly

A developing threat to Linux over the last several years has been the idea of fileless malware. Fileless malware is designed to inject…

Splunk App for Sandfly Agentless Intrusion Detection for Linux Now Available

June 03, 2020

Linux Forensics, Sandfly, Splunk

We are pleased to announce the release of the Sandfly Splunk app. This . Sandfly users can now combine the powerful search and analysis…

Using Elasticsearch and Kibana to Investigate Suspicious Linux Activity with Sandfly

May 28, 2020

Linux Forensics, Videos

In this video we’re going to show you how to use Sandfly with Elasticsearch Kibana dashboards to search for and investigate a suspicious…

Sandfly 2.6.0 – Elasticsearch Replication, Linux Docker Container Security Scanning, Hidden Process De-Cloaking and More

April 14, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.6.0 has been released and now has the ability to use external Elasticsearch databases. This new feature allows you to use…