Detecting Linux Kernel Process Masquerading with Command Line Forensics

March 31, 2020

Computer Forensics, Forensics, Linux Forensics

Linux kernel process masquerading is sometimes used by malware to hide when it is running. Let’s go over how you can unmask a piece of Linux…

Sandfly 2.5.2 – Scheduling Priority, Detecting Command Line Web Servers, Port Scanners and Kernel Thread Masquerading

March 26, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.5.2 has been released and now allows you to set the priority of scans on remote hosts to limit processor impacts. It also expands…

Sandfly 2.5.0 – Higher Performance, SSH Key Certificates and More Linux Forensics

February 18, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.5.0 has been released and features a 5-10X boost in investigation speed, lower CPU impacts during investigations and support for…

Sandfly 2.4.0 – Splunk Support, Reconnaissance, Process Injection Detection and Containers

January 13, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.4.0 has been released with major new features. We have boosted our Linux intrusion detection and incident response signatures to…

How To Decloak Stealth Linux Cryptocurrency Mining Malware

December 17, 2019

Linux Forensics

Increasingly on Linux we are seeing malware deploying anti-detection and evasion tactics. In this post we’re going to go over a recent piece…

Sandfly Filescan Open Source File Entropy Scanner for Linux

November 26, 2019

Forensics, Linux Forensics, Sandfly Filescan

We’re releasing an open source tool today called . Sandfly-filescan allows Linux admins and incident responders to quickly scan for…