Sandfly Update

Sandfly 2.7.0 – Mitre ATT&CK Tags, Enhanced Linux Stealth Rootkit De-Cloaking and SCTP Backdoor Detection

August 05, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.7.0 is now out and features some significant upgrades. Sandfly modules now are tagged with Mitre ATT&CK categories and tactics. We…

Sandfly 2.6.0 – Elasticsearch Replication, Linux Docker Container Security Scanning, Hidden Process De-Cloaking and More

April 14, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.6.0 has been released and now has the ability to use external Elasticsearch databases. This new feature allows you to use…

Sandfly 2.5.2 – Scheduling Priority, Detecting Command Line Web Servers, Port Scanners and Kernel Thread Masquerading

March 26, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.5.2 has been released and now allows you to set the priority of scans on remote hosts to limit processor impacts. It also expands…

Sandfly 2.5.0 – Higher Performance, SSH Key Certificates and More Linux Forensics

February 18, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.5.0 has been released and features a 5-10X boost in investigation speed, lower CPU impacts during investigations and support for…

Sandfly 2.4.0 – Splunk Support, Reconnaissance, Process Injection Detection and Containers

January 13, 2020

Sandfly, Sandfly Update, Update

Sandfly 2.4.0 has been released with major new features. We have boosted our Linux intrusion detection and incident response signatures to…

Sandfly 2.3.2 – Linux Packet Sniffer Detection and Faster Process Forensics

November 12, 2019

Sandfly, Sandfly Update, Update

Sandfly 2.3.2 has been released. It includes new capabilities to detect a variety of Linux network packet sniffers, plus has internal…