Get Sandfly

Agentless compromise detection

Full security visibility on Linux, zero footprint.

Sandfly connects over SSH, hunts for intruders and malware around the clock, and gathers the forensic evidence your team needs to act.

  • Nothing installed. No agent, no kernel modules, no syscall hooks. Sandfly connects over SSH and leaves nothing behind.

  • Deployed in minutes. Scanning your first hosts the same day, not after a rollout project.

  • Works everywhere. Almost any distribution, from decade-old systems to modern cloud.

We needed visibility into the systems, but it also could not impact production. We could not be toppling servers, we could not be causing production issues. Sandfly proved that it would not cause problems in evaluation, and it has held up in production.

Senior Security Engineer · Automotive manufacturer

Systems compromised right now? Go straight to Under Attack for urgent help.

The console

Comprehensive Linux Security

Sandfly's deep understanding of Linux intruder tactics offers reliable and effective threat protection. Known and unknown attacks are detected safely and fast.

Sandfly detects known and unknown threats on Linux.

Common questions

How Sandfly works

01.
Is Sandfly really agentless?
Yes. There is no agent to install on your Linux hosts. Sandfly only needs SSH running on them, so there is nothing to deploy or maintain on each endpoint.
02.
Which Linux distributions are supported?
Virtually all of them. Sandfly covers the widest range of Linux on the market, from systems over ten years old to modern cloud, across Intel, AMD, Arm, MIPS and IBM Power.
03.
How does it scale across a large fleet?
Sandfly uses a server and node design. You add nodes to cover different network segments, and reach isolated networks through jump or proxy hosts.
04.
What does Sandfly actually do?
It hunts for intruders, malware and suspicious activity on Linux 24 hours a day, gathers forensic evidence, and can run automated responses once a threat is found.