Agentless compromise detection
Full security visibility on Linux, zero footprint.
Sandfly connects over SSH, hunts for intruders and malware around the clock, and gathers the forensic evidence your team needs to act.
Nothing installed. No agent, no kernel modules, no syscall hooks. Sandfly connects over SSH and leaves nothing behind.
Deployed in minutes. Scanning your first hosts the same day, not after a rollout project.
Works everywhere. Almost any distribution, from decade-old systems to modern cloud.
We needed visibility into the systems, but it also could not impact production. We could not be toppling servers, we could not be causing production issues. Sandfly proved that it would not cause problems in evaluation, and it has held up in production.
Systems compromised right now? Go straight to Under Attack for urgent help.
The console
Comprehensive Linux Security
Sandfly's deep understanding of Linux intruder tactics offers reliable and effective threat protection. Known and unknown attacks are detected safely and fast.
Sandfly detects known and unknown threats on Linux.
Common questions