Product FAQ

Here you can find answers to common product questions about Sandfly.

Can Sandfly Be Used For Incident Response?
Absolutely. Sandfly is unique in the industry because incident responders can use Sandfly to instantly scan and detect compromises even if no prior secu...
Fri, 4 Aug, 2023 at 6:25 PM
Can Sandfly Send Events to a SIEM Like Splunk or Elasticsearch?
Yes. We have built in connectors that can send data directly to Splunk and Elasticsearch. We also have the ability to send structured syslog directly to...
Fri, 4 Aug, 2023 at 6:26 PM
Does Sandfly Collect or Analyze Any Data Off-Site?
No. Sandfly is completely self-contained. It sends no data back to us and does not ship potentially confidential data from your systems off-site for anal...
Fri, 4 Aug, 2023 at 6:36 PM
How Much CPU Does Sandfly Consume?
Sandfly easily has the lowest CPU impact of any Linux EDR product on the market. In fact,  Sandfly was designed from the beginning to run without making...
Fri, 4 Aug, 2023 at 6:38 PM
How Does Sandfly Interact with Remote Systems?
Sandfly connects to the remote Linux systems to be secured using the industry standard SSH protocol. Sandfly supports authentication mechanisms allowed with...
Fri, 4 Aug, 2023 at 6:49 PM
How are SSH Credentials Secured by Sandfly?
SSH keys are handled very carefully by the Sandfly platform. When you add SSH keys to Sandfly to gain access to your Linux systems, they are immediat...
Fri, 4 Aug, 2023 at 6:50 PM
Does Sandfly Support Key Vault Integration
Yes. Sandfly supports key vault integration with various vendors such as Hashicorp, Cyberark, Thycotic and more. We can customize these integrations based o...
Mon, 7 Aug, 2023 at 2:43 PM
Can Sandfly Run External Commands on Remote Hosts?
No. The forensic engines used by Sandfly are carefully designed to not allow any external commands to be run. This is part of our security model. The engine...
Fri, 4 Aug, 2023 at 6:51 PM
Does Sandfly Support SSH Jump Hosts?
Yes.  And: You can chain together multiple jump hosts to access restricted segments.  Incident responders can chain together disposable hosts to ac...
Mon, 7 Aug, 2023 at 2:35 PM
Does Sandfly Interfere With Keeping Linux Systems Updated?
No. Sandfly does not tie into kernel or core system libraries. You can update your systems as often as you'd like and it won't bother Sandfly. Furth...
Mon, 7 Aug, 2023 at 2:36 PM