Sandfly Security develops agentless Linux security software for organizations that need threat visibility without installing endpoint agents. Its platform focuses exclusively on Linux and is used to detect intrusions, hunt malware, gather forensic evidence, and support incident response across cloud, on-premises, hybrid, embedded, and air-gapped environments.
The company positions its approach around fast deployment, broad Linux compatibility, and low operational risk. By relying on SSH-based access rather than persistent agents, Sandfly Security is designed for servers, appliances, and edge systems where performance, stability, or change-control requirements make traditional endpoint tooling difficult to deploy. Its offering spans continuous monitoring, credential and SSH key auditing, drift detection, and AI-assisted event interpretation for Linux estates.
Offerings, Capabilities, and Integrations
Sandfly Security provides an agentless operating model for Linux monitoring, detection, and response. The platform automates compromise hunting and forensic collection without loading software on protected hosts, which makes it suitable for production servers, legacy systems, embedded devices, networking gear, and other Linux assets that are difficult to monitor with kernel-level agents.
Its capabilities include scheduled and on-demand scanning, baseline and drift comparison, custom threat hunting modules, automated process response options, and distributed deployment for large Linux fleets. Sandfly Security also supports operational integrations through a REST API, syslog forwarding, webhook notifications, Microsoft Sentinel replication, Elasticsearch and PostgreSQL replication, single sign-on, and external credential provider connections for teams that manage secrets outside the platform.
Products and Services
- Sandfly Agentless Security: Flagship Linux security platform that delivers agentless intrusion detection, threat hunting, forensic collection, and incident response workflows across Linux environments.
- Threat Detection: Continuous Linux threat detection capability that identifies malware, intruder activity, suspicious processes, credential abuse, and other signs of compromise.
- SSH Hunter: SSH key auditing and tracking capability that maps key usage, exposes risky or unauthorized keys, and helps investigate SSH-based lateral movement.
- Agentless Password Auditing: Password auditing capability for finding weak and default Linux credentials without deploying endpoint agents.
- Agentless Drift Detection: Drift detection capability that highlights unauthorized or unexpected changes across Linux systems, including users, services, files, processes, and kernel modules.
- Incident Response: Linux incident response capability that supports rapid deployment, compromise assessment, forensic evidence gathering, and deeper investigative workflows.
- AI Powered Analysis: AI-assisted event analysis capability that helps teams interpret Linux security alerts and forensic findings more quickly using LLM integrations and on-premises AI options.
- Custom Sandflies: Framework for creating and cloning custom threat hunting checks tailored to an organization’s own Linux environment and detection requirements.
- Sandfly Auto Response: Active response capability that can suspend or kill targeted malicious processes when selected detections trigger.
- Sandfly API: REST API for integrating Sandfly Security with external security tools, automation workflows, and operational scripts.
Target Customers
Sandfly Security targets organizations with Linux-heavy environments that cannot tolerate the performance, stability, or compatibility tradeoffs of traditional agent-based tooling. Its fit is strongest for teams securing cloud servers, on-premises infrastructure, mixed estates, embedded Linux systems, appliances, and isolated or air-gapped networks.
Typical buyers include security operations teams, incident response teams, infrastructure and platform engineering groups, and organizations responsible for mission-critical Linux systems. The company is especially relevant for enterprises and operators in areas such as manufacturing, telecommunications, education, automotive and mobility, energy, and critical infrastructure where Linux visibility is important but endpoint changes are tightly controlled.
Cloud Integrations and Marketplace
- AWS Marketplace: Sandfly Security is available in AWS Marketplace as an Amazon Machine Image for deployment on Amazon EC2.
- Microsoft Azure Marketplace: Sandfly Security is listed in Microsoft Azure Marketplace as a virtual machine offering for deployment in Azure environments.
- DigitalOcean Marketplace: Sandfly Security is available in DigitalOcean Marketplace as a 1-Click App and Droplet deployment option.
Key People
- Craig Rowland: CEO / Founder
- Rob Joyce: Advisory Board Member
- Ron Gula: Investor, Gula Tech Adventures
- Ken Elefant: Investor, Sorenson Capital
- Chris Jagger: Investor, Alt Ventures
Key Facts
- Headquarters: Christchurch, Canterbury, New Zealand
- Employees: 51-200
- Annual Revenue: Undisclosed
- Parent Company: None
- Subsidiaries: None
- Publicly Listed: No (privately held)