Sandfly Forensic Keyword List

JSON Keywords for Linux Forensic Data

This section lists out the forensic data Sandfly can return as part of its results. In the UI you will see this data in the forensics viewer. In the REST API ( it will be returned as a JSON object. This structured data is also passed over syslog to your destination of choice (e.g. SIEM or log aggregator).

Relevant keywords are returned for the detected attack type. For instance, you will only see process related keywords if a malicious process is the detected problem. File data only shows for file related detections, etc.

The data provided in this section reflects the current, released version of the product.