Sandfly Security

Sandfly Security Documentation

Welcome to the Sandfly Security documentation hub. Sandfly is an agentless compromise and intrusion detection system for Linux.

Sandfly automates security investigation and forensic evidence collection on Linux. Sandfly constantly searches for intruders 24 hours a day on your network without needing to load any agents on your endpoints.

Get Started

User Interface Overview

Sandfly User Interface Operation

Sandfly User Interface

Sandfly User Interface

The User Interface (UI) is broken down into four three areas:

  1. Top Bar
  2. Alarm Viewer
  3. Status Screen

User Interface Overview


Sandfly User Interface Operation

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.