# Sandfly Security Documentation > Sandfly Security is the security bot for Linux. Get agentless security and detection of malware, intruders and compromised Linux systems without loading anything on your endpoints. ## Guides - [Sandfly Agentless Security Overview](https://docs.sandflysecurity.com/docs/getting-started.md) - [Theory of Operation](https://docs.sandflysecurity.com/docs/theory-of-operation.md) - [Sandfly Scaling Guide](https://docs.sandflysecurity.com/docs/sandfly-scaling-guide.md) - [Installation Overview](https://docs.sandflysecurity.com/docs/installation-overview.md) - [Installation Requirements](https://docs.sandflysecurity.com/docs/installation-requirements.md) - [Protected System Requirements](https://docs.sandflysecurity.com/docs/protected-system-requirements.md) - [Standard Security vs. Maximum Security Install](https://docs.sandflysecurity.com/docs/standard-vs-maximum-security-install.md) - [Cloud Image Install](https://docs.sandflysecurity.com/docs/cloud-image-install.md) - [Server Install - Cloud Image - AWS](https://docs.sandflysecurity.com/docs/server-install-cloud-image-aws.md) - [Server Install - Cloud Image - DigitalOcean](https://docs.sandflysecurity.com/docs/server-install-cloud-image-do.md) - [Docker Image Install](https://docs.sandflysecurity.com/docs/docker-image-install.md) - [Install Container Tool](https://docs.sandflysecurity.com/docs/install-container-tool.md) - [Download Setup Archive](https://docs.sandflysecurity.com/docs/download-setup-archive.md) - [Server Install - Docker Image](https://docs.sandflysecurity.com/docs/server-install-docker.md) - [Node Install - Docker Image](https://docs.sandflysecurity.com/docs/node-install-docker.md) - [Sandfly Install - Docker Compose](https://docs.sandflysecurity.com/docs/sandfly-install-docker-compose.md) - [Sandfly Install - Kubernetes](https://docs.sandflysecurity.com/docs/sandfly-install-kubernetes.md) - [Installing a Custom SSL Certificate](https://docs.sandflysecurity.com/docs/installing-a-custom-ssl-certificate.md) - [Named Queues](https://docs.sandflysecurity.com/docs/named-queues.md) - [Quick Start Overview](https://docs.sandflysecurity.com/docs/quick-start-overview.md): Getting Started Quickly - [Login Screen](https://docs.sandflysecurity.com/docs/login-screen.md) - [User Interface Overview](https://docs.sandflysecurity.com/docs/user-interface-overview.md) - [Top Bar](https://docs.sandflysecurity.com/docs/top-bar.md): Sandfly Navigation Bar - [Threat Map](https://docs.sandflysecurity.com/docs/threat-map.md) - [Status Graph](https://docs.sandflysecurity.com/docs/status-graph.md) - [Sidebar](https://docs.sandflysecurity.com/docs/side-bar.md) - [UTC/Local Time Display](https://docs.sandflysecurity.com/docs/utclocal-time.md) - [Results Viewer](https://docs.sandflysecurity.com/docs/results-viewer.md): Dashboard Overview - [Results Top Bar](https://docs.sandflysecurity.com/docs/results-top-bar.md) - [Viewing Results](https://docs.sandflysecurity.com/docs/viewing-results.md) - [Deleting Results](https://docs.sandflysecurity.com/docs/deleting-results.md) - [Sandfly Hunter](https://docs.sandflysecurity.com/docs/sandfly-hunter.md) - [Hosts Management](https://docs.sandflysecurity.com/docs/hosts-management.md) - [Adding Hosts](https://docs.sandflysecurity.com/docs/adding-hosts.md) - [Viewing Hosts](https://docs.sandflysecurity.com/docs/viewing-hosts.md) - [Updating Hosts](https://docs.sandflysecurity.com/docs/updating-hosts.md) - [Deleting Hosts](https://docs.sandflysecurity.com/docs/deleting-hosts.md) - [Drift Detection](https://docs.sandflysecurity.com/docs/drift-detection-ui.md) - [Drift Detection Profiles](https://docs.sandflysecurity.com/docs/drift-detection-profiles.md) - [Drift Profile Details](https://docs.sandflysecurity.com/docs/drift-profile-details.md) - [Drift Detection Wizard](https://docs.sandflysecurity.com/docs/drift-detection-wizard.md) - [Drift Wizard - Model Hosts](https://docs.sandflysecurity.com/docs/drift-wizard-model-hosts.md) - [Drift Wizard - Use Case](https://docs.sandflysecurity.com/docs/drift-wizard-use-case.md) - [Drift Wizard - Drift Sandflies](https://docs.sandflysecurity.com/docs/drift-detection-drift-sandflies.md) - [Drift Wizard - Building Profile](https://docs.sandflysecurity.com/docs/drift-wizard-building-profile.md) - [Drift Wizard - Covered Hosts](https://docs.sandflysecurity.com/docs/drift-wizard-covered-hosts.md) - [Drift Wizard - Scan Schedule](https://docs.sandflysecurity.com/docs/drift-wizard-scan-schedule.md) - [Drift Wizard - Profile Details](https://docs.sandflysecurity.com/docs/drift-wizard-profile-details.md) - [SSH Hunter](https://docs.sandflysecurity.com/docs/ssh-hunter-ui.md) - [Security Zones](https://docs.sandflysecurity.com/docs/ssh-security-zones.md) - [Example: SSH Security Zone](https://docs.sandflysecurity.com/docs/example-ssh-security-zone.md) - [Banned Keys](https://docs.sandflysecurity.com/docs/banned-keys.md) - [Key Investigation](https://docs.sandflysecurity.com/docs/key-investigation.md) - [User Investigation](https://docs.sandflysecurity.com/docs/user-investigation.md) - [Host Investigation](https://docs.sandflysecurity.com/docs/host-investigation.md) - [Tag Workbench](https://docs.sandflysecurity.com/docs/ssh-key-tag-workbench.md) - [AI Analysis](https://docs.sandflysecurity.com/docs/ai-analysis-ui.md) - [Adding Analysis](https://docs.sandflysecurity.com/docs/adding-analysis.md) - [Viewing Analysis](https://docs.sandflysecurity.com/docs/viewing-analysis.md) - [Reports](https://docs.sandflysecurity.com/docs/reports-section.md) - [Scan](https://docs.sandflysecurity.com/docs/scan.md) - [Schedules](https://docs.sandflysecurity.com/docs/schedules.md) - [Adding Schedule - Scan Hosts](https://docs.sandflysecurity.com/docs/adding-schedule-scan-hosts.md) - [Adding Schedule - Discover Hosts](https://docs.sandflysecurity.com/docs/adding-schedule-discover-hosts.md) - [Viewing Schedule](https://docs.sandflysecurity.com/docs/viewing-schedule.md) - [Deactivating and Deleting Schedule](https://docs.sandflysecurity.com/docs/deactivating-and-deleting-schedule.md) - [Scheduling Optimization](https://docs.sandflysecurity.com/docs/scheduling-optimization.md) - [Response Actions](https://docs.sandflysecurity.com/docs/response-actions-ui.md) - [Result Response Actions](https://docs.sandflysecurity.com/docs/result-response-actions-ui.md) - [SSH Key Response Actions](https://docs.sandflysecurity.com/docs/ssh-key-response-actions-ui.md) - [Response Action Log](https://docs.sandflysecurity.com/docs/response-action-log-ui.md) - [Jump Hosts](https://docs.sandflysecurity.com/docs/jump-hosts.md) - [Host Credentials](https://docs.sandflysecurity.com/docs/host-credentials.md) - [Credentials Security](https://docs.sandflysecurity.com/docs/credentials-security.md) - [Adding Credentials](https://docs.sandflysecurity.com/docs/adding-credentials.md) - [Viewing Credentials](https://docs.sandflysecurity.com/docs/viewing-credentials.md) - [Updating Credentials](https://docs.sandflysecurity.com/docs/updating-credentials.md) - [Deleting Credentials](https://docs.sandflysecurity.com/docs/deleting-credentials.md) - [Sandflies](https://docs.sandflysecurity.com/docs/sandflies.md) - [Sandfly Types](https://docs.sandflysecurity.com/docs/sandfly-types.md) - [Viewing Sandflies](https://docs.sandflysecurity.com/docs/viewing-sandflies.md) - [Activating and Deactivating Sandflies](https://docs.sandflysecurity.com/docs/activating-and-deactivating-sandflies.md): You can deactivate a sandfly if you never want it run. This may be something you want to do if it is causing a false alarm in your environment and whitelisting the alert is not helping. - [Sandfly Auto Response](https://docs.sandflysecurity.com/docs/sandfly-auto-response.md) - [Whitelisting](https://docs.sandflysecurity.com/docs/whitelisting.md) - [Whitelisting a Sandfly](https://docs.sandflysecurity.com/docs/whitelisting-a-sandfly.md) - [Viewing and Deleting Whitelist Entries](https://docs.sandflysecurity.com/docs/viewing-and-deleting-whitelist-entries.md) - [Settings](https://docs.sandflysecurity.com/docs/settings-section.md) - [User Profile and Password](https://docs.sandflysecurity.com/docs/user-profile-and-password.md) - [Adding Users](https://docs.sandflysecurity.com/docs/adding-users.md) - [Single Sign-On (SSO)](https://docs.sandflysecurity.com/docs/sso-configuration.md) - [Your License](https://docs.sandflysecurity.com/docs/licensing.md) - [General Settings](https://docs.sandflysecurity.com/docs/server-configuration-setting.md) - [Threat Feeds](https://docs.sandflysecurity.com/docs/threat-feeds-ui.md) - [AI Configuration](https://docs.sandflysecurity.com/docs/ai-configuration.md) - [Notifications](https://docs.sandflysecurity.com/docs/alert-notifications.md) - [Adding Email Notifications](https://docs.sandflysecurity.com/docs/adding-email-notifications.md) - [Adding Webhook Notifications](https://docs.sandflysecurity.com/docs/adding-webhook-notifications.md) - [Deleting Notifications](https://docs.sandflysecurity.com/docs/deleting-notifications.md) - [Elasticsearch Replication](https://docs.sandflysecurity.com/docs/elasticsearch-replication.md) - [PostgreSQL Replication](https://docs.sandflysecurity.com/docs/postgres-replication.md) - [Sentinel Replication](https://docs.sandflysecurity.com/docs/sentinel-replication.md) - [Syslog](https://docs.sandflysecurity.com/docs/adding-syslog-notifications.md) - [3rd Party Applications](https://docs.sandflysecurity.com/docs/integrations-list.md) - [Logs](https://docs.sandflysecurity.com/docs/logs.md) - [Audit Log](https://docs.sandflysecurity.com/docs/audit-log.md) - [Scan Error Log](https://docs.sandflysecurity.com/docs/scan-error-log.md) - [Logging Out](https://docs.sandflysecurity.com/docs/log-out.md) - [Custom Sandfly Operation](https://docs.sandflysecurity.com/docs/custom-sandfly-operation.md) - [Custom Sandfly Creation](https://docs.sandflysecurity.com/docs/custom-sandfly-creation.md) - [Custom Sandfly Options](https://docs.sandflysecurity.com/docs/custom-sandfly-options.md) - [Rule Construction](https://docs.sandflysecurity.com/docs/rule-construction.md) - [Expr Rules for Sandfly](https://docs.sandflysecurity.com/docs/expr-rules-for-sandfly.md) - [Upgrading Sandfly Docker/Podman Deployment](https://docs.sandflysecurity.com/docs/upgrading-sandfly.md) - [Special Case Node Configurations](https://docs.sandflysecurity.com/docs/special-case-node-configurations.md) - [External Credential Provider Interface](https://docs.sandflysecurity.com/docs/external-credential-provider-interface.md) - [Docker Management](https://docs.sandflysecurity.com/docs/docker-management.md) - [Run Sandfly with Podman](https://docs.sandflysecurity.com/docs/run-sandfly-with-podman.md) - [Run Sandfly on Non-Default Ports](https://docs.sandflysecurity.com/docs/run-sandfly-on-non-default-ports.md) - [Backup and Restore Guide](https://docs.sandflysecurity.com/docs/backup-and-restore-guide.md) - [Log Level Change Guide](https://docs.sandflysecurity.com/docs/log-level-change-guide.md) - [Maintenance Scripts](https://docs.sandflysecurity.com/docs/maintenance-scripts.md) - [Hash Match Fields](https://docs.sandflysecurity.com/docs/hash-match-fields.md) - [Sandfly API](https://docs.sandflysecurity.com/docs/sandfly-api.md) - [API Endpoint Role Security Matrix](https://docs.sandflysecurity.com/docs/api-endpoint-role-security-matrix.md) - [Operational FAQ](https://docs.sandflysecurity.com/docs/operational-faq.md) - [Cisco NX-OS](https://docs.sandflysecurity.com/docs/notes-cisco-nx-os.md) - [JunOS Evolved](https://docs.sandflysecurity.com/docs/notes-junos-evolved.md) - [Tailscale SSH](https://docs.sandflysecurity.com/docs/notes-tailscale-ssh.md) - [Elastic Connector](https://docs.sandflysecurity.com/docs/notes-elastic-connector.md) - [Sandfly Forensic Keyword List](https://docs.sandflysecurity.com/docs/sandfly-forensic-keyword-list.md) - [Header Data](https://docs.sandflysecurity.com/docs/header-data.md): Header Data and Example - [Option Data](https://docs.sandflysecurity.com/docs/option-data.md) - [Operating System Data](https://docs.sandflysecurity.com/docs/operating-system-data.md) - [Explanation Data](https://docs.sandflysecurity.com/docs/explanation-data.md) - [File Data](https://docs.sandflysecurity.com/docs/file-data.md) - [Directory Data](https://docs.sandflysecurity.com/docs/directory-data.md) - [Process Data](https://docs.sandflysecurity.com/docs/process-data.md) - [User Data](https://docs.sandflysecurity.com/docs/user-data.md) - [Log Data](https://docs.sandflysecurity.com/docs/log-data.md) - [Lastlog Data](https://docs.sandflysecurity.com/docs/lastlog-data.md) - [(U|W|B)TMP Log Data](https://docs.sandflysecurity.com/docs/utmp-log-data.md) - [Cron Job Data](https://docs.sandflysecurity.com/docs/cron-job-data.md) - [At Job Data](https://docs.sandflysecurity.com/docs/at-job-data.md) - [Kernel Module Data](https://docs.sandflysecurity.com/docs/kernel-module-data.md) - [Systemd Data](https://docs.sandflysecurity.com/docs/systemd-data.md) - [License - EULA](https://docs.sandflysecurity.com/docs/license-eula.md) ## API Reference - [Getting Started - Sandfly API](https://docs.sandflysecurity.com/reference/api-landing-page.md) - [Get all email alerts](https://docs.sandflysecurity.com/reference/getemailalerts.md): Gets all of the email alert entries. - [Add email entry](https://docs.sandflysecurity.com/reference/addemailalert.md): Adds an email entry. - [Test email entry](https://docs.sandflysecurity.com/reference/testemailalert.md): Tests an email entry. - [Delete email entry](https://docs.sandflysecurity.com/reference/deleteemailalert.md): Deletes an email entry. - [Get email entry](https://docs.sandflysecurity.com/reference/getemailalert.md): Gets an email entry by name. - [Update email entry](https://docs.sandflysecurity.com/reference/updateemailalert.md): Updates an email entry. - [Get all syslog entries](https://docs.sandflysecurity.com/reference/getsyslogalerts.md): Gets all syslog entries - [Add syslog entry](https://docs.sandflysecurity.com/reference/addsyslogalert.md): Adds a syslog entry. - [Delete syslog entry](https://docs.sandflysecurity.com/reference/deletesyslogalert.md): Deletes a syslog entry. - [Get syslog entry](https://docs.sandflysecurity.com/reference/getsyslogalert.md): Get a syslog entry. - [Update syslog entry](https://docs.sandflysecurity.com/reference/updatesyslogalert.md): Updates a syslog entry. - [Get notifications](https://docs.sandflysecurity.com/reference/getnotifications.md): Get a list of all event notification configurations. - [Create notification](https://docs.sandflysecurity.com/reference/notificationadd.md): Create a new event notification configuration. - [Get notification details](https://docs.sandflysecurity.com/reference/getnotification.md): Get details of an event notification configuration. - [Update notification](https://docs.sandflysecurity.com/reference/updatenotification.md): Change an existing event notification configuration. - [Delete notification](https://docs.sandflysecurity.com/reference/deletenotification.md): Delete an event notification configuration. - [Test notification](https://docs.sandflysecurity.com/reference/testnotification.md): Attempt to send a test notification. - [Pause notifications](https://docs.sandflysecurity.com/reference/pausenotifications.md): Pauses notifications by ID. - [Unpause notifications](https://docs.sandflysecurity.com/reference/unpausenotifications.md): Unpauses notifications by ID. - [Pause notification](https://docs.sandflysecurity.com/reference/pausenotification.md): Pause a notification. - [Unpause notification](https://docs.sandflysecurity.com/reference/unpausenotification.md): Unpause a notification. - [Delete audit log](https://docs.sandflysecurity.com/reference/deleteauditlog.md): Deletes the audit log. - [Get audit log](https://docs.sandflysecurity.com/reference/getauditlog.md): Gets the audit log. - [Get current user](https://docs.sandflysecurity.com/reference/getme.md): Get the current logged in user. - [Get all users](https://docs.sandflysecurity.com/reference/getusers.md): Gets all of the users. - [Update user password](https://docs.sandflysecurity.com/reference/updateuserpassword.md): Updates the password of a user. - [Delete user](https://docs.sandflysecurity.com/reference/deleteuser.md): Deletes a user. - [Get user](https://docs.sandflysecurity.com/reference/getuser.md): Gets a user by username. - [Add user](https://docs.sandflysecurity.com/reference/createuser.md): Adds a user. - [Update user](https://docs.sandflysecurity.com/reference/updateuser.md): Updates a user. - [Get authentication token](https://docs.sandflysecurity.com/reference/apilogin.md): Gets the authentication token. - [Refresh authentication token](https://docs.sandflysecurity.com/reference/apiloginrefresh.md): Gets a new authentication token but marks old one as non-fresh. - [Log out user and revoke token](https://docs.sandflysecurity.com/reference/logout.md): Log out user and revoke token. - [Get login page info](https://docs.sandflysecurity.com/reference/getlogininfo.md): Returns pre-login information needed by the login page: whether SSO is enabled and the optional login warning message. - [Get SSO status](https://docs.sandflysecurity.com/reference/isssoenabled.md): Returns SSO enabled boolean. - [Get all server configurations](https://docs.sandflysecurity.com/reference/getconfig.md): Gets the current server configurations in the system. - [Update server configurations](https://docs.sandflysecurity.com/reference/updateconfig.md): Update server configurations. - [Regenerate self-signed TLS certificate](https://docs.sandflysecurity.com/reference/regeneratetlscert.md): Forces regeneration of the self-signed TLS certificate. This is a debug endpoint since certificates are auto-renewed before expiration. - [Rotate JWT Signing Key](https://docs.sandflysecurity.com/reference/rotatejwtkey.md): Generates a new JWT signing key and saves it to the database. This invalidates all existing user sessions, requiring users to log in again. The new key takes effect immediately. - [Delete credentials in bulk](https://docs.sandflysecurity.com/reference/deletecredentials.md): This deletes all credential_ids passed into the body as bulk operation. - [Get all credentials](https://docs.sandflysecurity.com/reference/getcredentials.md): Gets all of the credentials that are entered in the system. - [Delete remote system login encrypted record](https://docs.sandflysecurity.com/reference/deletecredential.md): Deletes a remote system login credential encrypted record. - [Get encrypted credentials](https://docs.sandflysecurity.com/reference/getcredential.md): Gets the encrypted credentials to allow scanning nodes to login to a remote host. - [Add remote system login credentials](https://docs.sandflysecurity.com/reference/addcredential.md): Creates either an sshkey/sshkey password or username/password to an encrypted remote host credential record. - [Update remote system login credentials](https://docs.sandflysecurity.com/reference/updatecredential.md): Updates the sshkey/sshkey password or username/password to an encrypted remote host credential record. - [Delete all scan errors](https://docs.sandflysecurity.com/reference/deletescanerrorlog.md): Deletes all errors. - [Get scan error log](https://docs.sandflysecurity.com/reference/getscanerrorlog.md): Gets the error log. - [Scan remote hosts](https://docs.sandflysecurity.com/reference/startscan.md): Scan remote hosts with host_id list and sandfly list. - [Scan remote hosts - ad hoc](https://docs.sandflysecurity.com/reference/startadhocscan.md): Scan remote hosts on an ad hoc basis with supplied key and sandflies. - [Delete hosts in bulk](https://docs.sandflysecurity.com/reference/deletehosts.md): Deletes all host_ids passed into the body as a bulk operation. - [Get all hosts](https://docs.sandflysecurity.com/reference/gethosts.md): Gets a list of all hosts in the system. **NOTE**: almost all uses of this function should use the `?summary=true` parameter; the raw call without a summary parameter or with `?summary=false` exists only for backward compatability. - [Add hosts](https://docs.sandflysecurity.com/reference/addhosts.md): Adds new hosts. - [Retry inactive hosts](https://docs.sandflysecurity.com/reference/retryhosts.md): Retry the attempt to connect to inactive hosts to add them to the system. - [Bulk tag hosts](https://docs.sandflysecurity.com/reference/bulktaghosts.md): Bulk update tags on hosts. - [Delete host](https://docs.sandflysecurity.com/reference/deletehost.md): Deletes a registered host by host ID. - [Get host](https://docs.sandflysecurity.com/reference/gethost.md): Gets a registered host by host ID. - [Update host](https://docs.sandflysecurity.com/reference/updatehost.md): Allows users to update a host (such as credentials to use, active or not, host aliases, jump_hosts and tags). - [Get host rollup](https://docs.sandflysecurity.com/reference/gethostrollup.md): Get a host and associated host data by host ID. - [Host kernel modules list](https://docs.sandflysecurity.com/reference/hostinfokernelmodules.md): Get kernel modules list for host. - [Host lastlog entry list](https://docs.sandflysecurity.com/reference/hostinfolastlog.md): Get lastlog entry list for host. - [Host network listeners list](https://docs.sandflysecurity.com/reference/hostinfolisteners.md): Get network listeners list for host. - [Host logged in users](https://docs.sandflysecurity.com/reference/hostinfologgedinusers.md): Get logged in users for host. - [Host process list](https://docs.sandflysecurity.com/reference/hostinfoprocesses.md): Get process list for host. - [Host scheduled tasks list](https://docs.sandflysecurity.com/reference/hostinfoscheduledtasks.md): Get scheduled tasks list for host. - [Host systemd service list](https://docs.sandflysecurity.com/reference/hostinfoservices.md): Get systemd service unit list for host. - [Host user list](https://docs.sandflysecurity.com/reference/hostinfousers.md): Get user list for host. - [Delete jump hosts in bulk](https://docs.sandflysecurity.com/reference/deletejumphosts.md): Deletes all jump hosts passed into the body as bulk operation. - [Get all jump hosts](https://docs.sandflysecurity.com/reference/getjumphosts.md): Gets all of the jump hosts in the system. - [Delete jump host](https://docs.sandflysecurity.com/reference/deletejumphost.md): Deletes a jump host by name. - [Get jump host](https://docs.sandflysecurity.com/reference/getjumphost.md): Gets a jump host by jump host name. - [Add jump host](https://docs.sandflysecurity.com/reference/addjumphost.md): Allows users to create a jump host. - [Update jump host](https://docs.sandflysecurity.com/reference/updatejumphost.md): Allows users to update a jump host (such as credentials to use or new hostname). - [Delete license](https://docs.sandflysecurity.com/reference/deletelicense.md): Deletes a license. - [Get license data](https://docs.sandflysecurity.com/reference/getlicense.md): Gets the license data. - [Add license entry](https://docs.sandflysecurity.com/reference/addlicense.md): Adds a license entry. - [Update license entry](https://docs.sandflysecurity.com/reference/updatelicense.md): Updates a license entry. - [Refresh license entitlement](https://docs.sandflysecurity.com/reference/refreshlicense.md): Refresh an online license entitlement. - [Get LLM analyses](https://docs.sandflysecurity.com/reference/getllmanalyses.md): Get list of all LLM analyses. The returned list will be in reverse chronological order of modification date. If a hostid or resultid query parameter is supplies, the results will be limited to that result and/or host ID (if both are provided, they are treated as "or"). - [Begin LLM analysis](https://docs.sandflysecurity.com/reference/beginllmanalysis.md): Begin a new LLM analysis for a host or result(s). - [Bulk delete LLM analyses](https://docs.sandflysecurity.com/reference/deletellmanalysisbulk.md): Bulk delete LLM analyses. Call is idempotent; will return OK even if LLM analysis ID does not exist. - [Get LLM analysis](https://docs.sandflysecurity.com/reference/getllmanalysis.md): Get an LLM analysis, with its metadata and model response(s). - [Delete LLM analysis](https://docs.sandflysecurity.com/reference/deletellmanalysis.md): Delete an LLM analysis. Call is idempotent; will return OK even if LLM analysis ID does not exist. - [Add chat to LLM analysis](https://docs.sandflysecurity.com/reference/addllmanalysischat.md): Add a new user chat message to an LLM analysis and submit to the model to get a response. The LLM analysis must be in the "ready" state. - [Wait for LLM analysis](https://docs.sandflysecurity.com/reference/waitllmanalysiscomplete.md): Wait for an LLM analysis to complete. This endpoint will not return until the requested LLM analysis ID has returned to a "ready" or "error" state. - [Host snapshot report](https://docs.sandflysecurity.com/reference/gethostsnapshot.md): Host snapshot report. - [Scan performance report](https://docs.sandflysecurity.com/reference/getscanperformance.md): Scan performance report. - [Perform response action on a process result](https://docs.sandflysecurity.com/reference/dispatchresultaction.md): Initiates a response action from an existing result. For process actions (process_kill, process_suspend, process_resume, process_retrieve), the result must contain process data with a SHA-512 hash. For file_retrieve, the result must contain a file path (from file, cron, or at job engines). Requires the responder role. Can be disabled server-wide with SF_DISABLE_RESPONSES and at the node level with SF_NODE_DISABLE_RESPONSES. Returns a ResponseActionResponse in both the queued (HTTP 202) and cached-fulfillment (HTTP 200, retrieve actions only) cases. - [Remove or deduplicate an SSH key across all hosts](https://docs.sandflysecurity.com/reference/dispatchsshkeyaction.md): Performs an SSH key response action (remove or deduplicate) across all hosts and users where the key is deployed. Requires the responder role. Creates one order per affected host, each containing one action per affected user. Can be disabled server-wide with SF_DISABLE_RESPONSES and at the node level with SF_NODE_DISABLE_RESPONSES. For 'remove' actions, a last-key protection safety check denies the request with HTTP 409 if any affected host would be left with zero SSH keys known to Sandfly; set allow_last_key_removal=true in the request body to override. - [Remove or deduplicate an SSH key on a specific host](https://docs.sandflysecurity.com/reference/dispatchsshkeyhostaction.md): Performs an SSH key response action on a specific host for all users that have the key. Requires the responder role. For 'remove' actions, a last-key protection safety check denies the request with HTTP 409 if the host would be left with zero SSH keys known to Sandfly; set allow_last_key_removal=true in the request body to override. - [Remove or deduplicate an SSH key for a specific user on a specific host](https://docs.sandflysecurity.com/reference/dispatchsshkeyhostuseraction.md): Performs an SSH key response action for a specific user on a specific host. Requires the responder role. For 'remove' actions, a last-key protection safety check denies the request with HTTP 409 if the host would be left with zero SSH keys known to Sandfly after removing the key for this user; set allow_last_key_removal=true in the request body to override. - [List response action log entries](https://docs.sandflysecurity.com/reference/getresponseactionlog.md): Returns a paginated list of response action log entries, ordered by request time descending. Includes a summary of each action without the bulky source result and action result JSON blobs. - [Get response action log entry](https://docs.sandflysecurity.com/reference/getresponseactionlogentry.md): Returns a single response action log entry by action ID, including the source result JSON and action result JSON. - [Delete file associated with retrieve action](https://docs.sandflysecurity.com/reference/deleteresponseactionlogentrydata.md): Delete the data blob associated with a process retrieve or file retrieve action from the database. - [Download a retrieved binary blob by hash](https://docs.sandflysecurity.com/reference/getbinary.md): Downloads the binary blob retrieved by a response action (process binary or file). Identified by SHA-512 content hash. Multiple action log entries may reference the same blob. Requires the responder role. - [Delete results](https://docs.sandflysecurity.com/reference/deleteresults.md): Deletes results. - [Get results](https://docs.sandflysecurity.com/reference/getresults.md): Gets all of the results. - [Get max result ID](https://docs.sandflysecurity.com/reference/getmaxid.md): Gets the highest sequence_id currently present in the results table that is safe for replication (no results IDs will ever appear in the future lower than this ID). - [Result timeline](https://docs.sandflysecurity.com/reference/getresultstimeline.md): Get results timelines for hosts. - [Delete all results](https://docs.sandflysecurity.com/reference/deleteallresults.md): Deletes all results. - [Delete result](https://docs.sandflysecurity.com/reference/deleteresult.md): Deletes a result by result ID. - [Get result](https://docs.sandflysecurity.com/reference/getresult.md): Gets a result by result ID. - [Get result detail](https://docs.sandflysecurity.com/reference/getresultdetail.md): Gets a result by ID along with additional mutable status data, including the response action log for this result. - [Delete sandfly results for host](https://docs.sandflysecurity.com/reference/deletehostsandflyresults.md): Delete all results for a sandfly list on a single host. - [Delete host results for sandfly](https://docs.sandflysecurity.com/reference/deletesandflyhostresults.md): Delete all results for a host list on a single sandfly. - [Get host result summary](https://docs.sandflysecurity.com/reference/gethostresultsummary.md): Gets results grouped by sandfly for a particular host. - [Get sandfly result summary](https://docs.sandflysecurity.com/reference/getsandflyresultsummary.md): Gets results grouped by host for a particular sandfly. - [Get result profiles](https://docs.sandflysecurity.com/reference/getprofiles.md): Get summary list of all result profiles. - [Create new result profile](https://docs.sandflysecurity.com/reference/createprofile.md): Create new result profile. One or more host IDs and/or result IDs must be included in the request, which will add the associated eligible results to the result profile. - [Create auto-drift profile](https://docs.sandflysecurity.com/reference/createprofileautodrift.md): Create a new result profile that will automatically gather results from a set of model hosts for a period of time before applying them as a drift (and optionally whitelist) profile on a set of covered hosts. - [Edit autodrift profile](https://docs.sandflysecurity.com/reference/editautodriftprofile.md): Edit an autodrift profile. Optionally edit different parts of the profile by setting the objects non-null; null objects (or keys left out) indicate that that portion of the profile will not be modified. - [Remove gather configuration](https://docs.sandflysecurity.com/reference/deleteautodriftgather.md): Remove gather configuration from an autodrift profile. - [Switch to enforce mode](https://docs.sandflysecurity.com/reference/enforceautodriftprofile.md): Immediately transition an autodrift profile to enforce mode. - [Restart gather period](https://docs.sandflysecurity.com/reference/restartautodriftgather.md): Restart/re-enter gather period on an autodrift profile. - [Remove schedule configuration](https://docs.sandflysecurity.com/reference/deleteautodriftschedule.md): Remove scan schedule configuration from an autodrift profile. - [Get auto-drift templates](https://docs.sandflysecurity.com/reference/getautodrifttemplates.md): Get recommended auto-drift result profile templates for various use cases. - [Get a result profile](https://docs.sandflysecurity.com/reference/getprofile.md): Get details of a result profile by ID. - [Update result profile](https://docs.sandflysecurity.com/reference/updateprofile.md): Update the details and associations of a result profile. This replaces all existing associations on the result profile. - [Delete a result profile](https://docs.sandflysecurity.com/reference/deleteprofile.md): Delete a single result profile by ID. - [Append results to result profile](https://docs.sandflysecurity.com/reference/appendprofile.md): Append additional results from model host(s) and/or result IDs to an existing result profile. - [Automatically append results to an autodrift profile](https://docs.sandflysecurity.com/reference/autoappendprofile.md): Append all current results from the previously configured model hosts to an existing auto-drift profile. - [Get result profile sandfly results](https://docs.sandflysecurity.com/reference/getprofilesandfly.md): Get a list of results that are part of a result profile for a given sandfly. - [Delete a sandfly from a result profile](https://docs.sandflysecurity.com/reference/deleteprofilesandfly.md): Delete all of the results for a sandfly on a result profile, removing enforcement of drift/whitelisting for the sandfly from the profile. - [Bulk delete sandflies from profile](https://docs.sandflysecurity.com/reference/bulkdeleteprofilesandflies.md): Bulk delete sandflies from a result profile. - [Delete result hash from result profile.](https://docs.sandflysecurity.com/reference/deleteprofileresult.md): Delete a specific result hash from a sandfly on a result profile. - [Bulk delete results from profile](https://docs.sandflysecurity.com/reference/bulkdeleteprofileresults.md): Bulk delete results from a sandfly on a result profile. - [Get result profiles for host](https://docs.sandflysecurity.com/reference/getprofilesforhost.md): Get summary of all result profiles that apply to this host ID. - [Export result profiles](https://docs.sandflysecurity.com/reference/exportprofiles.md): Export selected result profiles for backup or to move to another system. - [Import result profiles](https://docs.sandflysecurity.com/reference/importprofiles.md): Import selected result profiles from backup. - [Bulk pause result profiles](https://docs.sandflysecurity.com/reference/bulkpauseprofiles.md): Pause result profiles in bulk, preventing them from creating drift alerts or whitelisting incoming results. - [Bulk unpause result profiles](https://docs.sandflysecurity.com/reference/bulkunpauseprofiles.md): Unpause result profiles in bulk. - [Pause result profile](https://docs.sandflysecurity.com/reference/pauseprofile.md): Pause a result profile, preventing it from creating drift alerts or whitelisting incoming results. - [Unpause result profile](https://docs.sandflysecurity.com/reference/unpauseprofile.md): Unause a result profile. - [Delete result profiles](https://docs.sandflysecurity.com/reference/deleteprofiles.md): Bulk delete result profiles with a list of result profile IDs. - [Get result profile result](https://docs.sandflysecurity.com/reference/getprofileresultjson.md): Get result JSON for a result profile result ID. - [Get all registered sandflies](https://docs.sandflysecurity.com/reference/getsandflies.md): Gets all of the registered sandflies. - [Add custom sandfly](https://docs.sandflysecurity.com/reference/addsandfly.md): Adds a custom sandfly. - [Update custom sandfly](https://docs.sandflysecurity.com/reference/updatesandfly.md): Updates a custom sandfly. - [Activate sandflies in bulk](https://docs.sandflysecurity.com/reference/activatesandflies.md): Activates all sandflies passed into the body as bulk operation. - [Backup all custom sandflies](https://docs.sandflysecurity.com/reference/backupsandflies.md): This displays all registered custom sandflies as a big JSON object for backup purposes. - [Deactivate sandflies in bulk](https://docs.sandflysecurity.com/reference/deactivatesandflies.md): Deactivates all sandflies passed into the body as bulk operation. - [Delete custom sandflies](https://docs.sandflysecurity.com/reference/deletesandflies.md): Deletes a custom sandfly entry by name. - [Delete custom sandfly](https://docs.sandflysecurity.com/reference/deletesandfly.md): Deletes a custom sandfly entry. - [Get sandfly](https://docs.sandflysecurity.com/reference/getsandfly.md): Gets a sandfly with the supplied name. - [Activate sandfly](https://docs.sandflysecurity.com/reference/activatesandfly.md): Activates a sandfly by name. - [Deactivate sandfly](https://docs.sandflysecurity.com/reference/deactivatesandfly.md): Deactivates a sandfly by name. - [Reload all sandflies to default](https://docs.sandflysecurity.com/reference/reloadsandflies.md): Reloads all of the sandflies in server's sandfly directory to their default settings. - [Update system sandfly response options](https://docs.sandflysecurity.com/reference/updateresponse.md): Updates the system sandfly response options. - [Delete custom view](https://docs.sandflysecurity.com/reference/deleteview.md): Deletes a single custom grid view, for a specific data grid, for the current user. - [Delete schedules in bulk](https://docs.sandflysecurity.com/reference/deleteschedules.md): Deletes all schedule_ids passed into the body as a bulk operation. Schedules that don't exist will be ignored without error; schedules that are of type result_profile_gather will not be deleted, but any current trickle run will be canceled. - [Get all schedules](https://docs.sandflysecurity.com/reference/getschedules.md): Gets everything that is scheduled. - [Add a scan schedule](https://docs.sandflysecurity.com/reference/addschedule.md): Adds a scheduled scan. - [Run scheduled scan now](https://docs.sandflysecurity.com/reference/runschedule.md): Manually runs a schedule. - [Deactivate schedules](https://docs.sandflysecurity.com/reference/pauseschedules.md): Deactivates (pauses) schedules by ID. - [Activate schedules](https://docs.sandflysecurity.com/reference/unpauseschedules.md): Activates (unpauses) schedules by ID. - [Deactivate schedule](https://docs.sandflysecurity.com/reference/pauseschedule.md): Deactivates (pauses) a schedule. - [Activate schedule](https://docs.sandflysecurity.com/reference/resumeschedule.md): Activates (unpauses) a schedule. - [Delete schedule](https://docs.sandflysecurity.com/reference/deleteschedule.md): Deletes a schedule by schedule_name. Only schedules of type scan and discover can be deleted, result_profile_gather schedules can only be removed by editing or deleting the related result profile. - [Get schedule](https://docs.sandflysecurity.com/reference/getschedule.md): Gets a schedule by schedule_name - [Update scheduled scan](https://docs.sandflysecurity.com/reference/updateschedule.md): Updates a scheduled scan. - [Abort schedule run](https://docs.sandflysecurity.com/reference/abortschedule.md): Abort an active schedule run, preventing additional hosts from being added to the scan queue during this run.Note that this only prevents new hosts from being added to the scan queue, it does not affect scans that have already begun. - [Get SSH Hunter graph nodes](https://docs.sandflysecurity.com/reference/getsshgraph.md): Get graph of relationships between SSH public keys, hosts, and users from SSH Hunter. - [Get hosts with SSH public keys](https://docs.sandflysecurity.com/reference/getsshhosts.md): Get list of hosts with SSH public keys from SSH Hunter. Deprecated in favor of `GET /v4/hosts?summary=true&...` which now includes all of the same data. - [Get SSH public key details for a host](https://docs.sandflysecurity.com/reference/getsshhost.md): Get details of a host with SSH public keys from SSH Hunter. Deprecated in favor of `GET /v4/hostsrollup/{host_id}`, which includes all of the same data. - [Add SSH keys](https://docs.sandflysecurity.com/reference/addsshkeys.md): Add SSH public keys. - [Get SSH public key details](https://docs.sandflysecurity.com/reference/getsshkey.md): Get details of an SSH public key from SSH Hunter. - [Bulk tag SSH keys](https://docs.sandflysecurity.com/reference/bulktagsshkeys.md): Bulk update tags on SSH public keys. - [Tag SSH key](https://docs.sandflysecurity.com/reference/tagsshkey.md): Set tags on an SSH public key. - [Get SSH keys host tags](https://docs.sandflysecurity.com/reference/getsshkeyshosttags.md): For the set of requested keys, get the hosts tags for the hosts the keys were found on. The result object will contain an entry for each key in the input key list that exists in the database. Keys that don't exist will be ignored. - [Get hosts+tags for SSH keys](https://docs.sandflysecurity.com/reference/getsshhostsandtagsforkeys.md): For the requested list of SSH key IDs, returns a list of all hosts with those keys and the host tags on each host. - [Get keys+tags for hosts](https://docs.sandflysecurity.com/reference/getsshkeysandtagsforhosts.md): For the requested list of Host IDs, returns a list of all keys on those hosts and the key tags on each key. - [Get SSH public keys](https://docs.sandflysecurity.com/reference/getsshsummary.md): Get list of SSH public keys from SSH Hunter. - [Get users with SSH public keys](https://docs.sandflysecurity.com/reference/getsshusers.md): Get list of users with SSH public keys from SSH Hunter. - [Get SSH public key details for a user](https://docs.sandflysecurity.com/reference/getsshuser.md): Get details of a user with SSH public keys from SSH Hunter. - [Get SSH security zones](https://docs.sandflysecurity.com/reference/getsshzones.md): Get summary list of all SSH security zones. - [Create SSH security zone](https://docs.sandflysecurity.com/reference/createsshzone.md): Create a new SSH security zone. - [Get an SSH security zone](https://docs.sandflysecurity.com/reference/getsshzone.md): Get details of an SSH security zone by ID. - [Update SSH security zone](https://docs.sandflysecurity.com/reference/updatesshzone.md): Update an SSH security zone. - [Delete SSH security zone](https://docs.sandflysecurity.com/reference/deletesshzone.md): Delete an SSH security zone. - [Get system status statistics](https://docs.sandflysecurity.com/reference/getstatus.md): Gets system status statistics. - [Get node status statistics](https://docs.sandflysecurity.com/reference/getstatusbynodes.md): Gets node status statistics. - [Get system status by tags over time](https://docs.sandflysecurity.com/reference/getstatusbytag.md): Gets system status by tags over time. - [Purge task queues](https://docs.sandflysecurity.com/reference/purgetaskqueues.md): Purge the server's knowledge of all outstanding tasks. - [Get active queue names](https://docs.sandflysecurity.com/reference/getactivetaskqueues.md): Gets the active queue names with node counts. - [Get all host tags](https://docs.sandflysecurity.com/reference/gethosttags.md): Gets all of the host tags in a unique list format. - [Get all sandfly tags](https://docs.sandflysecurity.com/reference/getsandflytags.md): Gets all of the sandfly tags in a unique list format. - [Get all SSH key tags](https://docs.sandflysecurity.com/reference/getsshkeytags.md): Gets all unique SSH key tags. - [Get threat feeds](https://docs.sandflysecurity.com/reference/getthreatfeeds.md): Get a list of all threat feed configurations. - [Create threat feed](https://docs.sandflysecurity.com/reference/addthreatfeed.md): Create a new threat feed configuration. - [Get threat feed details](https://docs.sandflysecurity.com/reference/getthreatfeed.md): Get details of a threat feed configuration. - [Update threat feed](https://docs.sandflysecurity.com/reference/updatethreatfeed.md): Change an existing threat feed configuration. - [Delete threat feed](https://docs.sandflysecurity.com/reference/deletethreatfeed.md): Delete a threat feed configuration. - [Get version](https://docs.sandflysecurity.com/reference/getsystemversion.md): Gets the version of the product. - [Get whitelist rules](https://docs.sandflysecurity.com/reference/getwhitelistrules.md): Get all whitelist rules. - [Add Whitelist Rule](https://docs.sandflysecurity.com/reference/createwhitelistrule.md): Add a whitelist rule. - [Get whitelist rule](https://docs.sandflysecurity.com/reference/getwhitelistrule.md): Get a whitelist rule by ID. - [Update whitelist rule](https://docs.sandflysecurity.com/reference/updatewhitelistrule.md): Update a whitelist rule. - [Delete Whitelist Rule](https://docs.sandflysecurity.com/reference/deletewhitelistrule.md): Delete a whitelist rule. - [Activate whitelist rules in bulk](https://docs.sandflysecurity.com/reference/activatewhitelistrules.md): Activate whitelist rules by ID. - [Dectivate whitelist rules in bulk](https://docs.sandflysecurity.com/reference/deactivatewhitelistrules.md): Deactivate whitelist rules by ID. - [Activate whitelist](https://docs.sandflysecurity.com/reference/activatewhitelistrule.md): Activate a whitelist. - [Deactivate whitelist](https://docs.sandflysecurity.com/reference/deactivatewhitelistrule.md): Deactivate a whitelist. - [Get whitelists for host](https://docs.sandflysecurity.com/reference/gethostwhitelistrules.md): Get all whitelist rules for a particular host. - [Delete Whitelist Rules](https://docs.sandflysecurity.com/reference/deletewhitelistrules.md): Bulk deletes whitelist rules.