Sandflysecurity
Tel Aviv-Yafo, IL · Founded 2017 · 13 employees on LinkedIn · 3 known investors
Sandfly is an agentless Linux security platform that hunts for compromised systems, detecting rootkits, backdoors, cryptominers, and other intrusions across servers, cloud, embedded devices, and air-gapped networks. It offers over 1,100 pre-built detections plus customizable threat hunting modules, and is used by critical infrastructure providers.
Also known as Sandfly · Sandfly Security · Sandfly Security LTD
Founders & leadership
Sandflysecurity was founded in 2017 by Craig Rowland.

Investors · 3
Also in the syndicate · 1
Company profile
researched Aug 2026Sandfly Security is a Linux security company whose product is an agentless intrusion detection, threat hunting, and incident response platform. Rather than installing software agents on protected endpoints, Sandfly works against most Linux versions that have SSH installed, including Red Hat, CentOS, Ubuntu, Debian, Fedora, Suse, Amazon AWS Linux, Linode images, and DigitalOcean images. It automates continuous searching for hackers, malware, and suspicious activity, collects forensic evidence to support incident response, and can be configured to run automated responses when threats are detected.
Capabilities marketed by the company include detection of known and unknown Linux threats, SSH key monitoring to identify stolen credentials and lateral movement, password auditing for weak credentials, drift detection for unauthorized host changes, custom modules ("sandflies") for emerging threats, and an AI-based analyst feature for alert investigation. Modules are tagged to MITRE ATT&CK techniques, and alert data is available as JSON via the interface and a REST API. The platform supports a broad range of CPU architectures, with version 4.5.0 adding a new expression language syntax for custom threat hunting modules and expanded CPU support covering IBM POWER8, 9, and 10 processors. Sandfly states it protects systems ranging from modern cloud deployments to decade-old devices regardless of distribution or CPU architecture.
The company maintains public documentation at docs.sandflysecurity.com and a GitHub organization publishing setup scripts and open-source Linux forensics utilities, including an entropy scanner for packed or encrypted binaries, kernel module and file de-cloaking tools for stealth rootkits, and SSH key security scanners.
Founding story
Sandfly was founded by Craig Rowland, who previously built intrusion detection technologies, one of which reduced false alarms by up to 95 percent and was acquired by Cisco. Before working in the private sector he spent years with the Chief of Naval Operations at the U.S. Pentagon. Observing how security teams struggled to protect critical assets, he concluded that traditional agent-based approaches were poorly suited to securing Linux, which led to Sandfly's agentless design.
Business model
Sandfly sells a commercial Linux security platform, licensed per protected host and user, with a free tier covering up to 50 hosts and 5 user accounts alongside paid professional licensing and free trial licenses. The software is customer-deployed, including as a Docker/Podman deployment or via a preconfigured DigitalOcean Droplet image.
Commercial software licensing of the Sandfly platform, with a free-of-charge tier for small deployments and trial licenses used to convert users to paid licenses.
Traction
Sandfly reports use by companies in telecommunications, manufacturing, and networking that operate critical infrastructure. Public endorsements come from the Netfilter team, a senior security engineer at the University of Massachusetts, and DigitalOcean's deputy CISO, whose company also distributes Sandfly through its marketplace. Ericsson integrated Sandfly's agentless EDR into its Security Manager XDR product. The main sandfly-setup GitHub repository has 93 stars and 15 forks, and the sandfly-entropyscan tool has 170 stars.
Latest developments
Current marketing highlights an AI-powered analyst capability for alert investigation and an announced integration of Sandfly agentless EDR into the Ericsson Security Manager XDR solution. The DigitalOcean Marketplace listing shows version 5.8.1 running on Debian 13 (Trixie).
▸Full profile — market position, technology, go-to-market, geography, history
Market position
Positions itself against agent-based endpoint detection products, which the company argues have compatibility, stability, and CPU/performance drawbacks on Linux and cannot cover legacy or embedded systems. Cited customers and endorsers include the Netfilter team, the University of Massachusetts, DigitalOcean, and Ericsson, which integrated Sandfly's agentless EDR into its Ericsson Security Manager XDR solution.
Sandfly's core differentiator is that it requires no agent on protected Linux endpoints, which the company says avoids the CPU, stability, and compatibility problems of agent-based tools and allows coverage of legacy and embedded devices that other EDR products cannot support. It emphasizes Linux specialization, a large library of over 1,100 prebuilt checks with low false-positive noise, forensic evidence collection, and customizable modules.
Technology
Agentless architecture that reaches Linux hosts over SSH and runs modular checks ("sandflies") without installing endpoint software, then removes itself, leaving no persistent footprint. The catalog includes over 1,100 modules spanning templated, incident, directory, file, process, log, policy, and recon categories; one deployment exported 1,168 available sandflies. Findings include detailed forensic data points, cryptographic hashes, MITRE ATT&CK technique tags, and raw JSON, supporting pivoting across hosts. Deployment options include a combined server/node install or dockerized servers and nodes, with jump host support for segmented networks, external credential provider adapters, and application notes for platforms such as Cisco NX-OS, JunOS Evolved, and Tailscale SSH.
Go-to-market
Direct sales via website contact and free trial/free-tier licenses, distribution through the DigitalOcean Marketplace 1-Click App, OEM/partner integration such as embedding agentless EDR into Ericsson's Security Manager XDR solution, and technical community outreach through open-source forensic tools on GitHub, extensive public documentation, and third-party security press coverage. Support is offered during U.S. and New Zealand business hours.
Organizations running Linux infrastructure, particularly critical infrastructure operators in telecommunications, manufacturing, and networking, as well as cloud providers, universities, and operators of embedded, legacy, and air-gapped Linux systems.
Geography
Described in 2023 press coverage as headquartered in New Zealand; the corporate entity is Sandfly Security LTD, and support is provided during U.S. and New Zealand working hours. Investors include Alt Ventures New Zealand, and the company describes protecting Linux infrastructure globally.
History
By mid-2023 the platform had reached version 4.5.0, which introduced a new expression language for custom threat hunting modules, broadened built-in module coverage, and added IBM POWER8/9/10 CPU support; it was reviewed that year by the SANS Internet Storm Center. In March 2024 the company announced seed funding from Gula Tech Adventures and Sorenson Capital to expand product capabilities and accelerate go-to-market. The product had reached version 5.8.1 on the DigitalOcean Marketplace.
Compiled by commissioned research from 8 cited public sources — announcements, filings, and press listed under research sources below.
Key figures
latest reportedCompany-reported or press-reported figures, each dated to when it was claimed — not independently audited.
Timeline · 4
launches, deals, and filingsEricsson's Head of Security Solutions stated that Sandfly's agentless EDR was integrated into the Ericsson Security Manager XDR solution to extend detection capability where traditional endpoint agents are unsuitable.
Sandfly Security announced seed funding from Gula Tech Adventures and Sorenson Capital, to be used to expand product capabilities and accelerate go-to-market. The company lists its investors as Gula Tech Adventures, Sorenson Capital, and Alt Ventures New Zealand. No amount was disclosed.
Version 4.5.0 added a new expression language syntax for creating custom threat hunting modules, broadened coverage of built-in modules for Linux threats, and expanded CPU support to IBM POWER8, 9 and 10 processors.
DigitalOcean offers Sandfly Security as a 1-Click App in its marketplace; DigitalOcean's deputy CISO described the company as both a customer and a partner offering an integrated solution.
Dated company events from announcements, filings, and press; legal rows summarize public dockets and regulator releases.
▸Research sources · 8
primary sources listed
- Sandflysecuritysandflysecurity.com · web
8 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Sandflysecurity do?
- Sandfly Security provides agentless Linux intrusion detection and EDR for cloud, legacy, and embedded systems.
- Who founded Sandflysecurity?
- Sandflysecurity was founded by Craig Rowland in 2017.
- Who are Sandflysecurity's investors?
- Sandflysecurity's investors include Alt Ventures, Gula Tech Adventures.
- Where is Sandflysecurity headquartered?
- Sandflysecurity is headquartered in Tel Aviv-Yafo, IL.
