Sandfly Blog
Sandfly 5.4 is introducing an industry-first new feature: Agentless EDR support for Cisco and Juniper networking gear. This new feature gives customers full Linux EDR coverage of these critical devices combined with Sandfly's proven speed, stability, and safety. Sandfly continues to have the widest Linux-based server, embedded, network appliance and device support in the industry.
In addition to protecting edge devices like Juniper and Cisco, Sandfly 5.4 has these new features as well:
Sandfly's full functionality has been extended to routers and switches from Juniper and Cisco running Linux-based operating systems. This includes:
Sandfly's full feature set is available to any of these devices we can access. This means customers running Cisco and Juniper network gear get the following:
The recently disclosed attacks by Chinese nation state threat actors against telcos, dubbed Salt Typhoon, targeted critical networking gear from Cisco and Juniper. Once on these devices, the attackers can maintain persistence for extended periods and access extremely sensitive information about customers and network operations. The main reason they were able to persist for so long was because there was no effective way to monitor these devices before now.
Details of their attack patterns are available in several sources, but the main thrust of their attacks consisted of:
Sandfly's agentless security platform has EDR combined with drift detection. Both of these functions would make the actions of Salt Typhoon and others considerably more difficult.
For instance, our drift detection feature can be easily configured to lock down known-good profiles of devices and alert on any new process started, files changed, new users added and more. Our EDR can find threats running on systems, or as part of an incident response to check existing systems for signs of compromise. Finally, our ability to track SSH keys means new access added to devices can be seen immediately limiting lateral movement risks.
Juniper and Cisco both have special requirements to enable Sandfly SSH access. Juniper Evolved OS requires a signed binary to run which is accomplished with the instructions below. Cisco equipment also requires configuration to allow SSH access along with other special considerations. Please see the documentation for more details:
Cisco IOS-XR Application Notes
Juniper Evolved OS Application Notes
We have added in webhook support to send alerts to applications like Slack and others. The new notifications allow you to customize alert templates for other platforms as well. Webhook activation can be done by following the below instructions:
Sandfly can now access a list of hashes for known Linux malware from places such as Malware Bazaar, and other threat feeds. The hash lists will alert on any of the following:
The threat feed feature can also pull from a custom list of hashes maintained by security teams at a URL provided by the customer.
Threat feeds can be added by following our documentation below:
We expanded coverage to make a broader net for tactics used by Salt Typhoon plus other new threats. The new detections find more backdoor activity, suspicious processes, unusual network processes and related exploits. This expands our already extensive industry-leading Linux coverage. The new detections feature some of the following:
We have added more support for Microsoft Sentinel, including sending Host and SSH key data we collect to the platform. This data can be used for additional threat hunting and correlation by security teams inside Sentinel. The host data can be used to build out host asset inventory data for security teams inside the Sentinel platform as well to help with device discovery.
Cisco and Juniper device support is a critical new feature for many companies and we urge customers to check their edge devices for compromise as they are frequently targeted by nation-state attackers. Sandfly allows you to protect these devices simply and safely without endpoint agents. As always, Sandfly has free trials available for all license tiers. Please see below for more information:
All customers are encouraged to upgrade to see our expanded coverage and protection options for Linux. We are here to help with any questions. Please see our documentation on the new features and capabilities:
Customers wishing to upgrade can follow the instructions here:
If you have any questions, please reach out to us.
Thank you for using Sandfly.