Sandfly Blog
At Sandfly, we work with many customers in the critical infrastructure space and frequently deal with unusual Operational Technology (OT) applications and hardware. OT infrastructure security is an interesting area because it almost always involves Linux, and it often involves systems that cannot go down for any reason. This is exactly the type of environment where agentless security like Sandfly excels.
In particular, OT security presents several significant challenges where traditional agent-based Linux EDR solutions have a tough time operating:
Two of the most formidable threats currently active are Chinese state-sponsored groups dubbed Volt Typhoon and Salt Typhoon. They specialize in targeting and compromising OT infrastructure.
According to recent joint advisories from CISA, the NSA, and the FBI (advisory AA25-239), these advanced persistent threat actors exhibit tactics that extend beyond traditional espionage. While Salt Typhoon focuses heavily on massive-scale data theft by exploiting telecommunications infrastructure, Volt Typhoon actively pre-positions itself within power grids, water treatment facilities, and communication networks. The CISA threat assessment indicates that this positioning is designed to enable disruptive or destructive cyberattacks during potential future geopolitical conflicts.
Both groups evade detection by targeting edge networks and exploiting the soft underbelly of OT environments: Linux-based embedded devices, legacy servers, and routing equipment. For security teams, protecting these environments creates a paradox. You need deep visibility to catch stealthy intruders, but traditional endpoint security tools are often too dangerous to install on fragile, mission-critical OT systems.
At Sandfly, we have a tremendous amount of experience working in mission-critical and OT environments that run Linux. Here are three examples where we are trusted in extremely critical OT environments:
So when we talk about protecting OT systems, we are not just spewing marketing. Rather, we have practical, real-world experience watching some of the most important networking gear on the planet.
The primary challenge with protecting OT systems is that they rely heavily on Linux, and "Linux" is simply an umbrella term. Because the operating system is incredibly adaptable, a Linux deployment can be anything from a massive GPU cluster training an artificial intelligence model to a highly constrained embedded device in an IP camera or robot.
This extreme variety is where agent-based Endpoint Detection and Response (EDR) solutions reveal massive coverage gaps. While a traditional EDR vendor might claim they "support Linux," OT security teams must immediately ask the following critical questions:
Sandfly can handle all of these scenarios, from cloud-based deployments down to a tiny Linux controller buried in a broom closet. Because agent-based systems cannot deploy across this wide range of hardware, many security teams are left with massive visibility gaps where attackers like Salt Typhoon and Volt Typhoon can infiltrate and remain undetected for extended periods. Sandfly aims to stop that because we are designed to watch everything reliably and leave no blind spots.
Volt Typhoon and Salt Typhoon do not operate like typical hackers. When infiltrating a facility, they rarely drop noisy, recognizable malware files that trigger alarms. Instead, they utilize Living off the Land (LOTL). LOTL is a cyberattack technique where adversaries use legitimate, pre-installed administrative tools (like SSH, netcat, bash scripts, and more) to execute attacks, allowing them to evade traditional signature based malware detection. This is because these tools are not malware, but just being used maliciously.
Once these attackers compromise public facing edge devices with outdated firmware or weak credentials, they proxy their traffic to look like normal network activity. By hijacking legitimate system utilities, they blend in seamlessly with the daily activities of system administrators. Further, because they avoid introducing third party malware, traditional detection solutions may remain completely blind to their presence.
Finding these stealthy intruders requires analyzing system state and behavior, which typically demands EDR capabilities. However, bringing traditional EDR agents into an operational technology space introduces a severe set of risks that an agentless approach like Sandfly completely avoids.
Operational Technology runs the physical world. A crashed workstation in a corporate IT environment means a single annoyed employee. A crashed server in an OT environment can mean a regional power blackout or telephones stop working.
Traditional agent based EDR platforms are fundamentally ill-suited for high availability Linux environments for three major reasons:
Because of these massive hurdles, many OT administrators choose to run their Linux fleets completely unmonitored. This leaves the door wide open for groups like Salt and Volt Typhoon to enter and linger in the most critical of critical infrastructure.
Sandfly Security solves the visibility paradox by completely rethinking how Linux security works. Instead of forcing a persistent software agent onto the endpoint, Sandfly utilizes Agentless Security. Agentless Security is a cybersecurity approach that monitors and protects systems without requiring the installation of any persistent software or background services on the target device. Basically, if endpoint agents cause all of these compatibility and performance headaches on Linux, what if we just got rid of it?
Here are some of the benefits of not using an endpoint agent in OT environments:
Sandfly connects to endpoints using standard SSH and runs its investigative modules entirely in user space. It never loads kernel modules, it does not hook system calls, and it does not rely on eBPF technologies. Not tying into kernel space drastically lowers crash risks on production systems. If a Sandfly scan fails for any reason, it simply logs an error and stops, leaving zero impact on the host system.
Because it relies on standard SSH and pre-compiled static binaries, Sandfly works on virtually any Linux system. It effortlessly monitors modern cloud instances alongside decade old legacy servers, Internet of Things devices, and embedded hardware. It fully supports many CPU architectures like ARM, MIPS, and PowerPC, which are heavily prevalent in OT networking gear.
When Sandfly is not actively scanning a host, its resource consumption is exactly zero. When an automated scan triggers, it runs as a brief, low priority burst that typically consumes less than 2% of aggregate CPU for roughly 60 to 120 seconds at low priority before disappearing completely. This lightweight approach ensures that mission critical processes are never starved of compute resources. We've had this claim tested multiple times by mission critical users and are happy to show you how we can do this.
How do you use an agentless tool to catch an elite adversary that hides in plain sight? Sandfly is specifically designed to hunt the exact Living off the Land tactics that actors like Salt and Volt Typhoon rely upon.
The convergence of IT and OT networks has given nation-state actors an unprecedented avenue into the systems that sustain our daily lives. Defending against pre-positioning campaigns like Volt Typhoon or the massive intelligence sweeps of Salt Typhoon requires total visibility into your Linux and embedded infrastructure.
By abandoning the risky, resource heavy model of traditional endpoint agents, Sandfly Security provides a frictionless, universally compatible solution tailored for the strictest operational environments. It proves that you no longer have to choose between keeping your critical infrastructure stable and keeping it secure.
Do not wait for a nation-state actor to test the resilience of your critical infrastructure. See how Sandfly's agentless technology can give you complete, continuous visibility into your Linux and embedded systems without risking downtime. Request a demo today to see how you can start hunting threats like Volt Typhoon before they strike.
Get a Demo