> For the complete documentation index, see [llms.txt](https://docs.cloudcyte.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cloudcyte.com/getting-started/integrations/agentless-monitoring.md).

# Agentless Monitoring

The CyberCyte can collect and allow users to monitor the data without even installing the agent. For the agentless approach, please follow these steps below.

## 1. Deploying The Linux Agent

Please navigate to "Settings & Reporting" -> "Deployment Settings" and copy the "Linux Service Installer" command and execute it on one of the Linux device in the infrastructure. This is a mandatory and single deployment for agentless approach.

## 2. Assigning The Credentials

Please navigate to "Settings & Reporting" -> "Credential Settings" and click on the "+ Credential" button.

<figure><img src="/files/TeqeVtJ49d1s3Ts4gIty" alt=""><figcaption></figcaption></figure>

CyberCyte support Windows, SSH and also all kind of SNMP connections. But with SNMP connections, agent can only discover device and can't execute any analysis command in the machine; only the device name, OS kind and general details about machine, nothing specific about it.

<figure><img src="/files/t5PjqeoKeGE6KklCOw1J" alt=""><figcaption></figcaption></figure>

## 3. Policy Configuration

Please navigate to "Rules & Policies" -> "Policy Management" and edit/create "IP Scan & Penetration Testing" policy. This is a built-in policy and disabled by default.

<figure><img src="/files/Q6nAPFkzV4PwvoDUyBZV" alt=""><figcaption></figcaption></figure>

The some of the important values below needs to configured properly:

* Collection Interval: The general data collection interval.
* Scanner Host: This host will be the same as the agent installed Linux device.
* IP Blocks: This section contains important, the users will define IP block in their infrastructure.
* Port Scan Settings: This is selected by default and staticly configured, no extra configuration required.

<figure><img src="/files/8C9phMcbX5UROOABWidO" alt=""><figcaption></figcaption></figure>

* Credentials for Host Information Gathering: In this section users can select the defined credentials for enumaration. The portal will try to login to devices with each credential defined in the policy.&#x20;
* Agentless Collection Commands: This section provides collection commands that will run in the device after connection. This section can be configured based on the organization infrastructure.
* Agentless Windows Connection Priority: This section is pre-defined, no additional configuration required.

<figure><img src="/files/tnbowcNLdxaRCRBpZlcQ" alt=""><figcaption></figcaption></figure>

After the configuration please save the policy.

## 4. Monitoring The Devices & Results

Please navigate to "Endpoints & Network Devices" -> "Endpoint Devices" -> "Asset Management" or "Network Discovered Devices". The devices will be appeared on the portal as soon as conneciton established. The general device information can be observed in these pages.

<figure><img src="/files/NNYcHIlbd1SJSYKeMdax" alt=""><figcaption></figcaption></figure>

For the analysis results, please navigate to "Analysis & Investigation" -> "Artifact Analysis" -> "Agentless Discovery Artifacts". The collected data can be observed in that page with detailed information. The classifications can be customized based on the organization requirements.

<figure><img src="/files/PgxGz4ffTtjn9ncWS7YZ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/FY65wvSFMKSrHAes8ZGj" alt=""><figcaption></figcaption></figure>
