Agentless Monitoring
The CyberCyte can collect and allow users to monitor the data without even installing the agent. For the agentless approach, please follow these steps below.
1. Deploying The Linux Agent
Please navigate to "Settings & Reporting" -> "Deployment Settings" and copy the "Linux Service Installer" command and execute it on one of the Linux device in the infrastructure. This is a mandatory and single deployment for agentless approach.
2. Assigning The Credentials
Please navigate to "Settings & Reporting" -> "Credential Settings" and click on the "+ Credential" button.

CyberCyte support Windows, SSH and also all kind of SNMP connections. But with SNMP connections, agent can only discover device and can't execute any analysis command in the machine; only the device name, OS kind and general details about machine, nothing specific about it.

3. Policy Configuration
Please navigate to "Rules & Policies" -> "Policy Management" and edit/create "IP Scan & Penetration Testing" policy. This is a built-in policy and disabled by default.

The some of the important values below needs to configured properly:
Collection Interval: The general data collection interval.
Scanner Host: This host will be the same as the agent installed Linux device.
IP Blocks: This section contains important, the users will define IP block in their infrastructure.
Port Scan Settings: This is selected by default and staticly configured, no extra configuration required.

Credentials for Host Information Gathering: In this section users can select the defined credentials for enumaration. The portal will try to login to devices with each credential defined in the policy.
Agentless Collection Commands: This section provides collection commands that will run in the device after connection. This section can be configured based on the organization infrastructure.
Agentless Windows Connection Priority: This section is pre-defined, no additional configuration required.

After the configuration please save the policy.
4. Monitoring The Devices & Results
Please navigate to "Endpoints & Network Devices" -> "Endpoint Devices" -> "Asset Management" or "Network Discovered Devices". The devices will be appeared on the portal as soon as conneciton established. The general device information can be observed in these pages.

For the analysis results, please navigate to "Analysis & Investigation" -> "Artifact Analysis" -> "Agentless Discovery Artifacts". The collected data can be observed in that page with detailed information. The classifications can be customized based on the organization requirements.


Last updated
Was this helpful?