ThreatSabre Agent
Overview of the ThreatSabre Agent, a lightweight Linux broker that connects your Fortinet infrastructure to the ThreatSabre platform via outbound HTTPS.
About the ThreatSabre Agent
The ThreatSabre Agent (Agent for short) acts as a broker or proxy between the ThreatSabre platform and your infrastructure.
It is available as a standalone executable for Linux systems that use systemd or OpenRC as their init system. This includes Ubuntu, Alpine Linux, RHEL, Fedora, Debian, CentOS, and other common distributions.
How It Works
The Agent performs periodic outbound HTTPS calls to the ThreatSabre platform to receive configuration and instructions. When actions are required (such as polling FortiGate, FortiManager, or FortiManager Cloud devices), these instructions are provided in the HTTPS response. The Agent then executes the necessary API calls to your devices and sends the results back to the platform.
Requirements
Network Access:
- Outbound HTTPS to
https://api.threatsabre.comon TCP port 443 (Agent communication) - Outbound HTTPS to
https://files.threatsabre.comon TCP port 443 (installation and updates) - Outbound HTTPS to your FortiGate, FortiManager, or FortiManager Cloud devices on their HTTPS management ports
All communications are outbound HTTPS from the Agent; no inbound access needs to be configured.
System Requirements:
- Any Linux distribution using systemd or OpenRC (tested on Ubuntu 20.04+, Alpine 3.18+, RHEL 8+, Fedora 38+, Debian 11+, CentOS Stream 8+)
- CPU architecture: ARM64 (aarch64) and x86_64 (amd64) are supported
- Bare metal, virtual machines, or containers on any private or public cloud provider (e.g. VMware, Hyper-V, KVM, AWS, Azure, GCP)
- Root or sudo access for installation
- Minimal system resources (typically 512MB RAM, 5GB disk space, 1 vCPU)
wgetorcurl, andgunzip(present by default on supported platforms)- Alpine only:
bashandlibstdc++are required (apk add bash libstdc++)
Configuration
Other than setting the Agent Token during setup, all configuration is performed on the ThreatSabre platform. The Agent will automatically receive configuration updates during its periodic check-ins.
Deployment Architecture
One Agent can be set up to poll multiple FortiGates, FortiManagers, or FortiManager Cloud instances, and multiple Agents can be set up inside an organization to poll devices in different networks.
Obtaining Your Agent Token
Before installation, you'll need to generate an Agent Token from the ThreatSabre platform:
- Navigate to the Agents section in the ThreatSabre platform
- Create a new Agent
- Copy the generated Agent Token (you'll need this during installation)
Security Considerations
- The Agent Token provides authentication to the ThreatSabre platform—keep it secure
- The configuration file (/etc/threatsabre-agent/agent.conf) contains sensitive credentials and should be protected (600 permissions)
- The Agent only requires outbound network access—no inbound ports need to be opened
Onboarding wizard
Install a ThreatSabre Agent, connect an Agent Device, and onboard Fortinet devices into ThreatSabre.
Installation Guide
Install the ThreatSabre Agent on Linux using the automated install script, with options for interactive setup, CI/CD automation, version pinning, multi-instance deployments, and upgrade management.