ThreatSabre Docs
OnboardingThreatsabre agent

ThreatSabre Agent

Overview of the ThreatSabre Agent, a lightweight Linux broker that connects your Fortinet infrastructure to the ThreatSabre platform via outbound HTTPS.

About the ThreatSabre Agent

The ThreatSabre Agent (Agent for short) acts as a broker or proxy between the ThreatSabre platform and your infrastructure.

It is available as a standalone executable for Linux systems that use systemd or OpenRC as their init system. This includes Ubuntu, Alpine Linux, RHEL, Fedora, Debian, CentOS, and other common distributions.

How It Works

The Agent performs periodic outbound HTTPS calls to the ThreatSabre platform to receive configuration and instructions. When actions are required (such as polling FortiGate, FortiManager, or FortiManager Cloud devices), these instructions are provided in the HTTPS response. The Agent then executes the necessary API calls to your devices and sends the results back to the platform.

Requirements

Network Access:

  • Outbound HTTPS to https://api.threatsabre.com on TCP port 443 (Agent communication)
  • Outbound HTTPS to https://files.threatsabre.com on TCP port 443 (installation and updates)
  • Outbound HTTPS to your FortiGate, FortiManager, or FortiManager Cloud devices on their HTTPS management ports

All communications are outbound HTTPS from the Agent; no inbound access needs to be configured.

System Requirements:

  • Any Linux distribution using systemd or OpenRC (tested on Ubuntu 20.04+, Alpine 3.18+, RHEL 8+, Fedora 38+, Debian 11+, CentOS Stream 8+)
  • CPU architecture: ARM64 (aarch64) and x86_64 (amd64) are supported
  • Bare metal, virtual machines, or containers on any private or public cloud provider (e.g. VMware, Hyper-V, KVM, AWS, Azure, GCP)
  • Root or sudo access for installation
  • Minimal system resources (typically 512MB RAM, 5GB disk space, 1 vCPU)
  • wget or curl, and gunzip (present by default on supported platforms)
  • Alpine only: bash and libstdc++ are required (apk add bash libstdc++)

Configuration

Other than setting the Agent Token during setup, all configuration is performed on the ThreatSabre platform. The Agent will automatically receive configuration updates during its periodic check-ins.

Deployment Architecture

One Agent can be set up to poll multiple FortiGates, FortiManagers, or FortiManager Cloud instances, and multiple Agents can be set up inside an organization to poll devices in different networks.

Obtaining Your Agent Token

Before installation, you'll need to generate an Agent Token from the ThreatSabre platform:

  1. Navigate to the Agents section in the ThreatSabre platform
  2. Create a new Agent
  3. Copy the generated Agent Token (you'll need this during installation)

Security Considerations

  • The Agent Token provides authentication to the ThreatSabre platform—keep it secure
  • The configuration file (/etc/threatsabre-agent/agent.conf) contains sensitive credentials and should be protected (600 permissions)
  • The Agent only requires outbound network access—no inbound ports need to be opened

On this page