ENDPOINT SECURITY AGENT

SecurityScanner Endpoint Agent

Real-time security monitoring for your servers and workstations. Detect threats, monitor changes, and harden your infrastructure automatically.

securityscanner-agent
$ curl -sSL https://agent.securityscanner.ai/install.sh | sudo bash
[*] Downloading SecurityScanner Agent v1.3.0...
[*] Installing to /usr/local/bin/securityscanner-agent...
[+] Agent installed successfully!
 
$ sudo securityscanner-agent register --email admin@company.com
[+] Agent registered: a3f8c2e1-4b7d-...
[*] Starting security monitoring...
[*] Modules: auth, hardening, network, disk, process, docker, usb, file-integrity
[+] All systems operational. Monitoring active.

Comprehensive Security Monitoring

The agent runs 14 security monitors on your system, checking for threats, misconfigurations, and changes at configurable intervals.

SSH Security

Parses /var/log/auth.log for failed SSH logins and brute force patterns. Checks sshd_config for PermitRootLogin, PasswordAuthentication, and empty password settings. Alerts on root SSH logins and authorized_keys file changes.

Process Monitoring

Detects known cryptominers (xmrig, minerd, kdevtmpfsi, kinsing) and reverse shell patterns (bash -i, nc -e, python -c). Flags binaries running from suspicious paths like /var/tmp. Reports zombie processes and high CPU usage.

Network Port Monitoring

Runs ss -tlnp to track listening ports and alerts when new ports are opened. Monitors ESTABLISHED connections and reports changes to the network state.

File Integrity Monitoring

Computes checksums for critical files: /etc/passwd, /etc/shadow, /etc/group, /etc/sudoers, /etc/hosts, /etc/crontab, and /etc/ld.so.preload. Alerts when file hashes change. Scans for world-writable files and SUID binaries.

System Hardening Checks

Checks firewall status (ufw, iptables, nftables), disk encryption (LUKS/dm-crypt), AppArmor/SELinux enforcement, and kernel security parameters (ASLR, ip_forward, source routing, ICMP redirects, dmesg_restrict, hardlink/symlink protection). Audits password policies in /etc/login.defs.

Docker Monitoring

Counts running and stopped containers. Inspects containers for privileged mode and reports exposed ports.

Disk Usage Monitoring

Reports usage percentage, free space, and total size for each mounted partition. Tracks changes over time so you can spot filling disks early.

Log Monitoring

Reads journalctl output for error spikes in the last minute. Detects kernel panics, oops, and bug messages. Alerts when error rates are unusually high.

USB Device Monitoring

Scans /sys/bus/usb/devices to inventory connected USB devices. Alerts on new device connections and disconnections.

Software Inventory & Packages

Lists all installed packages via dpkg or rpm with version and architecture. Checks for available security updates using apt. Alerts when the package cache is stale or when packages are installed/removed.

Crontab Change Detection

Monitors /etc/crontab and /var/spool/cron/crontabs for modifications. Alerts when scheduled tasks are added or changed.

Auth & Sudo Monitoring

Tracks sudo commands with user and command details, su session changes, and PAM authentication failures. Logs failed login attempts across services.

Systemd Service Monitoring

Lists active and failed systemd services via systemctl. Alerts when a service enters a failed state.

Get Started in 3 Steps

Deploy the agent in under 60 seconds. No complex configuration required.

1

Install

Run a single command to download and install the agent on your server. Supports all major Linux distributions.

2

Register

Link the agent to your SecurityScanner.ai account with one command. The agent securely authenticates with our API.

3

Monitor

View security events, alerts, and system health from your dashboard at securityscanner.ai/endpoint-security.

Linux Quick Install

curl -sSL https://agent.securityscanner.ai/install.sh | sudo bash

Requires root privileges. Supports Ubuntu 20.04+, Debian 11+, CentOS 8+, RHEL 8+, Amazon Linux 2+

Download Agent

Choose your platform and start monitoring in minutes.

Linux Agent

v1.3.0

Supported Distributions

  • Ubuntu 20.04, 22.04, 24.04
  • Debian 11, 12
  • CentOS 8, 9 / RHEL 8, 9
  • Amazon Linux 2, 2023
  • Fedora 38+

Requirements

  • 64-bit (x86_64 / amd64)
  • 512 MB RAM minimum
  • 50 MB disk space
  • Root / sudo access
Download Linux Agent

Windows Agent

Coming Soon

Supported Versions

  • Windows 10 (21H2+)
  • Windows 11
  • Windows Server 2016+
  • Windows Server 2019, 2022

Requirements

  • 64-bit (x86_64)
  • 512 MB RAM minimum
  • 100 MB disk space
  • Administrator privileges
Windows Agent (Coming Soon)

Included With Your Plan

Endpoint security monitoring is available across all plans.

Free: 1 Agent Pro: 10 Agents Enterprise: Unlimited
Get Started Free