Skip to content

Deploying agents

BAS agents are lightweight endpoints you drop into a segment, site, or cloud you control. They poll the control plane outbound through NAT — no inbound ports, no firewall changes. Installing an agent on a host is the consent for running adversary-emulation on that host.

Consent boundary

Only install an agent on endpoints you own or are explicitly authorized to test. The agent runs ATT&CK techniques; on a host you don't control, that isn't testing.

Enroll from the console

Open Config → Agents → Enroll. Enrollment generates a scoped API key and the exact one-liner for the platform you pick. The console shows the real command for your tenant; the shapes below use https://<your-daedalus> as a placeholder for your control-plane hostname.

Linux / macOS (container-based)

A single command installs the container runtime if it's missing, pulls the agent image, and registers it to start on boot:

curl -fsSL https://<your-daedalus>/agent/install.sh | sudo bash -s -- \
  --server https://<your-daedalus> --key <ENROLLMENT_KEY>

macOS uses the same installer with a macOS-specific path selected automatically.

Windows (native)

Windows agents are native — no container runtime required. The one-liner downloads a signed executable and registers a boot task that runs as the system account:

irm https://<your-daedalus>/agent/install.ps1 | iex

The enrollment view fills in the server URL and key for you.

What the installer touches

The installer is deliberately conservative and records what it changed so uninstall can be exact:

  • If a container runtime was already present, it is used as-is and left untouched.
  • If the installer had to install the runtime, that fact is marked so uninstall can remove it again — but only if nothing else on the host has started using it.
  • The agent itself is a single service/task plus its working directory.

Uninstall — leave the host as you found it

Uninstall reverses exactly what enrollment added:

curl -fsSL https://<your-daedalus>/agent/uninstall.sh | sudo bash
irm https://<your-daedalus>/agent/uninstall.ps1 | iex

It removes the agent service/task and its files, and removes a container runtime only if the installer added it and no other containers or images remain that would be using it. If the host had the runtime before, or is now using it for something else, it is left in place.

Verify

After enrollment the agent appears under Config → Agents with its last-seen time and ATT&CK coverage. From there you can scope a project to a zone and, from the BAS view, queue techniques against it — dry-run by default.