LogoThreatmatic
Getting Started

Deploy your first agent

Install and activate the Threatmatic agent on your first endpoint

Deploy your first agent

The Threatmatic agent is a lightweight process that connects your endpoint to the control plane. It enforces policy in real time and requires no reboot or kernel extension on supported platforms.

Prerequisites

  • An active Threatmatic organization
  • Admin access to the Console
  • A supported endpoint (macOS 12+, Windows 10/11, or Linux kernel 5.4+)

Steps

Download the agent

  1. Sign in to the Threatmatic Console
  2. Navigate to Settings → Download Agent
  3. Select your operating system and download the installer

Create an API key

The agent uses an API key to authenticate with your organization's control plane.

  1. Navigate to Organization → API Keys
  2. Click Create API Key
  3. Give it a name (e.g. agent-enrollment) and copy the key — you will need it during installation
The API key is only shown once. Save it before closing the dialog.

Install the agent

Open the downloaded .pkg file and follow the installation wizard. You will be prompted to allow a system extension — approve it in System Settings → Privacy & Security.

Run the downloaded .msi as Administrator. The agent service starts automatically after installation.

sudo dpkg -i threatmatic-agent.deb # Debian/Ubuntu sudo rpm -i
threatmatic-agent.rpm # RHEL/Fedora sudo systemctl enable --now
threatmatic-agent

Activate with your API key

During installation you will be prompted for your API key. Enter the key you created in step 2.

The agent will connect to the control plane within seconds of activation.

Verify enrollment

Return to Devices in the Console. Your endpoint should appear with status Active within 30 seconds.


Optional: Install the Threatmatic π CA certificate

If your organization has subscribed to Threatmatic π (HTTPS payload inspection), you need to trust the Threatmatic CA certificate on each enrolled endpoint. This allows the inspection node to decrypt and re-encrypt HTTPS traffic transparently.

Skip this step if your organization has not enabled Threatmatic π.
  1. Download the CA certificate from Settings → Threatmatic π → Download CA Certificate
  2. Install it on the endpoint:
sudo security add-trusted-cert -d -r trustRoot \
  -k /Library/Keychains/System.keychain \
  threatmatic-ca-cert.pem

Double-click threatmatic-ca-cert.crt, select Install Certificate, choose Local Machine, and place it in the Trusted Root Certification Authorities store.

sudo cp threatmatic-ca-cert.pem /usr/local/share/ca-certificates/threatmatic.crt
sudo update-ca-certificates

Once installed, HTTPS traffic from this device will be inspected by Threatmatic π automatically.

How is this guide?

Last updated on

On this page