Deploy your first agent
Install and activate the Threatmatic agent on your first endpoint
Deploy your first agent
The Threatmatic agent is a lightweight process that connects your endpoint to the control plane. It enforces policy in real time and requires no reboot or kernel extension on supported platforms.
Prerequisites
- An active Threatmatic organization
- Admin access to the Console
- A supported endpoint (macOS 12+, Windows 10/11, or Linux kernel 5.4+)
Steps
Download the agent
- Sign in to the Threatmatic Console
- Navigate to Settings → Download Agent
- Select your operating system and download the installer
Create an API key
The agent uses an API key to authenticate with your organization's control plane.
- Navigate to Organization → API Keys
- Click Create API Key
- Give it a name (e.g.
agent-enrollment) and copy the key — you will need it during installation
Install the agent
Open the downloaded .pkg file and follow the installation wizard. You will
be prompted to allow a system extension — approve it in System Settings →
Privacy & Security.
Run the downloaded .msi as Administrator. The agent service starts
automatically after installation.
sudo dpkg -i threatmatic-agent.deb # Debian/Ubuntu sudo rpm -i
threatmatic-agent.rpm # RHEL/Fedora sudo systemctl enable --now
threatmatic-agentActivate with your API key
During installation you will be prompted for your API key. Enter the key you created in step 2.
The agent will connect to the control plane within seconds of activation.
Verify enrollment
Return to Devices in the Console. Your endpoint should appear with status Active within 30 seconds.
Optional: Install the Threatmatic π CA certificate
If your organization has subscribed to Threatmatic π (HTTPS payload inspection), you need to trust the Threatmatic CA certificate on each enrolled endpoint. This allows the inspection node to decrypt and re-encrypt HTTPS traffic transparently.
- Download the CA certificate from Settings → Threatmatic π → Download CA Certificate
- Install it on the endpoint:
sudo security add-trusted-cert -d -r trustRoot \
-k /Library/Keychains/System.keychain \
threatmatic-ca-cert.pemDouble-click threatmatic-ca-cert.crt, select Install Certificate, choose Local Machine,
and place it in the Trusted Root Certification Authorities store.
sudo cp threatmatic-ca-cert.pem /usr/local/share/ca-certificates/threatmatic.crt
sudo update-ca-certificatesOnce installed, HTTPS traffic from this device will be inspected by Threatmatic π automatically.
How is this guide?
Last updated on