Skip to main content

Radegast Agent

Agent wrapper for the rustinel EDR binary. This project syncs detection packs from a backend, extracts rules into the local rules/ tree, and forwards encrypted alert lines from logs/ to the backend.

Features

  • Syncs detection packs via backend API
  • Extracts sigma, yara, and merged ioc rules
  • Tracks IOC ownership across packs so removed pack IOC files are cleaned up safely
  • Tails alerts.json logs and forwards encrypted alerts to the backend
  • Optional local rustinel process startup controlled by configuration

Requirements

  • Python 3.11+
  • hatchling build backend for packaging

Installation

You can also install this project as a UV tool directly from GitHub:

uv tool install git+https://github.com/radegast-edr/radegast-agent-python

radegast-edr-agent --version

Configuration

The agent uses environment variables prefixed with RADEGAST_AGENT_.

Variable Default Description
RADEGAST_AGENT_BACKEND_URL http://localhost:8000/api/v1 Backend API URL, including the default /api/v1 path
RADEGAST_AGENT_DEVICE_TOKEN `` Device token for authenticating to the backend
RADEGAST_AGENT_RUSTINEL_BINARY ./rustinel Local path to the rustinel binary
RADEGAST_AGENT_RULES_DIR ./rules Base directory for extracted rules
RADEGAST_AGENT_ALERTS_DIR ./logs Directory containing alert files
RADEGAST_AGENT_ALERTS_FILENAME alerts.json Alert file base name
RADEGAST_AGENT_SEND_SEVERITY true If true, parse the severity of the alert and send it unencrypted in the request
RADEGAST_AGENT_SEND_RULE_ID true If true, parse rule.id from the alert and sends it unencrypted in the request
RADEGAST_AGENT_SEND_EXCLUDED_BY true If true, send the exclusion ID for soft exclusions unencrypted in the request
RADEGAST_AGENT_MAX_LOG_SIZE_MB 10 Maximum size of the rustinel log file in MB before rotation
RADEGAST_AGENT_MAX_LOG_AGE_DAYS 720 Maximum age of rotated rustinel log archives in days before deletion
RADEGAST_AGENT_SYNC_INTERVAL 300 Seconds between pack sync checks
RADEGAST_AGENT_AUTOUPDATE_INITIAL_DELAY 300 (5 minutes) Seconds until first autoupdate check after startup
RADEGAST_AGENT_AUTOUPDATE_INTERVAL 86400 (24 hours) Seconds between subsequent autoupdate checks
RADEGAST_AGENT_INIT_WAIT_SECONDS 90 Seconds to wait for backend to re-encrypt exclusions on new key registration
RADEGAST_AGENT_SIGNING_KEY_PATH ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key Path to the device signing keypair
RADEGAST_AGENT_ENCRYPTION_KEY_PATH ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_enc_key Path to the device encryption keypair
RADEGAST_AGENT_STATE_DIR ./.radegast-agent Local state directory for manifests, offsets, and the default signing key location
RADEGAST_AGENT_RUSTINEL_CONFIG config.toml Path to the rustinel configuration file to sync active response settings to

Notes

  • The agent does not launch rustinel — it must be started separately. The agent only tails alerts from the configured alerts_dir.
  • If RADEGAST_AGENT_SIGNING_KEY_PATH is unset, it defaults to ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key.
  • IOC files are merged into rules/ioc/ and an ownership registry is kept in rules/ioc/ioc_packs.json.

Usage

Run the agent via the console script:

radegast-edr-agent

Print the installed version:

radegast-edr-agent --version

Or with Python directly:

python -m radegast_edr_agent.cli

Project layout

  • radegast_edr_agent/ — application package
    • cli.py — main entry point
    • config.py — environment-backed config schema
    • client.py — backend API client
    • packs.py — pack synchronization and extraction
    • process.py — subprocess management for rustinel
    • tailer.py — alert file tailing and forwarding
    • version.py — version reporting and detection utilities
    • autoupdate.py — agent autoupdate functionality
  • tests/ — unit tests
  • pyproject.toml — package metadata and build config

Testing

Run the test suite with:

.venv/bin/python -m pytest

License

This project does not include a license file by default. Add a LICENSE file if you want to define reuse terms.

Metadata

Release files for radegast-edr-agent 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for radegast-edr-agent 0.6.0
File Size Uploaded
radegast_edr_agent-0.6.0.tar.gz 86.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for radegast-edr-agent 0.6.0
File Interpreter ABI Platform
radegast_edr_agent-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 114.2 kB

Release files / radegast_edr_agent-0.6.0.tar.gz

Download URL radegast_edr_agent-0.6.0.tar.gz
Size 86.6 kB
Tags Source
SHA-256 checksum
How to use checksums
314c0b9af404d343525a007ec74e963c54b444227701ac1b768782f04b017c7f
BLAKE2b-256 checksum
How to use checksums
747746182cd1008e68006ee0586249788887a438344eac9eea7dccc4b807c4af
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 8, 2026.

Transparency log

Release files / radegast_edr_agent-0.6.0-py3-none-any.whl

Download URL radegast_edr_agent-0.6.0-py3-none-any.whl
Size 27.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
c739559c4145177f00af78657b6470e119283844e8bb2c7bffc41b63f0186434
BLAKE2b-256 checksum
How to use checksums
f9064dfd1f549e1b8d719b1fc7f20f9774db44c5aad465fa9750dc913feddb21
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 8, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

This release

0.6.0 This release

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page