Radegast Agent
Agent wrapper for the rustinel EDR binary. This project syncs detection packs from a backend, extracts rules into the local rules/ tree, and forwards encrypted alert lines from logs/ to the backend.
Features
- Syncs detection packs via backend API
- Extracts
sigma,yara, and mergediocrules - Tracks IOC ownership across packs so removed pack IOC files are cleaned up safely
- Tails
alerts.jsonlogs and forwards encrypted alerts to the backend - Optional local
rustinelprocess startup controlled by configuration
Requirements
- Python 3.11+
hatchlingbuild backend for packaging
Installation
You can also install this project as a UV tool directly from GitHub:
uv tool install git+https://github.com/radegast-edr/radegast-agent-python
radegast-edr-agent --version
Configuration
The agent uses environment variables prefixed with RADEGAST_AGENT_.
| Variable | Default | Description |
|---|---|---|
RADEGAST_AGENT_BACKEND_URL |
http://localhost:8000/api/v1 |
Backend API URL, including the default /api/v1 path |
RADEGAST_AGENT_DEVICE_TOKEN |
`` | Device token for authenticating to the backend |
RADEGAST_AGENT_RUSTINEL_BINARY |
./rustinel |
Local path to the rustinel binary |
RADEGAST_AGENT_RULES_DIR |
./rules |
Base directory for extracted rules |
RADEGAST_AGENT_ALERTS_DIR |
./logs |
Directory containing alert files |
RADEGAST_AGENT_ALERTS_FILENAME |
alerts.json |
Alert file base name |
RADEGAST_AGENT_SEND_SEVERITY |
true |
If true, parse the severity of the alert and send it unencrypted in the request |
RADEGAST_AGENT_SEND_RULE_ID |
true |
If true, parse rule.id from the alert and sends it unencrypted in the request |
RADEGAST_AGENT_SEND_EXCLUDED_BY |
true |
If true, send the exclusion ID for soft exclusions unencrypted in the request |
RADEGAST_AGENT_MAX_LOG_SIZE_MB |
10 |
Maximum size of the rustinel log file in MB before rotation |
RADEGAST_AGENT_MAX_LOG_AGE_DAYS |
720 |
Maximum age of rotated rustinel log archives in days before deletion |
RADEGAST_AGENT_SYNC_INTERVAL |
300 |
Seconds between pack sync checks |
RADEGAST_AGENT_AUTOUPDATE_INITIAL_DELAY |
300 (5 minutes) |
Seconds until first autoupdate check after startup |
RADEGAST_AGENT_AUTOUPDATE_INTERVAL |
86400 (24 hours) |
Seconds between subsequent autoupdate checks |
RADEGAST_AGENT_INIT_WAIT_SECONDS |
90 |
Seconds to wait for backend to re-encrypt exclusions on new key registration |
RADEGAST_AGENT_SIGNING_KEY_PATH |
${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key |
Path to the device signing keypair |
RADEGAST_AGENT_ENCRYPTION_KEY_PATH |
${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_enc_key |
Path to the device encryption keypair |
RADEGAST_AGENT_STATE_DIR |
./.radegast-agent |
Local state directory for manifests, offsets, and the default signing key location |
RADEGAST_AGENT_RUSTINEL_CONFIG |
config.toml |
Path to the rustinel configuration file to sync active response settings to |
RADEGAST_AGENT_HEALTHCHECK |
true |
Enable periodic healthcheck probe rule generation and verification |
RADEGAST_AGENT_HEALTHCHECK_INTERVAL |
60 |
Seconds between healthcheck runs |
RADEGAST_AGENT_HEALTHCHECK_TIMEOUT |
10.0 |
Seconds to wait for rustinel alert detection before marking unhealthy |
RADEGAST_AGENT_HEALTHCHECK_RULE_DIR |
${RADEGAST_AGENT_RULES_DIR:-./rules}/sigma/_healthcheck |
Directory where healthcheck probe Sigma rules are generated |
Notes
- The agent does not launch
rustinel— it must be started separately. The agent only tails alerts from the configuredalerts_dir. - If
RADEGAST_AGENT_SIGNING_KEY_PATHis unset, it defaults to${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key. - IOC files are merged into
rules/ioc/and an ownership registry is kept inrules/ioc/ioc_packs.json.
Usage
Run the agent via the console script:
radegast-edr-agent
Print the installed version:
radegast-edr-agent --version
Or with Python directly:
python -m radegast_edr_agent.cli
Project layout
radegast_edr_agent/— application packagecli.py— main entry pointconfig.py— environment-backed config schemaclient.py— backend API clientpacks.py— pack synchronization and extractionprocess.py— subprocess management forrustineltailer.py— alert file tailing and forwardingversion.py— version reporting and detection utilitiesautoupdate.py— agent autoupdate functionality
tests/— unit testspyproject.toml— package metadata and build config
Testing
Run the test suite with:
.venv/bin/python -m pytest
License
This project does not include a license file by default. Add a LICENSE file if you want to define reuse terms.
Metadata
Release files for radegast-edr-agent 0.7.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| radegast_edr_agent-0.7.1.tar.gz | 90.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| radegast_edr_agent-0.7.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 121.5 kB
Release files / radegast_edr_agent-0.7.1.tar.gz
| Download URL | radegast_edr_agent-0.7.1.tar.gz |
|---|---|
| Size | 90.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
29f7939f919ec9265445c09735e5437dab6e7afd182f535d6a1bdd6f8e3dc55d
|
|
BLAKE2b-256 checksum How to use checksums |
88d39e85a3557972c5c8df7bad3d8d1479104b71767377631a92efa75b6288df
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.
Transparency logRelease files / radegast_edr_agent-0.7.1-py3-none-any.whl
| Download URL | radegast_edr_agent-0.7.1-py3-none-any.whl |
|---|---|
| Size | 30.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
29d9113e83d6f384ed6f8d88cb4867316c0cc15f21e2e2e1a5dd6433011423e7
|
|
BLAKE2b-256 checksum How to use checksums |
84c5f714bab004ab56d76f4cd66fcbe6e451206e2cd5f6820eeafd415c1d70ea
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.
Transparency log