Skip to main content

Radegast Agent

Agent wrapper for the rustinel EDR binary. This project syncs detection packs from a backend, extracts rules into the local rules/ tree, and forwards encrypted alert lines from logs/ to the backend.

Features

  • Syncs detection packs via backend API
  • Extracts sigma, yara, and merged ioc rules
  • Tracks IOC ownership across packs so removed pack IOC files are cleaned up safely
  • Tails alerts.json logs and forwards encrypted alerts to the backend
  • Optional local rustinel process startup controlled by configuration

Requirements

  • Python 3.11+
  • hatchling build backend for packaging

Installation

You can also install this project as a UV tool directly from GitHub:

uv tool install git+https://github.com/radegast-edr/radegast-agent-python

radegast-edr-agent --version

Configuration

The agent uses environment variables prefixed with RADEGAST_AGENT_.

Variable Default Description
RADEGAST_AGENT_BACKEND_URL http://localhost:8000/api/v1 Backend API URL, including the default /api/v1 path
RADEGAST_AGENT_DEVICE_TOKEN `` Device token for authenticating to the backend
RADEGAST_AGENT_RUSTINEL_BINARY ./rustinel Local path to the rustinel binary
RADEGAST_AGENT_RULES_DIR ./rules Base directory for extracted rules
RADEGAST_AGENT_ALERTS_DIR ./logs Directory containing alert files
RADEGAST_AGENT_ALERTS_FILENAME alerts.json Alert file base name
RADEGAST_AGENT_SEND_SEVERITY true If true, parse the severity of the alert and send it unencrypted in the request
RADEGAST_AGENT_SEND_RULE_ID true If true, parse rule.id from the alert and sends it unencrypted in the request
RADEGAST_AGENT_SEND_EXCLUDED_BY true If true, send the exclusion ID for soft exclusions unencrypted in the request
RADEGAST_AGENT_MAX_LOG_SIZE_MB 10 Maximum size of the rustinel log file in MB before rotation
RADEGAST_AGENT_MAX_LOG_AGE_DAYS 720 Maximum age of rotated rustinel log archives in days before deletion
RADEGAST_AGENT_SYNC_INTERVAL 300 Seconds between pack sync checks
RADEGAST_AGENT_AUTOUPDATE_INITIAL_DELAY 300 (5 minutes) Seconds until first autoupdate check after startup
RADEGAST_AGENT_AUTOUPDATE_INTERVAL 86400 (24 hours) Seconds between subsequent autoupdate checks
RADEGAST_AGENT_INIT_WAIT_SECONDS 90 Seconds to wait for backend to re-encrypt exclusions on new key registration
RADEGAST_AGENT_SIGNING_KEY_PATH ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key Path to the device signing keypair
RADEGAST_AGENT_ENCRYPTION_KEY_PATH ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_enc_key Path to the device encryption keypair
RADEGAST_AGENT_STATE_DIR ./.radegast-agent Local state directory for manifests, offsets, and the default signing key location
RADEGAST_AGENT_RUSTINEL_CONFIG config.toml Path to the rustinel configuration file to sync active response settings to
RADEGAST_AGENT_HEALTHCHECK true Enable periodic healthcheck probe rule generation and verification
RADEGAST_AGENT_HEALTHCHECK_INTERVAL 60 Seconds between healthcheck runs
RADEGAST_AGENT_HEALTHCHECK_TIMEOUT 10.0 Seconds to wait for rustinel alert detection before marking unhealthy
RADEGAST_AGENT_HEALTHCHECK_RULE_DIR ${RADEGAST_AGENT_RULES_DIR:-./rules}/sigma/_healthcheck Directory where healthcheck probe Sigma rules are generated

Notes

  • The agent does not launch rustinel — it must be started separately. The agent only tails alerts from the configured alerts_dir.
  • If RADEGAST_AGENT_SIGNING_KEY_PATH is unset, it defaults to ${RADEGAST_AGENT_STATE_DIR:-./.radegast-agent}/device_key.
  • IOC files are merged into rules/ioc/ and an ownership registry is kept in rules/ioc/ioc_packs.json.

Usage

Run the agent via the console script:

radegast-edr-agent

Print the installed version:

radegast-edr-agent --version

Or with Python directly:

python -m radegast_edr_agent.cli

Project layout

  • radegast_edr_agent/ — application package
    • cli.py — main entry point
    • config.py — environment-backed config schema
    • client.py — backend API client
    • packs.py — pack synchronization and extraction
    • process.py — subprocess management for rustinel
    • tailer.py — alert file tailing and forwarding
    • version.py — version reporting and detection utilities
    • autoupdate.py — agent autoupdate functionality
  • tests/ — unit tests
  • pyproject.toml — package metadata and build config

Testing

Run the test suite with:

.venv/bin/python -m pytest

License

This project does not include a license file by default. Add a LICENSE file if you want to define reuse terms.

Metadata

Release files for radegast-edr-agent 0.9.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for radegast-edr-agent 0.9.0
File Size Uploaded
radegast_edr_agent-0.9.0.tar.gz 92.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for radegast-edr-agent 0.9.0
File Interpreter ABI Platform
radegast_edr_agent-0.9.0-py3-none-any.whl Python 3 none any Details

Total release size: 124.0 kB

Release files / radegast_edr_agent-0.9.0.tar.gz

Download URL radegast_edr_agent-0.9.0.tar.gz
Size 92.2 kB
Tags Source
SHA-256 checksum
How to use checksums
17a46a79aa26c1d7e76e7094660475f12e797036f0f2f0da6797e3490bce7743
BLAKE2b-256 checksum
How to use checksums
bc0e3352282531ef6550e08233ea3ff1cc1ef8b48da91e6b023d2d51aa4f2ef1
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release files / radegast_edr_agent-0.9.0-py3-none-any.whl

Download URL radegast_edr_agent-0.9.0-py3-none-any.whl
Size 31.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
fc8c3348540e6fdd8166028150020fbe262361562ce6dd6ac5b5c05da1228943
BLAKE2b-256 checksum
How to use checksums
28a86fe5212b9be495a9a08c5aaefa7efe0564b99bf0ef2c5e526ef49892c594
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 23, 2026.

Transparency log

Release history Release notifications | RSS feed

0.9.1

2 release files

This release

0.9.0 This release

2 release files

0.8.0

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.2

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page