Skip to content

[ti_threatconnect] Add Agentless Deployment Support #19594

Description

@moxarth-rathod

Description

Add agentless support to the ti_threatconnect.

Requirements

Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.

1. Technical implementation

  • Update integration manifest.yml to enable agentless deployment mode ()
  • Update integration documentation with agentless deployment instructions
  • Update changelog.md

Example reference: #13367

2. Performance documentation

  • Test and document throughput in agentless (requires access to vendor environment and/or sample data)
  • Document specific metrics for each integration. For example/where possible:
    • API response time: Average time for vendor API calls to complete
    • Events processed per minute: How many log entries/events the integration can handle
    • Error rates: Percentage of failed API calls or data processing errors
    • Container resource usage: CPU and memory consumption under typical load
    • Vendor-specific limits: Rate limiting thresholds and API quotas

Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"

Dependencies

  • Agentless infrastructure GA readiness (still in beta)
  • Input compatibility: Currently agentless is optimized for httpjson and cel inputs
  • UX enhancement: Add agentless deployment filter/toggle to integrations catalog page for better discoverability

Activity

  1. added
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Jun 17, 2026
  2. infra-vault-gh-plugin-prod commented on Jun 17, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  3. github-actions commented on Jun 17, 2026

    @github-actions
    Contributor

    tl;dr: This is ready to implement, but the PR should include a format_version bump before adding deployment_modes; ti_threatconnect is currently on manifest spec 3.0.3, where deployment_modes is stripped by the spec compatibility patches.

    Recommendation

    Proceed with agentless enablement for ti_threatconnect using the existing Phase I pattern from #13367, but use the newer pattern already present in Security Service Integrations CEL packages: set package format_version to 3.3.2, add deployment_modes.default + deployment_modes.agentless.release: beta, update generated/source docs, and add the changelog/version bump.

    There does not appear to be a CEL-input blocker: ti_threatconnect already collects via CEL, which matches the issue’s stated agentless-compatible input path.

    Findings
    • packages/ti_threatconnect/manifest.yml:2-5 currently uses format_version: 3.0.3 and package version 2.1.1.
    • packages/ti_threatconnect/manifest.yml:26-33 has one threatconnect policy template with a CEL input, but no deployment_modes block.
    • docs/extend/manifest-spec.md:657-664 removes deployment_modes.default before spec 3.2.0 and removes policy_templates[].deployment_modes entirely before spec 3.1.4; this is why the package should not keep format_version: 3.0.3 when adding agentless.
    • Existing Security Service Integrations CEL packages use the target pattern:
      • packages/cisa_kevs/manifest.yml:1,28-36 uses format_version: 3.3.2, default.enabled: true, agentless.enabled: true, agentless.release: beta, and team: security-service-integrations.
      • packages/ti_anomali/manifest.yml:6,43-51 uses the same agentless block on a threat-intel integration.
      • packages/ti_google_threat_intelligence/manifest.yml:47-55 uses the same agentless block on another CEL threat-intel integration.
    • packages/ti_threatconnect/data_stream/indicator/manifest.yml:5-9 confirms the data stream uses input: cel with cel.yml.hbs.
    • packages/ti_threatconnect/data_stream/indicator/agent/stream/cel.yml.hbs:1-147 uses standard CEL resource options (resource.url, proxy, SSL, timeout, request tracing, redaction) similar to agentless CEL packages such as packages/cisa_kevs/data_stream/vulnerability/agent/stream/cel.yml.hbs:1-19.
    • Docs need updating: packages/ti_threatconnect/docs/README.md:18-20 and packages/ti_threatconnect/_dev/build/docs/README.md:18-20 still say only “Elastic Agent must be installed.” Existing agentless docs such as packages/ti_anomali/docs/README.md:51-63 split deployment into Agentless-based and Agent-based installation.
    • Performance documentation should account for the latest-indicator transform: packages/ti_threatconnect/docs/README.md:40-43 tells users to query the latest destination index, and packages/ti_threatconnect/elasticsearch/transform/latest/transform.yml:23-27 runs with frequency: 30s and delay: 120s.
    Verification

    I verified the repository/spec evidence above directly from local files. I could not run package validation in this runner because elastic-package is not installed:

    $ elastic-package version && elastic-package check --help | sed -n '1,120p'
    bash: elastic-package: command not found
    Detailed Action Plan
    1. Update packages/ti_threatconnect/manifest.yml:
      • Change format_version at line 2 from 3.0.3 to 3.3.2.
      • Bump package version at line 5, likely from 2.1.1 to 2.2.0 for this enhancement.
      • Under policy_templates[0] after description at lines 27-29, add:
        deployment_modes:
          default:
            enabled: true
          agentless:
            enabled: true
            release: beta
            organization: security
            division: engineering
            team: security-service-integrations
    1. Update docs in packages/ti_threatconnect/_dev/build/docs/README.md and regenerate/verify packages/ti_threatconnect/docs/README.md:

      • Replace the current ## Requirements section at lines 18-20 with the agentless/agent-based structure used by packages/ti_anomali/docs/README.md:51-63.
      • Keep the existing setup steps for Access ID, Secret Key, and URL.
      • Add any measured agentless performance results once a ThreatConnect test/vendor environment is available.
    2. Update packages/ti_threatconnect/changelog.yml:

      • Add a top enhancement entry for the new package version, e.g. “Add agentless deployment support for ThreatConnect.”
    3. Validate locally in an environment with elastic-package available:

      • Build/check the package.
      • Run existing pipeline/system tests for packages/ti_threatconnect where credentials/sample setup allow.
      • For the performance requirement, capture API response time, events/minute, error rate, resource usage, ThreatConnect API/rate limits, and transform catch-up/lag because the user-facing latest index depends on the transform delay.
    Related Items
    Type Item Relevance
    PR #13367 Reference Phase I agentless enablement pattern cited by this issue.
    PR #14014 Prior docs cleanup touched ti_threatconnect installation text; useful context for keeping docs format consistent.
    File packages/ti_threatconnect/manifest.yml Main implementation location for format_version, package version, and deployment_modes.
    File packages/ti_threatconnect/data_stream/indicator/manifest.yml Confirms current collection input is CEL.
    File packages/ti_threatconnect/_dev/build/docs/README.md Source docs that should get the agentless/agent-based deployment wording.
    File packages/ti_threatconnect/changelog.yml Needs the versioned enhancement entry.
    File docs/extend/manifest-spec.md Shows why format_version must be bumped for deployment_modes.
    File packages/ti_anomali/manifest.yml Comparable threat-intel agentless manifest pattern.
    File packages/cisa_kevs/manifest.yml Comparable SSI CEL agentless manifest pattern.

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions