Repository navigation
[ti_threatconnect] Add Agentless Deployment Support #19594
Description
Activity
- addedenhancementNew feature or requestNew feature or requestTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]
on Jun 17, 2026 - added a parent issue
on Jun 17, 2026 - addedTeam:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
on Jun 17, 2026 infra-vault-gh-plugin-prod commented
on Jun 17, 2026 More actionsPinging @elastic/security-service-integrations (Team:Security-Service Integrations)
github-actions commented
on Jun 17, 2026 on Jun 17, 2026 – with GitHub ActionsContributorMore actionstl;dr: This is ready to implement, but the PR should include a
format_versionbump before addingdeployment_modes;ti_threatconnectis currently on manifest spec3.0.3, wheredeployment_modesis stripped by the spec compatibility patches.Recommendation
Proceed with agentless enablement for
ti_threatconnectusing the existing Phase I pattern from #13367, but use the newer pattern already present in Security Service Integrations CEL packages: set packageformat_versionto3.3.2, adddeployment_modes.default+deployment_modes.agentless.release: beta, update generated/source docs, and add the changelog/version bump.There does not appear to be a CEL-input blocker:
ti_threatconnectalready collects via CEL, which matches the issue’s stated agentless-compatible input path.Findings
packages/ti_threatconnect/manifest.yml:2-5currently usesformat_version: 3.0.3and package version2.1.1.packages/ti_threatconnect/manifest.yml:26-33has onethreatconnectpolicy template with a CEL input, but nodeployment_modesblock.docs/extend/manifest-spec.md:657-664removesdeployment_modes.defaultbefore spec3.2.0and removespolicy_templates[].deployment_modesentirely before spec3.1.4; this is why the package should not keepformat_version: 3.0.3when adding agentless.- Existing Security Service Integrations CEL packages use the target pattern:
packages/cisa_kevs/manifest.yml:1,28-36usesformat_version: 3.3.2,default.enabled: true,agentless.enabled: true,agentless.release: beta, andteam: security-service-integrations.packages/ti_anomali/manifest.yml:6,43-51uses the same agentless block on a threat-intel integration.packages/ti_google_threat_intelligence/manifest.yml:47-55uses the same agentless block on another CEL threat-intel integration.
packages/ti_threatconnect/data_stream/indicator/manifest.yml:5-9confirms the data stream usesinput: celwithcel.yml.hbs.packages/ti_threatconnect/data_stream/indicator/agent/stream/cel.yml.hbs:1-147uses standard CEL resource options (resource.url, proxy, SSL, timeout, request tracing, redaction) similar to agentless CEL packages such aspackages/cisa_kevs/data_stream/vulnerability/agent/stream/cel.yml.hbs:1-19.- Docs need updating:
packages/ti_threatconnect/docs/README.md:18-20andpackages/ti_threatconnect/_dev/build/docs/README.md:18-20still say only “Elastic Agent must be installed.” Existing agentless docs such aspackages/ti_anomali/docs/README.md:51-63split deployment into Agentless-based and Agent-based installation. - Performance documentation should account for the latest-indicator transform:
packages/ti_threatconnect/docs/README.md:40-43tells users to query the latest destination index, andpackages/ti_threatconnect/elasticsearch/transform/latest/transform.yml:23-27runs withfrequency: 30sanddelay: 120s.
Verification
I verified the repository/spec evidence above directly from local files. I could not run package validation in this runner because
elastic-packageis not installed:$ elastic-package version && elastic-package check --help | sed -n '1,120p' bash: elastic-package: command not found
Detailed Action Plan
- Update
packages/ti_threatconnect/manifest.yml:- Change
format_versionat line 2 from3.0.3to3.3.2. - Bump package
versionat line 5, likely from2.1.1to2.2.0for this enhancement. - Under
policy_templates[0]afterdescriptionat lines 27-29, add:
- Change
deployment_modes: default: enabled: true agentless: enabled: true release: beta organization: security division: engineering team: security-service-integrations
-
Update docs in
packages/ti_threatconnect/_dev/build/docs/README.mdand regenerate/verifypackages/ti_threatconnect/docs/README.md:- Replace the current
## Requirementssection at lines 18-20 with the agentless/agent-based structure used bypackages/ti_anomali/docs/README.md:51-63. - Keep the existing setup steps for Access ID, Secret Key, and URL.
- Add any measured agentless performance results once a ThreatConnect test/vendor environment is available.
- Replace the current
-
Update
packages/ti_threatconnect/changelog.yml:- Add a top enhancement entry for the new package version, e.g. “Add agentless deployment support for ThreatConnect.”
-
Validate locally in an environment with
elastic-packageavailable:- Build/check the package.
- Run existing pipeline/system tests for
packages/ti_threatconnectwhere credentials/sample setup allow. - For the performance requirement, capture API response time, events/minute, error rate, resource usage, ThreatConnect API/rate limits, and transform catch-up/lag because the user-facing latest index depends on the transform delay.
Related Items
Type Item Relevance PR #13367 Reference Phase I agentless enablement pattern cited by this issue. PR #14014 Prior docs cleanup touched ti_threatconnectinstallation text; useful context for keeping docs format consistent.File packages/ti_threatconnect/manifest.ymlMain implementation location for format_version, package version, anddeployment_modes.File packages/ti_threatconnect/data_stream/indicator/manifest.ymlConfirms current collection input is CEL. File packages/ti_threatconnect/_dev/build/docs/README.mdSource docs that should get the agentless/agent-based deployment wording. File packages/ti_threatconnect/changelog.ymlNeeds the versioned enhancement entry. File docs/extend/manifest-spec.mdShows why format_versionmust be bumped fordeployment_modes.File packages/ti_anomali/manifest.ymlComparable threat-intel agentless manifest pattern. File packages/cisa_kevs/manifest.ymlComparable SSI CEL agentless manifest pattern.
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
Description
Add agentless support to the ti_threatconnect.
Requirements
Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.
1. Technical implementation
Example reference: #13367
2. Performance documentation
Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"
Dependencies