Skip to content

[zerofox] Add Agentless Deployment Support #19700

Description

@moxarth-rathod

Description

Add agentless support to the zerofox.

Requirements

Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.

1. Technical implementation

  • Update integration manifest.yml to enable agentless deployment mode ()
  • Update integration documentation with agentless deployment instructions
  • Update changelog.md

Example reference: #13367

2. Performance documentation

  • Test and document throughput in agentless (requires access to vendor environment and/or sample data)
  • Document specific metrics for each integration. For example/where possible:
    • API response time: Average time for vendor API calls to complete
    • Events processed per minute: How many log entries/events the integration can handle
    • Error rates: Percentage of failed API calls or data processing errors
    • Container resource usage: CPU and memory consumption under typical load
    • Vendor-specific limits: Rate limiting thresholds and API quotas

Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"

Dependencies

  • Agentless infrastructure GA readiness (still in beta)
  • Input compatibility: Currently agentless is optimized for httpjson and cel inputs
  • UX enhancement: Add agentless deployment filter/toggle to integrations catalog page for better discoverability

Activity

  1. added
    enhancementNew feature or request
    Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]
    Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]
    on Jun 23, 2026
  2. infra-vault-gh-plugin-prod commented on Jun 23, 2026

    @infra-vault-gh-plugin-prod

    Pinging @elastic/security-service-integrations (Team:Security-Service Integrations)

  3. github-actions commented on Jun 23, 2026

    @github-actions
    Contributor

    tl;dr: ZeroFox is a good Phase I agentless candidate; implement this as a manifest/docs/changelog change, with performance metrics left as follow-up work that needs a ZeroFox environment.

    Recommendation

    Enable agentless deployment for packages/zerofox by following the current Security Service integration pattern: add deployment_modes to the zerofox policy template, bump the package version and manifest format, add the standard agentless docs block, and add a changelog entry. I did not find evidence that stream/auth changes are required: the package is a single httpjson API polling integration.

    Findings

    Key ZeroFox facts:

    File Evidence
    packages/zerofox/manifest.yml:3 Current package version is 1.29.0; this should be bumped for the enhancement.
    packages/zerofox/manifest.yml:6 Current format_version is 3.0.2; comparable current agentless packages use 3.3.2.
    packages/zerofox/manifest.yml:21-26 Single policy template named zerofox, with one httpjson input.
    packages/zerofox/manifest.yml:36-42 Request tracing is hidden from users (show_user: false) and should remain off by default for agentless.
    packages/zerofox/manifest.yml:50-57 Auth is a secret API token, compatible with remote API collection.
    packages/zerofox/manifest.yml:76-78 Owner is elastic/security-service-integrations, matching the agentless ownership metadata used by similar packages.
    packages/zerofox/data_stream/alerts/manifest.yml:1-7 The only data stream is logs/alerts and the only stream input is httpjson.
    packages/zerofox/data_stream/alerts/agent/stream/httpjson.yml.hbs:1-36 The stream performs API GET polling, sets the token header, paginates on body.next, and maintains a cursor.
    packages/zerofox/docs/README.md:1-7 and packages/zerofox/_dev/build/docs/README.md:1-7 Docs currently jump from the intro to Compatibility; there is no agentless section.
    packages/zerofox/changelog.yml:1-6 Top changelog entry is 1.29.0; add the new enhancement entry above it.

    Comparable current pattern:

    File Evidence
    packages/bitwarden/manifest.yml:43-51 Uses deployment_modes.default.enabled: true and deployment_modes.agentless with enabled: true, release: beta, organization: security, division: engineering, team: security-service-integrations.
    packages/bitwarden/docs/README.md:9-12 Shows the standard “Agentless Enabled Integration” documentation block.
    packages/bitwarden/changelog.yml:8-11 Uses changelog wording “Enable Agentless deployment.”
    PR #13367 The issue’s reference PR enabled agentless for AWS Security Hub through manifest/docs/changelog changes.

    Related search results: no PR matched "[zerofox]" "Agentless"; the only issue search result for that query was this issue.

    Verification

    Local static search confirms ZeroFox does not already have agentless wiring in the relevant package files:

    $ rg -n "deployment_modes|agentless" packages/zerofox/{manifest.yml,docs/README.md,_dev/build/docs/README.md,changelog.yml}
    No matches found.
    

    elastic-package is not installed in this runner, so I could not run package validation here:

    $ command -v elastic-package || echo "elastic-package not installed"
    elastic-package not installed
    
    Detailed Action Plan
    1. Update packages/zerofox/manifest.yml:
      • bump version from 1.29.0 to 1.30.0;
      • bump format_version from 3.0.2 to the current agentless-compatible package format used by comparable packages, for example 3.3.2;
      • add this block under policy_templates[0] (name: zerofox) before inputs:
    deployment_modes:
      default:
        enabled: true
      agentless:
        enabled: true
        release: beta
        organization: security
        division: engineering
        team: security-service-integrations
    1. Update packages/zerofox/docs/README.md and regenerate/update packages/zerofox/_dev/build/docs/README.md with the standard block before ## Compatibility:
    ## Agentless Enabled Integration
    
    Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and the [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html).
    Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments.  This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.
    1. Add a top entry to packages/zerofox/changelog.yml:
    - version: "1.30.0"
      changes:
        - description: Enable Agentless deployment.
          type: enhancement
          link: https://github.com/elastic/integrations/pull/<PR_NUMBER>
    1. Validate in a developer environment with elastic-package installed:
    cd packages/zerofox
    elastic-package build
    elastic-package check -v
    elastic-package test pipeline
    elastic-package test system
    
    1. For the performance requirement, collect and document metrics only after testing against a real ZeroFox/vendor environment or representative sample data: average API response time, events processed per minute, API/data processing error rate, container CPU/memory, and ZeroFox API quota/rate-limit behavior.
    Related Items
    Type Item Relevance
    Issue #19700 Current ZeroFox agentless request.
    PR #13367 Reference implementation linked by the issue; enabled agentless for AWS Security Hub.
    File packages/zerofox/manifest.yml Main implementation surface for deployment_modes, version, and format version.
    File packages/zerofox/docs/README.md Source docs that need the agentless section.
    File packages/zerofox/_dev/build/docs/README.md Generated docs currently missing the agentless section.
    File packages/zerofox/changelog.yml Needs the release entry.
    File packages/bitwarden/manifest.yml Current Security Service pattern including release: beta.

    What is this? | From workflow: Issue Triage

    Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

Integration:zerofoxZeroFox (Partner supported)Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Team:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]enhancementNew feature or request

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions