Repository navigation
[zerofox] Add Agentless Deployment Support #19700
Description
Activity
- addedenhancementNew feature or requestNew feature or requestTeam:Security-Service IntegrationsSecurity Service Integrations team [elastic/security-service-integrations]Security Service Integrations team [elastic/security-service-integrations]Integration:zerofoxZeroFox (Partner supported)ZeroFox (Partner supported)Team:SDE-CrestCrest developers on the Security Integrations team [elastic/sit-crest-contractors]Crest developers on the Security Integrations team [elastic/sit-crest-contractors]
on Jun 23, 2026 - added a parent issue
on Jun 23, 2026 infra-vault-gh-plugin-prod commented
on Jun 23, 2026 More actionsPinging @elastic/security-service-integrations (Team:Security-Service Integrations)
github-actions commented
on Jun 23, 2026 on Jun 23, 2026 – with GitHub ActionsContributorMore actionstl;dr: ZeroFox is a good Phase I agentless candidate; implement this as a manifest/docs/changelog change, with performance metrics left as follow-up work that needs a ZeroFox environment.
Recommendation
Enable agentless deployment for
packages/zerofoxby following the current Security Service integration pattern: adddeployment_modesto thezerofoxpolicy template, bump the package version and manifest format, add the standard agentless docs block, and add a changelog entry. I did not find evidence that stream/auth changes are required: the package is a singlehttpjsonAPI polling integration.Findings
Key ZeroFox facts:
File Evidence packages/zerofox/manifest.yml:3Current package version is 1.29.0; this should be bumped for the enhancement.packages/zerofox/manifest.yml:6Current format_versionis3.0.2; comparable current agentless packages use3.3.2.packages/zerofox/manifest.yml:21-26Single policy template named zerofox, with onehttpjsoninput.packages/zerofox/manifest.yml:36-42Request tracing is hidden from users ( show_user: false) and should remain off by default for agentless.packages/zerofox/manifest.yml:50-57Auth is a secret API token, compatible with remote API collection. packages/zerofox/manifest.yml:76-78Owner is elastic/security-service-integrations, matching the agentless ownership metadata used by similar packages.packages/zerofox/data_stream/alerts/manifest.yml:1-7The only data stream is logs/alerts and the only stream input is httpjson.packages/zerofox/data_stream/alerts/agent/stream/httpjson.yml.hbs:1-36The stream performs API GET polling, sets the token header, paginates on body.next, and maintains a cursor.packages/zerofox/docs/README.md:1-7andpackages/zerofox/_dev/build/docs/README.md:1-7Docs currently jump from the intro to Compatibility; there is no agentless section. packages/zerofox/changelog.yml:1-6Top changelog entry is 1.29.0; add the new enhancement entry above it.Comparable current pattern:
File Evidence packages/bitwarden/manifest.yml:43-51Uses deployment_modes.default.enabled: trueanddeployment_modes.agentlesswithenabled: true,release: beta,organization: security,division: engineering,team: security-service-integrations.packages/bitwarden/docs/README.md:9-12Shows the standard “Agentless Enabled Integration” documentation block. packages/bitwarden/changelog.yml:8-11Uses changelog wording “Enable Agentless deployment.” PR #13367 The issue’s reference PR enabled agentless for AWS Security Hub through manifest/docs/changelog changes. Related search results: no PR matched
"[zerofox]" "Agentless"; the only issue search result for that query was this issue.Verification
Local static search confirms ZeroFox does not already have agentless wiring in the relevant package files:
$ rg -n "deployment_modes|agentless" packages/zerofox/{manifest.yml,docs/README.md,_dev/build/docs/README.md,changelog.yml} No matches found.elastic-packageis not installed in this runner, so I could not run package validation here:$ command -v elastic-package || echo "elastic-package not installed" elastic-package not installedDetailed Action Plan
- Update
packages/zerofox/manifest.yml:- bump
versionfrom1.29.0to1.30.0; - bump
format_versionfrom3.0.2to the current agentless-compatible package format used by comparable packages, for example3.3.2; - add this block under
policy_templates[0](name: zerofox) beforeinputs:
- bump
deployment_modes: default: enabled: true agentless: enabled: true release: beta organization: security division: engineering team: security-service-integrations
- Update
packages/zerofox/docs/README.mdand regenerate/updatepackages/zerofox/_dev/build/docs/README.mdwith the standard block before## Compatibility:
## Agentless Enabled Integration Agentless integrations allow you to collect data without having to manage Elastic Agent in your cloud. They make manual agent deployment unnecessary, so you can focus on your data instead of the agent that collects it. For more information, refer to [Agentless integrations](https://www.elastic.co/guide/en/serverless/current/security-agentless-integrations.html) and the [Agentless integrations FAQ](https://www.elastic.co/guide/en/serverless/current/agentless-integration-troubleshooting.html). Agentless deployments are only supported in Elastic Serverless and Elastic Cloud environments. This functionality is in beta and is subject to change. Beta features are not subject to the support SLA of official GA features.
- Add a top entry to
packages/zerofox/changelog.yml:
- version: "1.30.0" changes: - description: Enable Agentless deployment. type: enhancement link: https://github.com/elastic/integrations/pull/<PR_NUMBER>
- Validate in a developer environment with
elastic-packageinstalled:
cd packages/zerofox elastic-package build elastic-package check -v elastic-package test pipeline elastic-package test system- For the performance requirement, collect and document metrics only after testing against a real ZeroFox/vendor environment or representative sample data: average API response time, events processed per minute, API/data processing error rate, container CPU/memory, and ZeroFox API quota/rate-limit behavior.
Related Items
Type Item Relevance Issue #19700 Current ZeroFox agentless request. PR #13367 Reference implementation linked by the issue; enabled agentless for AWS Security Hub. File packages/zerofox/manifest.ymlMain implementation surface for deployment_modes, version, and format version.File packages/zerofox/docs/README.mdSource docs that need the agentless section. File packages/zerofox/_dev/build/docs/README.mdGenerated docs currently missing the agentless section. File packages/zerofox/changelog.ymlNeeds the release entry. File packages/bitwarden/manifest.ymlCurrent Security Service pattern including release: beta.
What is this? | From workflow: Issue Triage
Give us feedback! React with 🚀 if perfect, 👍 if helpful, 👎 if not.
- Update
Description
Add agentless support to the zerofox.
Requirements
Following the established Phase I pattern, for each integration see the Onboarding Integration Guide.
1. Technical implementation
Example reference: #13367
2. Performance documentation
Example documentation format: "Crowdstrike Falcon Intelligence: 200ms avg API response, 5,000 events/min, 0.1% error rate, 512MB RAM/0.5CPU, 1000 API calls/hour limit"
Dependencies