Agents
A small service on each monitored host. It connects out to your Lawliet server on a heartbeat and never listens on a port.
Supported systems
| Platform | Runs as | Status |
|---|---|---|
| Linux: Ubuntu 22.04 and 24.04, Debian 11 and 12, RHEL and Rocky 8 and 9 | systemd service | Field-tested |
| Windows | Scheduled task as SYSTEM | Supported |
| macOS | launchd service | Supported |
The Linux agent needs Python 3.10 or newer.
What an agent does
- Runs compliance checks when a scan asks for them.
- Watches the paths you choose for file integrity changes.
- Reports data loss prevention findings, stored redacted.
- Sends host metrics, processes and connections for the inventory.
- Carries out signed commands: remediation and containment.
Enrolling a host
Run ./lawliet token on the server, or open Environment, Install agent in the console, and copy the command for the platform.
# Linux, as root
curl -sSL https://your-server/api/v1/agents/download/linux | sudo bash -s -- \
--server https://your-server --token <enrolment-token>
# Windows, PowerShell as Administrator
Invoke-WebRequest https://your-server/api/v1/agents/download/windows -OutFile install.ps1
.\install.ps1 -Server https://your-server -Token <enrolment-token>
# macOS
curl -sSL https://your-server/api/v1/agents/download/macos | sudo bash -s -- \
--server https://your-server --token <enrolment-token>
Using a self-signed certificate? Each host has to trust it. ./lawliet tls --export writes the certificate to copy to your hosts.
How commands reach a host
Commands wait in a queue on the server. On its next heartbeat the agent collects them, checks each one's HMAC-SHA256 signature and timestamp, and runs it. A command older than ten minutes, or more than a minute in the future, is refused. This is why time sync matters on both ends.
Agent upgrades
Agents can upgrade themselves to a release signed with an Ed25519 key that we hold offline. An agent refuses any release without a valid signature. Automatic upgrade is off by default.

