transparency
What the agent collects
inframole-agent is a single, signed, read-only binary for Windows and Linux. Every five minutes it sends one small report over HTTPS. It has no command channel: the server can only answer with its reporting settings, never tell it to run anything.
See for yourself before installing anything — this prints the exact report and sends nothing:
inframole-agent dry-run
Collected, and why
| Data | Why |
|---|---|
| Hostname, FQDN, OS name and version, kernel, architecture, boot time | Identify the machine and show what it is. |
| Machine ID (only when enrolling) | Recognise the same machine after a reinstall of the agent, instead of creating a duplicate. |
| Network interfaces: name, MAC, IP addresses (loopback skipped) | Match connections from other hosts to this one. |
| Running services: name, display name, state, start type | Show what runs on the host (IIS, SQL Server, nginx…). |
| Listening TCP ports and the owning process name / path | Know what the host offers to others. |
| Established TCP connections, aggregated per peer, port and process — counts and first/last seen | Suggest who depends on whom. Shown as “detected”, never as confirmed. |
Never collected
- Passwords, credentials or tokens
- File contents or user documents
- Process command lines or arguments
- Environment variables
- Browser data
- Logged-in users
- Packet contents — only which peer and port, never the data
Enforced twice: the agent's data structures have no fields for any of this, and the server rejects any report with a field it does not expect.
A real report
Shortened to one item per list. This sample is checked against the live protocol schema in our test suite.
{
"schemaVersion": 1,
"agentVersion": "0.3.0",
"collectedAt": "2026-09-29T10:05:00Z",
"windowStart": "2026-09-29T10:00:00Z",
"host": {
"hostname": "prod-web-01",
"fqdn": "prod-web-01.corp.local",
"os": "windows",
"osName": "Microsoft Windows Server 2022 Standard",
"osVersion": "10.0.20348",
"kernelVersion": "10.0.20348",
"arch": "amd64",
"bootTime": "2026-09-01T06:30:00Z"
},
"interfaces": [
{
"name": "Ethernet0",
"mac": "00:15:5d:01:02:03",
"addresses": [
"10.20.4.15/24"
]
}
],
"services": [
{
"name": "W3SVC",
"displayName": "World Wide Web Publishing Service",
"state": "running",
"startType": "auto"
}
],
"listeners": [
{
"proto": "tcp",
"address": "0.0.0.0",
"port": 443,
"process": {
"name": "System",
"pid": 4
}
}
],
"connections": [
{
"proto": "tcp",
"direction": "outbound",
"localPort": 0,
"remoteAddress": "10.20.4.40",
"remotePort": 1433,
"process": {
"name": "w3wp.exe",
"path": "C:WindowsSystem32inetsrvw3wp.exe"
},
"count": 42,
"firstSeen": "2026-09-29T10:00:00Z",
"lastSeen": "2026-09-29T10:04:30Z"
},
{
"proto": "tcp",
"direction": "inbound",
"localPort": 443,
"remoteAddress": "10.20.1.5",
"remotePort": 0,
"count": 318,
"firstSeen": "2026-09-29T10:00:02Z",
"lastSeen": "2026-09-29T10:04:58Z"
}
],
"truncated": false
}Good to know
- Aggregated, not recorded. Connections are sampled every 30 seconds and summarised per peer, port and process. Loopback, link-local and multicast traffic is ignored. Raw reports are kept for 7 days.
- Permissions. It runs as a service (LocalSystem or root) so it can see which process owns a port. Without admin rights it still works, with fewer process names.
- Optional Proxmox inventory. Only if you enable it on the host, with a read-only token that never leaves the machine: node, VM and container names, ids, status and memory size. Nothing else from the API is kept.
- Verifiable. Releases are signed and published with SHA-256 checksums; the install commands verify them before running.
- Easy to remove. inframole-agent uninstall stops the service and deletes its configuration. Revoking the agent in InfraMole rejects its reports immediately.
