Docs › Agent
How the agent works
inframole-agent is a single binary for Windows and Linux (x86-64
and ARM64). It observes the host it runs on and sends one small report to
your InfraMole server every five minutes. It is strictly read-only.
What it reports
| Data | Used for |
|---|---|
| Hostname, FQDN, OS, kernel, architecture, boot time | Identifying the host |
| Network interfaces (name, MAC, IP addresses) | Matching connections from other hosts |
| Running services (name, state, start type) | Showing what runs on the host |
| Listening TCP ports + owning process name / path | Knowing what the host offers |
| Established TCP connections, aggregated per peer, port and process | Suggesting dependencies |
Connections are sampled every 30 seconds and summarised; loopback, link-local and multicast traffic is ignored. The full list, with a real example report, is on What the agent collects.
What it never collects
Passwords, credentials, tokens, file contents, user documents, browser data, command-line arguments, environment variables, logged-in users and packet contents. The agent's data structures have no fields for them, and the server rejects any report with unexpected fields.
How it talks to the server
- Outbound HTTPS only, to your InfraMole address. Nothing connects to the agent; no inbound port is opened.
- No command channel: the server can only answer with reporting intervals. It can never tell the agent to run anything.
- Each agent has its own credential, created at enrollment from an enrollment token (it expires, and can be limited to a number of agents). Revoking the agent in InfraMole rejects its reports immediately.
Permissions
The agent runs as a service (LocalSystem on Windows, root with systemd on Linux) because the operating system requires it to see which process owns each socket. It writes nothing outside its configuration directory. Without administrator rights it still works, with fewer process names.
From reports to suggestions
- The first report creates the host in the Library as Discovered.
- Connections seen at least twice to an IP that belongs to exactly one
other resource become a detected relationship in Suggestions
(for example
APP01 → SQL01:1433 (likely MSSQL)). - A person confirms, adds context or ignores it. Ignored pairs are never suggested again.
- If a host stops reporting for three intervals it becomes Stale; it returns to its previous state when it reports again.
Limits of observation
Polling can miss rare or very short connections (for example a nightly job). NAT, load balancers and proxies hide the real peer. And a connection does not prove a dependency — which is why a person confirms.
Verifying the binaries
Releases publish SHA256SUMS, signed with Sigstore, and a build-provenance
attestation for every binary. The install commands in InfraMole check the
checksum before running anything. See Install the agent.
