Secure60 Linux Agent (s60-linuxagent) is a lightweight Linux agent that records which systems a host connected to, and which domains it looked up.
Linux hosts already report who ran what through auditd and syslog. Linux Agent adds the missing half: where the host talked to. That makes it possible to spot a server reaching a destination it has never used before, resolving a domain nobody else in the estate resolves, or connecting to an address that no DNS lookup ever returned — the signature of a hardcoded command-and-control address.
| Event | Description |
|---|---|
network-connection |
A new connection, with source and destination address, port, protocol and direction |
network-connection-close |
The connection ending, with the bytes transferred each way |
network-flow-summary |
Many connections to the same destination rolled up into one record with a count and byte totals |
dns-query |
A DNS lookup: the domain, the record type, the answers and the response code |
dns-summary |
Repeated lookups for the same domain rolled up with a count |
agent-startup |
Version, configuration fingerprint and what the agent is watching |
agent-heartbeat |
Liveness, plus a full account of anything the agent was unable to record |
TCP, UDP and ICMP are all covered. Events use the Common Information Model, so a DNS lookup recorded by Linux Agent and the same lookup recorded on a DNS server land in the same fields and can be compared directly.
Every record is tagged with the application name s60-linuxagent, so the whole stream can be found in Search, filtered on a dashboard, or charted on a host’s page without knowing the individual field names.
Linux Agent reports every way it could have missed something — packets the kernel dropped, buffer overruns, events shed under load. Nothing is discarded quietly.
This matters because absence is itself a signal. If the network shows traffic from a host and the host reported none, that is worth investigating — an attacker who disables monitoring still generates traffic. That reasoning only holds if the agent is honest about its own gaps, so Secure60 knows the difference between “the host made no such connection” and “the record was lost”.
Measured on production-grade hosts under real load:
| Situation | CPU | Memory |
|---|---|---|
| A busy server, including one fully saturated across all 16 cores | Not measurable — under 0.02% of one core | 8 MB |
| Sustained heavy connection churn (5,694 connection events per second) | 18.65% of one core, with no data lost | 16 MB |
Linux Agent reads connection records the kernel already maintains rather than inspecting network traffic, so its cost follows the number of connections, not the volume of data. On one test host carrying 131 MB/s across 62,000 packets per second, Linux Agent had almost nothing to do, because that traffic used a small number of long-lived connections.
Summarisation is enabled by default and reduced 261,948 connection events to 39 records in testing, with the counts and byte totals preserved.
A single binary runs on every supported distribution and version, with no runtime dependencies to install.
For byte counters, enable connection accounting in the kernel. It is off by default on most systems, and Linux Agent will tell you at startup if it is missing:
sudo sysctl -w net.netfilter.nf_conntrack_acct=1
echo 'net.netfilter.nf_conntrack_acct = 1' | sudo tee /etc/sysctl.d/60-s60-linuxagent.conf
The first line applies it now; the second makes it survive a reboot. This applies to connections opened after it is set.
Do not use sysctl --system to apply it. That command re-applies every
sysctl file on the system, which can revert settings other software relies on
— on a host running containers it resets net.ipv4.ip_forward and will break
container networking.
Verify the checksum before installing.
| Package | For |
|---|---|
| s60-linuxagent-0.5.6-1.x86_64.rpm | RHEL, Rocky, AlmaLinux, Fedora, SUSE, Amazon Linux (64-bit) |
| s60-linuxagent_0.5.6_amd64.deb | Debian, Ubuntu (64-bit) |
| s60-linuxagent-0.5.6-linux-amd64.tar.gz | Any other distribution (64-bit) |
| s60-linuxagent-0.5.6-1.aarch64.rpm | RHEL family (ARM64) |
| s60-linuxagent_0.5.6_arm64.deb | Debian, Ubuntu (ARM64) |
| s60-linuxagent-0.5.6-linux-arm64.tar.gz | Any other distribution (ARM64) |
| SHA256SUMS | Checksums |
No package repository is added to your systems. Linux Agent is installed from a downloaded file, so nothing Secure60 hosts can affect your own patching.
# Verify, then install
sha256sum -c SHA256SUMS --ignore-missing
# RHEL / Rocky / Alma / Fedora / SUSE / Amazon Linux
sudo dnf install ./s60-linuxagent-0.5.6-1.x86_64.rpm
# Debian / Ubuntu
sudo apt install ./s60-linuxagent_0.5.6_amd64.deb
# Anything else
tar xzf s60-linuxagent-0.5.6-linux-amd64.tar.gz && sudo ./install.sh
Linux Agent does not start on install. It captures nothing until you have set a configuration and started it deliberately.
Edit /etc/secure60/linuxagent.yaml. The Collector address is the only
setting most people need to change, and it is the first block in the file:
output:
mode: collector
url: http://your-collector:80/linuxagent
Port 80 for HTTP, 443 for HTTPS.
The trailing /linuxagent is optional. The Collector accepts any path and
ignores it — http://your-collector:80 works just as well. Keeping it simply
tags the stream as http_path on each event, which makes it easy to pick out
later.
Certificates are not verified by default, so a self-signed or expired
Collector certificate will not stop data flowing. To verify, set ca_file to
your Collector’s certificate, or tls_verify: true to use the system trust
store. The agent logs which mode it is using at startup.
The shipped defaults are deliberately conservative and suit most servers: outbound connections and DNS are recorded, inbound connections are not, and repeated connections are summarised every 30 seconds.
Useful settings:
| Setting | Default | Notes |
|---|---|---|
capture.flows.inbound |
false |
Leave off on servers — inbound connections are high volume and rarely informative. Worth enabling on workstations and jump hosts. |
capture.dns.interfaces |
[auto] |
Name interfaces explicitly on hosts running containers, so the same traffic is not recorded twice. |
capture.dns.scope |
host |
Records only DNS this host sends or receives. Set to all only on a SPAN/mirror port, where the interface is meant to see other hosts’ traffic — everything captured is then attributed to this host. |
aggregate.window_seconds |
30 |
Longer windows mean fewer records and less timing detail. |
exclude.dst_ports |
— | Worth excluding monitoring agents, which produce constant uninformative traffic. |
exclude.self |
true |
Leave enabled. Prevents Linux Agent from recording its own deliveries to the Collector. |
Check and preview before starting:
sudo s60-linuxagent --check-config # validate the file
sudo s60-linuxagent --dry-run # show what would be sent, send nothing
sudo systemctl enable --now s60-linuxagent
sudo systemctl status s60-linuxagent
To apply configuration changes without interrupting collection:
sudo systemctl reload s60-linuxagent
If the new configuration is invalid, Linux Agent keeps running on the previous one and records the error rather than stopping.
Linux Agent is restarted automatically if it stops unexpectedly, and starts again after a reboot.
Install the newer package over the top. Your configuration is preserved and the service restarts on the new version.
sudo dnf install ./s60-linuxagent-<new-version>-1.x86_64.rpm
sudo systemctl disable --now s60-linuxagent
sudo dnf remove s60-linuxagent # or: sudo apt remove s60-linuxagent
Your configuration is retained so a reinstall picks up where you left off.
The service will not start. Run sudo s60-linuxagent --check-config. Linux Agent refuses to start on an invalid configuration rather than collecting the wrong thing.
Byte counts are missing. Kernel connection accounting is off; see Requirements above. Linux Agent omits these fields rather than reporting zero, so that “no data transferred” is never confused with “not measured”.
The heartbeat reports dropped events. The host is producing more connections than the current settings allow for. Exclude monitoring ports, turn off inbound capture, or lengthen the summarisation window.
Nothing arrives at the Collector. Linux Agent stores events on disk and resends them when the Collector is reachable again, so a temporary outage delays data rather than losing it. Check journalctl -u s60-linuxagent for delivery errors.