Deployment
Most of the CyberOptix CTEM Platform runs as a service you simply use. These pages cover the parts that run on your infrastructure, because they have to be somewhere the targets are.
| System | What it does | Deploy one when |
|---|---|---|
| Scanner | Discovery and vulnerability testing | You need to assess internal networks |
| Apex appliance | Guided assessment, campaigns, reporting | You want assessment sessions, not just scans |
| Syslog collector | Receives syslog and ships it to the platform | You are feeding the SIEM from your own devices |
| Integrator | Relays integration work | An integration target has no public endpoint |
Everything external - internet-facing attack surface, cloud accounts, source control, identity providers - is reached by the platform directly and needs nothing deployed.
What they have in common
Every edge system follows the same shape, which is worth knowing once rather than four times:
Ubuntu Server 24.04. All of them ship as .deb packages from the Purple Team
Software repositories. Red Hat is no longer supported.
Outbound only. They connect out to the platform and poll for work. None of them accepts inbound connections, so none needs a forwarded port or a hole in your firewall.
Install, then link. Installing puts the software on the host and does nothing else. Linking binds that host to your organization and is what makes it live. A host that is installed but unlinked is inert, which is what makes it safe to bake edge systems into a machine image and link them afterwards.
They run unprivileged. All of them run as the optix service account. Where
elevated capability is genuinely needed - raw sockets for nmap, for instance - it is
granted narrowly rather than by running the whole thing as root.
Packages are named cyberoptix.scanner, cyberoptix.apex and so on, and the service
account is optix. These are product-internal identifiers rather than branding, so they
read the same regardless of which brand you access the platform under.
Adding the package repository
Every guide below starts with the same three commands. If a host already has another edge system on it, the repository is already configured and you can skip straight to the install step.
sudo rm -f /usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg
wget -O - https://apt.fury.io/purpleteamsoftware/gpg.key | sudo gpg --dearmor -o /usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg] https://apt.purpleteamsoftware.com/ /" | sudo tee /etc/apt/sources.list.d/purpleteamsoftware.list
The first line is not optional housekeeping. gpg --dearmor prompts before overwriting
an existing keyring, and on a re-run - which is exactly when you hit this - there is
nothing attached to answer the prompt, so the command appears to hang.
Where to start
Deploying a scanner is the most common first step, and Scanners covers the install-then-link pattern in full. Create a scanner group first, though: the link command you need at the end of the install comes from the group.