Skip to main content

Deployment

Most of the CyberOptix CTEM Platform runs as a service you simply use. These pages cover the parts that run on your infrastructure, because they have to be somewhere the targets are.

SystemWhat it doesDeploy one when
ScannerDiscovery and vulnerability testingYou need to assess internal networks
Apex applianceGuided assessment, campaigns, reportingYou want assessment sessions, not just scans
Syslog collectorReceives syslog and ships it to the platformYou are feeding the SIEM from your own devices
IntegratorRelays integration workAn integration target has no public endpoint

Everything external - internet-facing attack surface, cloud accounts, source control, identity providers - is reached by the platform directly and needs nothing deployed.

What they have in common​

Every edge system follows the same shape, which is worth knowing once rather than four times:

Ubuntu Server 24.04. All of them ship as .deb packages from the Purple Team Software repositories. Red Hat is no longer supported.

Outbound only. They connect out to the platform and poll for work. None of them accepts inbound connections, so none needs a forwarded port or a hole in your firewall.

Install, then link. Installing puts the software on the host and does nothing else. Linking binds that host to your organization and is what makes it live. A host that is installed but unlinked is inert, which is what makes it safe to bake edge systems into a machine image and link them afterwards.

They run unprivileged. All of them run as the optix service account. Where elevated capability is genuinely needed - raw sockets for nmap, for instance - it is granted narrowly rather than by running the whole thing as root.

About the package names

Packages are named cyberoptix.scanner, cyberoptix.apex and so on, and the service account is optix. These are product-internal identifiers rather than branding, so they read the same regardless of which brand you access the platform under.

Adding the package repository​

Every guide below starts with the same three commands. If a host already has another edge system on it, the repository is already configured and you can skip straight to the install step.

sudo rm -f /usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg
wget -O - https://apt.fury.io/purpleteamsoftware/gpg.key | sudo gpg --dearmor -o /usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg
echo "deb [signed-by=/usr/share/keyrings/purpleteamsoftware-archive-keyring.gpg] https://apt.purpleteamsoftware.com/ /" | sudo tee /etc/apt/sources.list.d/purpleteamsoftware.list

The first line is not optional housekeeping. gpg --dearmor prompts before overwriting an existing keyring, and on a re-run - which is exactly when you hit this - there is nothing attached to answer the prompt, so the command appears to hang.

Where to start​

Deploying a scanner is the most common first step, and Scanners covers the install-then-link pattern in full. Create a scanner group first, though: the link command you need at the end of the install comes from the group.