Skip to main content
The Agger Labs integration syncs anti-ransomware incidents and endpoint inventory from Agger into Wirespeed, including:
  • Ransomware incidents: Canary, tampering, startup guard, and Agger trigger detections
  • Endpoint inventory: Devices with the Agger agent installed, including hostname, operating system, and online status

Prerequisites

Before setting up this integration, ensure you have an Agger Labs tenant with admin access

Step 1: Create an API Client

  1. Log in to your Agger admin console
  2. Create an API client scoped to the companies you want Wirespeed to access
  3. Grant at least these permissions:
    • read:incidents
    • read:endpoints
    • update:endpoints
  4. Copy the Client ID and Client Secret
Store the client secret securely. Agger may only show it once when the API client is created.

Step 2: Add the Integration in Wirespeed

  1. Log in to Wirespeed and navigate to Integrations > Add Integration
  2. Search for and select Agger Labs
  3. Enter your Client ID and Client Secret
  4. Click Integrate to complete the setup

What Gets Synced?

Incidents (Detections)

Wirespeed ingests anti-ransomware incidents from Agger, including process details, SHA256 hashes, mitigation status, and affected endpoints.

Endpoints

All endpoints with the Agger agent are synced as endpoint inventory, including hostname, operating system, IP addresses, and online status.

Troubleshooting

Authentication Errors

If you see authentication errors:
  1. Verify the client ID and secret are correct
  2. Confirm the API client has read:incidents and read:endpoints permissions
  3. Confirm the API client is scoped to the expected companies

No Incidents Appearing

If incidents aren’t showing up:
  1. Incidents may take a few minutes to appear after initial setup
  2. The initial sync pulls up to the newest 5,000 incidents
  3. Verify that incidents exist in your Agger console

Additional Resources

On first sync, Wirespeed fetches up to the newest 5,000 incidents.