- Ransomware incidents: Canary, tampering, startup guard, and Agger trigger detections
- Endpoint inventory: Devices with the Agger agent installed, including hostname, operating system, and online status
Prerequisites
Before setting up this integration, ensure you have an Agger Labs tenant with admin accessStep 1: Create an API Client
- Log in to your Agger admin console
- Create an API client scoped to the companies you want Wirespeed to access
- Grant at least these permissions:
read:incidentsread:endpointsupdate:endpoints
- Copy the Client ID and Client Secret
Step 2: Add the Integration in Wirespeed
- Log in to Wirespeed and navigate to Integrations > Add Integration
- Search for and select Agger Labs
- Enter your Client ID and Client Secret
- Click Integrate to complete the setup
What Gets Synced?
Incidents (Detections)
Wirespeed ingests anti-ransomware incidents from Agger, including process details, SHA256 hashes, mitigation status, and affected endpoints.Endpoints
All endpoints with the Agger agent are synced as endpoint inventory, including hostname, operating system, IP addresses, and online status.Troubleshooting
Authentication Errors
If you see authentication errors:- Verify the client ID and secret are correct
- Confirm the API client has
read:incidentsandread:endpointspermissions - Confirm the API client is scoped to the expected companies
No Incidents Appearing
If incidents aren’t showing up:- Incidents may take a few minutes to appear after initial setup
- The initial sync pulls up to the newest 5,000 incidents
- Verify that incidents exist in your Agger console
Additional Resources
On first sync, Wirespeed fetches up to the newest 5,000 incidents.

