Agent Dependency and Whitelisting

Dependencies

The ConnectSecure agent requires several dependencies in the default agent installation directory according to the installed operating system.

For Windows: ‘C:\Program Files (x86)\CyberCNSAgent’

For Mac/Linux: /opt/CyberCNSAgent

Windows

MAC

Linux

ARM

Windows

MAC

Linux

ARM

Lightweight Agents

connectsecurepatch.exe

 

 

 

cybercnsagentmonitor.exe

 

 

 

cyberutilities.exe

cyberutilities_darwin

cyberutilities_linux

cyberutilities_arm

main.ps1

main.ps1

main.ps1

main.ps1

osqueryi.exe

nmap

nmap

osqueryi_arm

scripts.zip

osqueryi_darwin

osqueryi_linux

scripts.zip

vcruntime140.dll

scripts.zip

scripts.zip

 

WindowsSpeculationControlFinder.zip

 

 

 

Additional Dependencies For Probe Agent

osqueryi_darwin

osqueryi.exe

osqueryi.exe

osqueryi.exe

osqueryi_linux

osqueryi_linux

osqueryi_darwin

osqueryi_linux

osqueryi_arm

osqueryi_arm

osqueryi_arm

osqueryi_darwin

firewall_configs.zip

firewall_configs.zip

firewall_configs.zip

firewall_configs.zip

nmap.zip

nmap

nmap

nmap

npcap.exe > 1.50 version

 

 

 

WindowsSpeculationControlFinder.zip

WindowsSpeculationControlFinder.zip

WindowsSpeculationControlFinder.zip

WindowsSpeculationControlFinder.zip

You can view the status of dependencies based on the agent by clicking on Overview > Agents and tapping on the three-dot Action menu.

image-20240522-210457.png

Select the Dependency Status option.

image-20240522-210527.png

This is an example of a Windows-based asset with a probe agent installed:


Please whitelist outbound communication from the agent machine to *.myconnectsecure.com and Whitelist below URL for Cloudflare R2 to download dependencies:
45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com

You can test the connection using the below command:

telnet 45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com 443

You can install TELNET CLIENT from Microsoft here: https://learn.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc771275(v=ws.10)

Dissolvable Agent for Probe-Scanned Assets

For remote assets getting scanned via Probe Agent:

  • Whitelist the executable path below for the dissolvable agent to be entered into a remote asset.  "C:\windows\CyberCNS_DissolvableAgent" 

  • To whitelist the folder on the remote asset, use the installation folder path, i.e “C:\Windows\CyberCNSAgent”


Port Communications

ConnectSecure V4 Agent(s) require ports 4222 and 443 to be open from the agent machine to the respective Region/POD IP addresses as shown below, based on your POD.


Windows Defender Policy

Use the PowerShell command to add the CyberCNSAgent to your Windows Defender allow policy:

Command: Add-MpPreference -AttackSurfaceReductionOnlyExclusions "C:\Program Files (x86)\CyberCNSAgent\cybercnsagent.exe"


Supported Operating Systems

Check out the complete list here: Agent Configurations | Supported Operating Systems


For optimal agent communication, you should consider adding the neccessary allow/whitelist policies based on the POD/Region of your ConnectSecure portal hosting. Tap the INFO icon from the Global Dashboard view to obtain your location.

Based on your POD, tap the location to see the details.


Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD101 (Atlanta)

API Communication & Attack Surface Mapper

pod-101-co-ordinator-1

pod-101-worker-2

pod-101-worker-3

pod-101-worker-4

155.138.163.9

144.202.22.7

144.202.31.82

155.138.239.5

US

POD101 (Atlanta)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD101 (Atlanta)

Domain

*.myconnectsecure.com

US

POD101 (Atlanta)

External Scan

externalscan-pod101

96.30.199.202
144.202.19.68
104.156.254.48
155.138.195.116
155.138.196.189

US

POD101 (Atlanta)

Load Balancer

pod-101-ccns-lb

servicebus-pod-101-atl

pod-101-cybercns-lb

servicebus-pod-101-cybercns-atl

144.202.23.74

96.90.197.238

144.202.24.89

45.76.60.220

US

POD101 (Atlanta)

NATS Communication Domain Names

servicebus1011.myconnectsecure.com

servicebus1012.myconnectsecure.com

servicebus1013.myconnectsecure.com

servicebus1014.myconnectsecure.com

US

POD101 (Atlanta)

API Communication Domain Names

pod101.myconnectsecure.com

pod101.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD102 (LAX)

API Communication & Attack Surface Mapper

pod-102-co-ordinator-1

pod-102-worker-2

pod-102-worker-3

pod-102-worker-4

149.28.93.167

149.248.19.118

45.32.80.51

149.248.4.153

US

POD102 (LAX)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD102 (LAX)

Domain

*.myconnectsecure.com

US

POD102 (LAX)

External Scan

externalscan-pod102

149.28.94.44
66.42.106.63
45.76.69.20
45.63.48.188
149.28.82.167

US

POD102 (LAX)

Load Balancer

pod-102-ccns-lb

servicebus-pod-102-lax

pod-102-cybercns-lb

servicebus-pod-102-cybercns-lax

45.77.87.242

108.61.217.214

149.248.1.190

45.32.64.70

US

POD102 (LAX)

NATS Communication Domain Names

servicebus1021.myconnectsecure.com

servicebus1022.myconnectsecure.com

servicebus1023.myconnectsecure.com

servicebus1024.myconnectsecure.com

US

POD102 (LAX)

API Communication Domain Names

pod102.myconnectsecure.com

pod102.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD103 (Miami)

API Communication & Attack Surface Mapper

pod-103-co-ordinator-1

pod-103-worker-2

pod-103-worker-3

pod-103-worker-4

47.77.164.106

45.32.162.89

45.77.163.10

45.63.105.163

US

POD103 (Miami)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD103 (Miami)

Domain

*.myconnectsecure.com

US

POD103 (Miami)

External Scan

externalscan-podui-pod103

144.202.37.9
104.238.137.61
45.77.93.69
45.77.165.110
45.32.172.78

US

POD103 (Miami)

Load Balancer

pod-103-ccns-lb

servicebus-pod-103-MIA

pod-103-cybercns-lb

servicebus-pod-103-cybercns-MIA

104.207.144.192

149.28.101.233

149.28.97.153

45.63..110.13

US

POD103 (Miami)

NATS Communication Domain Names

servicebus1031.myconnectsecure.com

servicebus1032.myconnectsecure.com

servicebus1033.myconnectsecure.com

servicebus1034.myconnectsecure.com

US

POD103 (Miami)

API Communication Domain Names

pod103.myconnectsecure.com

pod103.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD104 (LAX)

API Communication & Attack Surface Mapper

pod-104-co-ordinator-1
pod-104-worker-2
pod-104-worker-3
pod-104-worker-4

149.248.11.111
104.238.140.172
149.28.85.100
149.28.89.183

US

POD104 (LAX)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD104 (LAX)

Domain

*.myconnectsecure.com

US

POD104 (LAX)

External Scan

externalscan-pod104

45.32.73.67
45.77.124.22
149.28.83.41
149.28.93.179
45.77.87.43

US

POD104 (LAX)

Load Balancer

pod-104-ccns-lb
servicebus-pod-104-lax
pod-104-cybercns-lb
servicebus-pod-104-cybercns-lax

144.202.125.97
66.42.108.17
149.28.76.247
149.28.77.82

US

POD104 (LAX)

NATS Communication Domain Names

servicebus1041.myconnectsecure.com

servicebus1042.myconnectsecure.com

servicebus1043.myconnectsecure.com

servicebus1044.myconnectsecure.com

US

POD104 (LAX)

API Communication Domain Names

pod104.myconnectsecure.com

pod104.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD105 (Atlanta)

API Communication & Attack Surface Mapper

pod-105-co-ordinator-1
pod-105-worker-2
pod-105-worker-3
pod-105-worker-4

155.138.211.47
155.138.216.219
45.76.63.93
155.138.201.146

US

POD105 (Atlanta)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD105 (Atlanta)

Domain

*.myconnectsecure.com

US

POD105 (Atlanta)

External Scan

externalscan-pod105

66.42.80.25
155.138.215.234
45.32.216.246
45.76.60.14
45.32.213.19

US

POD105 (Atlanta)

Load Balancer

pod-105-ccns-lb
servicebus-pod-105-ATL
pod-105-cybercns-lb
servicebus-pod-105-cybercns-ATL

66.42.92.100
155.138.174.213
45.32.223.18
96.30.199.63

US

POD105 (Atlanta)

NATS Communication Domain Names

servicebus1051.myconnectsecure.com
servicebus1052.myconnectsecure.com
servicebus1053.myconnectsecure.com
servicebus1054.myconnectsecure.com

US

POD105 (Atlanta)

API Communication Domain Names

pod105.myconnectsecure.com
pod105.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD106 (Silicon)

API Communication & Attack Surface Mapper

pod-106-co-ordinator-1
pod-106-worker-2
pod-106-worker-3
pod-106-worker-4

144.202.103.41
45.32.131.33
45.63.84.112
45.77.188.72

US

POD106 (Silicon)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD106 (Silicon)

Domain

*.myconnectsecure.com

US

POD106 (Silicon)

External Scan

externalscan-pod106

45.77.184.219
45.32.137.105
45.32.139.104
45.63.95.220
45.32.133.60

US

POD106 (Silicon)

Load Balancer

pod-106-ccns-lb
servicebus-pod-106-SJC
pod-106-cybercns-lb

45.32.136.214
45.77.7.237
149.28.208.2

US

POD106 (Silicon)

NATS Communication Domain Names

servicebus1061.myconnectsecure.com
servicebus1062.myconnectsecure.com
servicebus1063.myconnectsecure.com
servicebus1064.myconnectsecure.com

US

POD106 (Silicon)

API Communication Domain Names

pod106.myconnectsecure.com
pod106.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD107 (Miami)

API Communication & Attack Surface Mapper

pod-107-co-ordinator-1
pod-107-worker-2
pod-107-worker-3
pod-107-worker-4

pod-107-boldbi-5

pod-107-boldreport-6

104.156.246.18
104.238.138.160
45.63.111.129
45.32.164.88

207.246.65.150

149.28.99.175

US

POD107 (Miami)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD107 (Miami)

Domain

*.myconnectsecure.com

US

POD107 (Miami)

External Scan

externalscan-pod107

45.32.164.13
104.207.145.147
207.246.74.82
45.77.115.180
207.246.115.53

US

POD107 (Miami)

Load Balancer

pod-107-ccns-lb
servicebus-pod-107-MIA
pod-107-cybercns-lb

149.28.104.10
144.202.43.11
45.63.105.191

US

POD107 (Miami)

NATS Communication Domain Names

servicebus1071.myconnectsecure.com/
servicebus1072.myconnectsecure.com/
servicebus1073.myconnectsecure.com/
servicebus1074.myconnectsecure.com/

104.156.246.18
104.238.138.160
45.63.111.129
45.32.164.88

US

POD107 (Miami)

API Communication Domain Names

pod107.myconnectsecure.com
pod107.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

US

POD200 (Canada)

API Communication & Attack Surface Mapper

pod-200-co-ordinator-1
pod-200-worker-2
pod-200-worker-3
pod-200-worker-4

155.138.158.204
216.128.185.33
149.248.60.138
216.128.178.144

US

POD200 (Canada)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

US

POD200 (Canada)

Domain

*.myconnectsecure.com

US

POD200 (Canada)

External Scan

externalscan-pod200

149.248.59.179
216.128.185.253
155.138.131.149
216.128.185.85
149.248.54.51

US

POD200 (Canada)

Load Balancer

servicebus-200-canada
pod-200-ccns-lb
servicebus-200-cybercns-canada
pod-200-cybercns-lb

155.138.156.16
155.138.140.251
155.138.140.52
216.128.176.130

US

POD200 (Canada)

NATS Communication Domain Names

servicebus2001.myconnectsecure.com
servicebus2002.myconnectsecure.com
servicebus2003.myconnectsecure.com
servicebus2004.myconnectsecure.com

US

POD200 (Canada)

API Communication Domain Names

pod200.myconnectsecure.com
pod200.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

EU

POD300 (London)

API Communication & Attack Surface Mapper

pod-300-co-ordinator-1
pod-300-worker-2
pod-300-worker-3
pod-300-worker-4

192.248.150.43
95.179.196.101
95.179.230.189
45.77.88.130

EU

POD300 (London)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

EU

POD300 (London)

Domain

*.myconnectsecure.com

EU

POD300 (London)

External Scan

externalscan-pod300

78.141.199.55
95.179.196.193
192.248.169.16
209.250.226.92
78.141.239.205

EU

POD300 (London)

Load Balancer

pod-300-ccns-lb
servicebus-pod-300-LHR
pod-300-cybercns-lb
servicebus-pod-300-cybercns-LHR

209.250.225.16
95.179.230.15
192.248.173.195
95.179.226.241

EU

POD300 (London)

NATS Communication Domain Names

servicebus3001.myconnectsecure.com
servicebus3002.myconnectsecure.com
servicebus3003.myconnectsecure.com
servicebus3004.myconnectsecure.com

EU

POD300 (London)

API Communication Domain Names

pod300.myconnectsecure.com
pod300.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

EU

POD400 (Poland)

API Communication & Attack Surface Mapper

pod-400-co-ordinator-1
pod-400-worker-2
pod-400-worker-3
pod-400-worker-4

70.34.243.47
70.34.252.117
70.34.248.226
70.34.254.208

EU

POD400 (Poland)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

EU

POD400 (Poland)

Domain

*.myconnectsecure.com

EU

POD400 (Poland)

External Scan

externalscan-pod400

64.176.68.187
70.34.255.68
70.34.250.223
64.176.69.206
64.176.66.138

EU

POD400 (Poland)

Load Balancer

pod-400-ccns-lb
servicebus-pod-400-WAW
pod-400-cybercns-lb
servicebus-pod-400-cybercns-WAW

64.176.69.126
64.176.68.29
70.34.254.228
70.34.246.119

EU

POD400 (Poland)

NATS Communication Domain Names

servicebus4001.myconnectsecure.com
servicebus4002.myconnectsecure.com
servicebus4003.myconnectsecure.com
servicebus4004.myconnectsecure.com

EU

POD400 (Poland)

API Communication Domain Names

pod400.myconnectsecure.com
pod400.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

EU

POD401 (Madrid)

API Communication & Attack Surface Mapper

pod-401-co-ordinator-1
pod-401-worker-2
pod-401-worker-3
pod-401-worker-4

65.20.100.219
65.20.103.194
65.20.98.64
65.20.105.37

EU

POD401 (Madrid)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

EU

POD401 (Madrid)

Domain

*.myconnectsecure.com

EU

POD401 (Madrid)

External Scan

externalscan-pod401

65.20.101.228
65.20.102.116
65.20.100.179
208.85.19.248
65.20.101.135

EU

POD401 (Madrid)

Load Balancer

pod-401-ccns-lb
servicebus-pod-401-MAD
pod-401-cybercns-lb
servicebus-pod-401-cybercns-MAD

65.20.103.34
208.85.23.92
65.20.101.84
65.20.103.106

EU

POD401 (Madrid)

NATS Communication Domain Names

servicebus4011.myconnectsecure.com
servicebus4012.myconnectsecure.com
servicebus4013.myconnectsecure.com
servicebus4014.myconnectsecure.com

EU

POD401 (Madrid)

API Communication Domain Names

pod401.myconnectsecure.com
pod401.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

AU

POD500 (Sydney)

API Communication & Attack Surface Mapper

pod-500-co-ordinator-1
pod-500-worker-2
pod-500-worker-3
pod-500-worker-4

149.28.188.232
45.32.189.250
45.77.237.248
45.32.245.127

AU

POD500 (Sydney)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

AU

POD500 (Sydney)

Domain

*.myconnectsecure.com

AU

POD500 (Sydney)

External Scan

externalscan-pod500

45.32.243.130
45.63.31.29
45.77.239.50
139.180.174.25
149.28.178.12

AU

POD500 (Sydney)

Load Balancer

pod-500-ccns-lb
servicebus-pod-500-syd
pod-500-cybercns-lb
servicebus-pod-500-cybercns-syd
pod-500-cybercns-lb

139.180.161.236
149.28.169.80
45.76.115.227
45.63.27.172
45.63.97.214

AU

POD500 (Sydney)

NATS Communication Domain Names

servicebus5001.myconnectsecure.com
servicebus5002.myconnectsecure.com
servicebus5003.myconnectsecure.com
servicebus5004.myconnectsecure.com

AU

POD500 (Sydney)

API Communication Domain Names

pod500.myconnectsecure.com
pod500.mycybercns.com

Region

POD# (Location)

Function

Server

IP

Region

POD# (Location)

Function

Server

IP

AF

POD600 (Johannesburg)

API Communication & Attack Surface Mapper

pod-600-co-ordinator-1
pod-600-worker-2
pod-600-worker-3
pod-600-worker-4

139.84.230.190
139.84.232.134
139.84.233.23
139.84.226.34

AF

POD600 (Johannesburg)

Cloudflare R2

http://45ee58f3bc4d04c0e1ae971fde066899.r2.cloudflarestorage.com/

AF

POD600 (Johannesburg)

Domain

*.myconnectsecure.com

AF

POD600 (Johannesburg)

External Scan

externalscan-pod600

139.84.237.7
139.84.230.101
139.84.227.200
139.84.238.60
139.84.239.62

AF

POD600 (Johannesburg)

Load Balancer

pod-600-ccns-lb
servicebus-pod-600-JNB
pod-600-cybercns-lb
servicebus-pod-600-cybercns-JNB

139.84.229.231
139.84.226.159
139.84.226.92
139.84.228.205

AF

POD600 (Johannesburg)

NATS Communication Domain Names

servicebus6001.myconnectsecure.com
servicebus6002.myconnectsecure.com
servicebus6003.myconnectsecure.com
servicebus6004.myconnectsecure.com

AF

POD600 (Johannesburg)

API Communication Domain Names

pod600.myconnectsecure.com
pod600.mycybercns.com