ZebraByte Device Agent Overview
Learn what the ZebraByteDevice Agent does, from registering devices and running as an OS service to collecting posture controls and automatic updating from signed versions.
ZebraByteDevice Agent (probo-agent) is a lightweight device posture agent. it works as a managed OS service, registers a device against your platform organization and periodically reports security posture checks throughout the period. Device Agent API (/api/agent/v1).
What it does
Title: “What It Does”- Enrolls devices with a one-shot sign-in token on the platform console
- It works as a service. for macOS (
launchd), Linux (systemd), FreeBSD (rc.d), and Windows (Service Control Manager) - Collects posture checks such as disk encryption, screen lock, firewall, time synchronization, OS version, automatic update, password policy, remote connection and malware protection
- Heartbeats and reports positioning to the platform on a server-configured range
- Auto-updates from signedGitHubReleases (
probo-agent/v*), with checking Cosign/Sigstore before installing a new binary
It is not a MDM. the platform server cannot push arbitrary controls, shell commands, or device control actions to the agent. Security.
Supported platforms
Section “Supported Platforms”| Platform | Install options | Enrollment |
|---|---|---|
| macOS | Signed universal .pkg |
The browser / tab through Probo Agent.app and probo:// deeplink |
| Windows | Signed .msi |
Tray-assisted browser recording on the platform console |
| Linux | install.sh, CLI archive |
CLI (install.sh or probo-agent install) |
| FreeBSD | install.sh, CLI archive |
CLI (install.sh or probo-agent install) |
See Install to choose a platform, or go directly to macOS, Windows, Linux, or FreeBSD.
How enrollment works
Section entitled “How Enrollment Works”- Create or open a device in the platform console and generate a sign-up token.
- Install the agent – on the desktop, prefer the package installer, then register from us.the platform.com/enroll or eu.the platform.com/enrollon servers, pass the server URL and the token on the command line.
- The agent changes the one-shot token for a key to the device, configures heartbeat / posture intervals, and starts the OS service.
- The posture results appear on the device in the platform console.
Posture checks
Section entitled “Posture checks”The agent evaluates this verification set for each collection cycle:
| Check key | What it verifies |
|---|---|
DISK_ENCRYPTION |
Full-disk encryption is enabled |
SCREEN_LOCK |
Screen lock / idle lock is configured |
FIREWALL_ENABLED |
Host firewall is enabled |
TIME_SYNC |
System clock synchronization is active |
OS_VERSION |
Operating system meets the expected version policy |
AUTO_UPDATE |
Automatic updates are enabled |
PASSWORD_POLICY |
Local password policy is present |
REMOTE_LOGIN |
Remote login exposure is assessed |
MALWARE_PROTECTION |
Integrated anti-malware protection is enabled where appropriate |
Use probo-agent collect to run local checks without pushing the results.