Skip to main content

Tanium

Tanium is a unified endpoint management and security platform that provides real-time visibility, control, and management of endpoints across an organization's IT infrastructure. As a comprehensive endpoint detection and response (EDR) and IT operations solution, Tanium enables organizations to monitor, secure, and manage all endpoints including workstations, servers, laptops, desktops, virtual machines, and cloud instances at enterprise scale.

CategoryEDR
DirectionQuery source
Sign-inNone
Query languagesSTIX
Websitetanium.com

Before you start​

warning

The setup page can't take credentials for Tanium yet. Create the connection, then contact Huntbase support to finish signing it in.

Watch out for
  • If you leave Expiration empty, the token lasts 7 days. The maximum is 365 days by default.
  • After five minutes, or once you leave or refresh the page, the token value can no longer be viewed.
  • A token has the permissions of the account or persona it is bound to. Tanium recommends binding tokens to a service account.

For the vendor's own instructions, see Tanium API token documentation.

Connect Tanium​

  1. Go to Connections and click New connection, or click New connection on the Tanium product page.
  2. On Product, pick Tanium and choose the Owner.
  3. On Details, give the connection a Name and, optionally, a Description.
  4. On Connect, fill in the settings and credentials described below.
  5. On Verify, review the summary and click Create & check.

For everything else on the setup page — saving a draft, I'll do this later, and what each check result means — see Connections.

Settings​

Where your Tanium lives:

FieldRequiredNotes
Server AddressYesThe hostname of your Tanium instance.
PortYesSet the port number that is associated with the hostname or IP address. Defaults to 443.

Query it​

Once connected, Tanium can serve these languages in a query tab, and Scout can use it when you ask in Auto:

LanguageUse it for
STIXSTIX patterns for indicator sweeps, translated into the product's native search.

Next steps​