Urgent.News

What's breaking now, across thousands of outlets.

Tech

Tanium expands Security Operations with Atlas-powered detection, response and hunting

Endpoint management and security company Tanium Inc. today expanded its Security Operations portfolio with new detection, response and threat-hunting tools built on its Tanium Atlas agentic artificial intelligence platform. The release is Tanium’s attempt to move customers closer to what it calls a self-driving security operations center. In that model, software agents work through investigation…

Tanium expands Security Operations with Atlas-powered detection, response and hunting

Endpoint management and security company Tanium Inc. has unveiled new tools for Security Operations, leveraging its Tanium Atlas agentic artificial intelligence platform. Tanium aims to enable a self-driving security operations center, where software agents perform investigations and responses autonomously, within pre-defined limits.

Analysts typically rely on alerts that are sometimes hours old after being pulled from logs into a security information and event management platform. Tanium's new tools aim to streamline this process, delivering live queries directly to endpoints.

The company has launched detection, response, and threat-hunting features built on Tanium Atlas. Endpoint Drift compares a device's current behavior to its historical baseline, surfacing anomalies. The Insights Engine utilizes advanced in-memory techniques, enabling focused hunting and ranking suspicious activities across a fleet.

Response actions are executed directly on the endpoint, such as quarantining a host or retrieving forensic evidence. A Federated SOC architecture allows separate teams to work independently on the same platform.

Tanium's Windows quarantine has been rebuilt to support agent-initiated actions. Atlas handles hunting and triage, with Alert Prioritization and Triage sorting alerts by priority and suggesting next steps. Historical records are checked against live endpoint data when validating alerts or tracing incident root causes. Google's Threat Intelligence service and reputation data from five third-party providers are integrated into the investigation and hunting workflows to minimize false positives.

Analysts can now move directly from investigation to remediation without switching platforms. Tanium's CTO, Harman Kaur, emphasized that security teams don't need additional tools that generate more alerts. Instead, they require accurate real-time endpoint visibility and the ability to act before an attacker does. Customers can transition from investigation to remediation within Tanium, while those seeking more guidance can utilize Tanium's expert-led threat-hunting service, HuntIQ, where analysts work alongside Atlas agents in customer environments, feeding back findings to enhance detections. These Security Operations enhancements are now available.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in Tech

More from Tuesday 6 October →