Tanium Threat Response
The Tanium Threat Response integration for ThreatConnect enables users to send indicators and signatures to Tanium Threat Response as intel packages. The following Playbooks apps are available for this integration:
- Tanium Threat Response – Indicators
- This app enables users to send address, host, and file indicators from ThreatConnect to their Tanium Threat Response instance as intel packages based on specified criteria. This functionality allows users to operationalize intelligence from ThreatConnect in the form of searching and monitoring for malicious indicators in their endpoint environment
- Tanium Threat Response – Signatures
- This app enables ThreatConnect customers to send signatures from ThreatConnect to their Tanium Threat Response instance as intel packages based on specified criteria. This functionality allows users to operationalize intelligence from ThreatConnect in the form of signature-based searching and monitoring for malicious activity in their endpoint environment.
- Tanium Threat Response
- Deploy Indicator Intel Package
- Deploy Signature Intel Package
- Delete Intel Package
These apps can be found in the ThreatConnect App Catalog under the names: Tanium Threat Response – Indicators, Tanium Threat Response – Signatures, and Tanium Threat Response
