Tanium Security Operations relaunch adds AI threat hunting
Tanium has relaunched its Tanium Security Operations platform. The update adds behavior-based endpoint detection, a model for running several SOC teams on one platform, and an AI assistant that lets analysts hunt for threats using plain-language questions.
The company says the relaunch targets AI-assisted intrusions in which attackers avoid malware entirely. Instead, they use legitimate administrative tools to blend in with normal activity and move from one endpoint to the next.
When the attacker looks like IT
Tanium's argument is that AI has lowered the bar for attackers who don't need custom malware at all. An intruder can log in with stolen credentials and work with the same administrative tools that IT staff rely on every day. A security product that searches for known-malicious files sees nothing unusual in that activity.
To spot this kind of intrusion, defenders need a baseline of what normal behavior looks like on each machine, and they need to act across the whole estate as soon as something changes. Tanium already collects that kind of real-time endpoint data for IT management. Security Operations now points the same data at attackers. It is meant to work alongside existing SIEM (security information and event management) and EDR (endpoint detection and response) tools, not replace them.
"AI has changed who the attacker is and how fast they move. The next breach won't look like malware. It will look like one of your own administrators," said Harman Kaur, CTO at Tanium. "We have spent years learning what normal looks like on every endpoint our customers run. Now we use that to catch what doesn't belong and stop it everywhere at once."
With the relaunch, detection, response and hunting no longer pass from one tool to another. Tanium says they now run as a single continuous loop on one platform.
Behavior over signatures
Two new detection components sit at the center of the update. Endpoint Drift learns how each endpoint usually behaves and ranks the machines that are acting out of character, so hunters know where to start.
The Insights Engine replaces Tanium's earlier process injection detection. According to the company, it is built to catch attackers who hide inside trusted processes.
Response at fleet scale
Tanium argues that a single quarantine button is too blunt and too slow when an attack spreads across thousands of endpoints in minutes. The platform offers a range of actions that run directly on the endpoint, from killing one process or collecting forensic evidence to isolating a host. These can target a single machine or the entire fleet at once.
A new Federated SOC model lets separate security teams share one platform. Each team sets its own suppressions and automatic reactions, and one team's rules never apply to another team's endpoints. Humans define the guardrails, and automated actions stay within them.
Hunting in plain language
Tanium says most teams rarely hunt because it takes deep expertise and days of work. Its answer is Tanium Atlas. An analyst types a question in plain language, receives answers from every endpoint within seconds, and can act on the results from the same interface. Hunt strategies written by Tanium's own threat hunters guide each step.
Atlas also ranks the alert queue and recommends whether each alert should be dismissed, escalated, hunted or contained. New SecOps dashboards and templates give teams a starting point.
Dave Gruber, chief analyst at Omdia, said attack execution speeds "out pace current security operations mechanisms and processes." He added that agentic SOC capabilities "still lag attacker activities" without access to near real-time telemetry and response. He described Tanium's approach as addressing "one of the most persistent gaps in enterprise SOC architectures."
Managed hunting with HuntIQ
Organizations that want outside help can use Tanium HuntIQ, which pairs Tanium threat hunters with the same platform and AI. HuntIQ hunters work inside customer environments to find threats, improve detections and support incident response.
According to Tanium, they can build a hunt before a patch or CVE exists, as they did for the FalconFlank zero-day. Their findings feed back into the platform to improve later hunts.
Why It Matters
The relaunch fits a pattern our readers will recognize. Vendors keep warning that attackers are ahead of defenders in using AI, and abuse of legitimate admin tools is a common feature of recent incidents. Tanium is betting that defenders who already hold detailed endpoint data are better placed to spot "living off the land" activity than tools that rely mainly on file signatures.
The push toward agentic SOC tooling is crowded, though. Behavioral baselining has long struggled with noisy alerts, so it is worth watching whether Endpoint Drift's rankings hold up in large, messy environments. The Federated SOC model could matter to large organizations and service providers that run separate security teams. Finally, plain-language hunting suggests vendors want to make hunting accessible to less specialized analysts. It is too early to say how well AI recommendations will hold up once real attackers try to blend in.
