Tanium Security Operations relaunch adds AI threat hunting
Tanium has relaunched its Tanium Security Operations platform. The update adds behavior-based endpoint detection, a model for running several SOC teams on one platform, and an AI assistant that lets analysts hunt for threats using plain-language questions.
The company says the relaunch targets AI-assisted intrusions in which attackers avoid malware entirely. Instead, they use legitimate administrative tools to blend in with normal activity and move from one endpoint to the next.
When the attacker looks like IT
Tanium's argument is that AI has lowered the bar for attackers who don't need custom malware at all. An intruder can log in with stolen credentials and work with the same administrative tools that IT staff rely on every day. A security product that searches for known-malicious files sees nothing unusual in that activity.
