Tanium Inc Cloud
Effective for Configuration Management with Room for Improvement
Endpoint monitoring has strengthened incident response and provides rapid isolation and forensics
What is our primary use case?
Implementation is based on client requirement and we don't create any particular policies or any rules among all the networks. The decision is completely based on client-side requirement. Analytics are also completely based on client requirement. To the end users, everything is completely provided by the client. We don't know exactly what they have invested in the particular tool or the subscription value. However, I can suggest that it plays a main role while any high alert is going on and it should be present in any endpoint or any user's machine within enterprise-level security patches.
What is most valuable?
Tanium provides an endpoint which is isolated from the network and environment. We can easily search its logs and history and connect remotely directly to that particular device which has been isolated from the network. We can search for the history and logs, including audit logs and event logs. The complete activity of the user or owner of the device is visible to us. We can see the artifacts of particular USB transfers internally for official use.
We can not only connect remotely but also see the device status and how many failures have occurred within the network so far. We can see the IP address, how many times it has changed its IP address, and how many times it was connected to VPN or external VPN or internal VPN and what has been searched while on VPN. We can block the IOCs or IP addresses as well. We can block domains, hashes, SHA values, SHA-256, SHA-1, SHA-5 and MD5.
Although I am not completely involved in the automation team, we do have that team and I have worked in some CERT recently. Tanium is more useful while we are in the CERT because most of the times when we are on high alert, Tanium does play a main role for that particular incident or any high case. Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection and the tool should be present in the particular device. It is completely mandatory and it is in the policy as well.
What needs improvement?
In my opinion, sometimes it takes a long time to give solutions or resolve the issue. Tanium side team will respond instantly but sometimes they are delaying in the response. These are the two major causes which I have observed so far. Additionally, while remotely connecting, sometimes it automatically disconnects and the issue is still unresolvable. We are working on that, but it is still a question mark.
For how long have I used the solution?
I have four years of experience in cybersecurity and I have experience with Tanium for around two years.
Which solution did I use previously and why did I switch?
I am not using Sophos products like Cloud Optix or Sophos Labs. Previously, I worked in one organization which used Sophos Firewall Endpoint and XDR, and SecurOn as well. However, I have joined a new organization and they are not using either SecurOn or Sophos.
How was the initial setup?
It is completely simple and no need for any tension while installing it.
What was our ROI?
Tanium is a simple tool and we can easily integrate it to many devices and it is a mandatory tool to secure an endpoint. It is mandatory to give any RDP connection.
What's my experience with pricing, setup cost, and licensing?
It is moderate. It is not that much too costly or really that much low cost, but it is moderate.
Which other solutions did I evaluate?
Splunk or CrowdStrike are competitors for Tanium right now. However, Tanium is still at the top.
What other advice do I have?
We are not reselling Tanium but we are taking services from them. Implementation is based on client requirement. The review rating for this product is nine out of ten.
Real-Time Endpoint Visibility and Powerful Automation in One Platform
Simplifies Security with Real-Time Visibility
Real-Time Endpoint Management, Seamless Setup
Lightning-Fast Endpoint Queries with Powerful Custom Automation
The appeal of their platform is how they pull this off. Being able to live-query or execute across 10,000 endpoints in 30 seconds is pretty awesome.
I tend to skip a lot of the out-of-the-box stuff, because it’s almost never designed for anyone’s specific use case. For me, the real benefit is the platform itself and the custom content you can build on top of it.
Sensors are custom-designed scripts to gather whatever data you want, in whatever two-dimensional way you want. Packages let you deploy scripts to make changes to systems, whether that’s uninstalling, installing, changing reg keys, updating group policy, etc. Automate lets you chain sensors and packages together for more advanced routines—think downtime procedures, or a series of if/then/else steps.
The biggest benefit for me has been using it to answer C-suite questions immediately. They ask something, I write a short sensor script, push it out, and I instantly have an answer. From there, I can chain it into a package to fix the underlying problem, and then schedule that sensor and package to run automatically. In an afternoon, it becomes something I don’t have to worry about again.
If you get caught up in all the frills and extra stuff they layer on top, you might be disappointed—unless what they built happens to match your exact use case. But if you think of it mainly in terms of those three (really just two) core pieces, and you have people you can dedicate to learning and using it well, it’s a great tool.
Besides that, it depends what modules your new company owns. Modules are add-ons you can purchase from Tanium. One does patching. Another scans for vulnerabilities. Another does file integrity monitoring. So it's a fairly wide range of possibilities.
We run Tanium alongside our anti-virus solution. Tanium provides documentation on the exclusions. They also provide free training.
Real-Time Monitoring Enhances IT Efficiency
Streamlined Workflows and Effortless Third-Party Integrations
Real-Time Endpoint Visibility and Control at Scale with Tanium
For me, the biggest benefit is that it helps identify issues quickly, deploy updates faster, and reduce manual effort. This improves operational efficiency, strengthens security, and allows problems to be resolved before they have a major impact on users or business operations.
One Console for Endpoint Security and Asset Visibility
1. Lack of Endpoint Visibility
Many organizations struggle to know:
How many endpoints they actually have.
Which devices are online or offline.
What software is installed.
Which devices are missing security updates.
Tanium solves this by providing near real-time inventory and visibility across all endpoints from a single console.
2. Slow Incident Response
Traditional tools may take hours or even days to collect endpoint information during a security investigation.
Tanium allows security teams to query all endpoints within seconds or minutes, enabling them to quickly answer questions such as:
Which machines have a specific malicious file?
Which devices are running a vulnerable version of software?
Which users logged into an affected machine?