https://catalogartifact.azureedge.net/publicartifacts/taniuminc1646329360287.incident_scoping_agent-404e461c-d998-41b0-998a-193d675c36fc/image2_TaniumLogo.png

Incident Scoping Agent (Preview)

firmy Tanium Inc

Scope Defender incidents across the enterprise to identify affected entities in real-time.

The Tanium Incident Scoping Agent automates enterprise-wide scoping for Microsoft Defender incidents by bridging detection and investigation. Integrated directly into Microsoft Security Copilot, the Tanium agent uses real-time intelligence from the Tanium Autonomous IT Platform to confirm impacted endpoints across the enterprise.

Agent Task: Ingest entities from a Microsoft Defender incident - files, processes, registry keys, IP addresses, and domains - and identify which are notable or unusual, prioritizing what matters for investigation.


Agent workflow

Input: Scopes each notable entity included in a Microsoft Defender incident across the entire endpoint environment using Tanium real-time intelligence, identifying additional impacted devices, users, and processes that Microsoft Defender might not have surfaced.

Output: Generates a clear scoping report with hashes, paths, users, and parent processes, so analysts have the full view across the environment.

Powered by Tanium's real-time intelligence, the Tanium Incident Scoping Agent enables:

  • Reduced mean time to investigate: Automates the manual KQL queries and console hopping analysts perform on every incident, delivering enterprise-wide results to analysts in near real time.
  • Assurance before containment: Gives analysts the full picture before they act, and the peace of mind to know that every file, process, and network artifact has been checked across the estate.
  • Entity-level intelligence: Provides prevalence and variation data - hashes, paths, parent processes, and users - so analysts can distinguish common artifacts from potential threats.

For more details about Tanium, go to https://www.tanium.com/contact-us/.

Disclaimer:

Your Private Preview of the Service includes Tanium confidential and/or proprietary information and Beta software (“Preview Software”). Because Preview Software can be at various stages of development, operation and use of the Preview Software may be unpredictable. As part of the Private Preview you acknowledge and agree that: (a) Preview Software has not been fully tested; (b) use of Preview Software will be for purposes of evaluating and testing new functionality and providing Feedback to Tanium; and (c) you will inform personnel regarding the nature of the Preview Software.

Tanium’s statements regarding its plans, directions, and intent are subject to change without notice at Tanium’s sole discretion. Information regarding potential future products or functionality is intended to outline our general product direction and it should not be relied on in making a purchasing decision, nor is it incorporated into any contract. It is not a commitment, promise, or legal obligation. The development, release, and timing of any future products or functionality remain at our sole discretion.

W skrócie

https://catalogartifact.azureedge.net/publicartifacts/taniuminc1646329360287.incident_scoping_agent-404e461c-d998-41b0-998a-193d675c36fc/image1_Screenshotfinal2.png