Incident Response requirements

Review the requirements before you install and use Incident Response.

Tanium dependencies

Component Requirement
Platform Version 6.5 or later.
Tanium Client All Tanium Client versions are supported.
License For information about licensing Incident Response, contact your Technical Account Manager (TAM). The license for Incident Response includes the following solutions:
  • Tanium Incident Response
  • Tanium IR Gatherer (IR Gatherer)
  • Tanium Quarantine (Quarantine)
  • Tanium Live Response (Live Response)
  • Tanium Index (Index)
  • Windows Security Patch Management (for more information, see Tanium Knowledge Base)
Tanium™ Trace Version 2.3.2.0004 or later is required for real-time events on Linux endpoints with Tanium Index 2.0.0 or later.

Third-party software requirements

For Tanium Incident Response, the required third-party software is installed automatically.

However, the IR Gatherer solution has third-party software requirements that are not installed automatically. The related documentation includes instructions to download the software and include it in packages that are distributed to the endpoints.

  • KnockKnock (optional)
  • OSX Collector (optional)

Endpoint hardware and software requirements

Disk space

If a solution is not listed, the required disk space is minimal.

IR solution Disk space
Index 1 GB free space

Supported endpoint operating systems

See the documentation for the IR solution for specific version numbers.

IR solution Windows Mac Linux
Incident Response X X X
IR Gatherer X X X
Copy tools X X X
Quarantine X X X
Index X X X
Live Response X    

Host and network security requirements

Specific ports and processes are needed to run Incident Response.

Ports

The following ports are required for IR communication.

IR Solution Port Direction Purpose
IR Gatherer 443, 22, 21, or 445 Outbound Outbound connections over ports depending on how the collected data is being transferred.
Live Response 443 (S3), 22 (SFTP/SCP), or 445 (SMB) Outbound Outbound connections over ports depending on how the collected data is being transferred.

Security exclusions

If security software is in use in the environment to monitor and block unknown host system processes, your security administrator must create exclusions to allow the Tanium processes to run without interference.

Target Device Process
Endpoint Computers
  • <Tanium Client>\Tools\EPI\TaniumEndpointIndex.exe
  • <Tanium Client>\Tools\EPI\TaniumExecWrapper.exe
  • <Tanium Client>\Tools\IR\handle.exe
  • <Tanium Client>\Tools\IR\listdlls.exe
  • <Tanium Client>\Tools\IR\TaniumHandle.exe
  • <Tanium Client>\Tools\IR\listdlls.exe
  • <Tanium Client>\Tools\IR\TaniumListModules.exe
  • <Tanium Client>\Tools\IR\powerforensics\powerforensics.dll
  • <Tanium Client>\Tools\IR\TaniumFileInfo.exe
  • <Tanium Client>\Tools\IR\TaniumExecWrapper.exe

Internet URLs

If security software is deployed in the environment to monitor and block unknown URLs, your security administrator must whitelist the following URL:

  • content.tanium.com

Console roles and privileges

Tanium 6.5 and 7.0

For Tanium Platform version 6.5 and 7.0, the following user roles are required:

  • Administrator - Incident Response and all solutions
  • Content administrator - Quarantine

Tanium 7.1 and later

In 7.1.314.3071 and later, you can use role-based access control (RBAC) permissions to restrict access to IR solution content sets. If a solution is not listed below, RBAC does not apply and the roles are the same as 7.0.

For more information, see the Tanium Core Platform User Guide: Users and user groups.

Table 1:   Incident Response Roles and Privileges for Tanium 7.1
Role Type Privilege
Incident Response Administrator‡*
  • Perform all functions within IR and configure IR.
Incident Response User*
  • Ask saved questions and view the results
  • Run IR sensors and view the results
  • View packages
Incident Response Read Only User*
  • Ask saved questions and view the results
  • Run IR sensors and view the results

‡ To install IR solutions, you must have the reserved role of Administrator.

* Requires permissions for the Interact module to ask questions, see results, and drill-down to endpoints.

Table 2:   Index Roles and Privileges for Tanium 7.1
Role Type Privilege
Index Administrator‡*
  • Perform all functions within Index and configure Index.

Index User*

  • Ask saved questions and view the results
  • Run Index sensors and view the results
  • View packages

Index Read Only User*

  • Ask saved questions and view the results
  • Run Index sensors and view the results

‡ To install IR solutions, you must have the reserved role of Administrator.

* Requires permissions for the Interact module to ask questions, see results, and drill-down to endpoints.

Last updated: 4/24/2018 3:54 PM | Feedback