Exporting reputation data

View reputation data

To view a list of the malicious hashes that Reputation has pulled from the reputation services, click Malicious Reputations from the Reputation menu.
Only hashes with a malicious or pending status are listed.

In Trace, you can view the ratings on hashes for Live Endpoints or Snapshots. For more information, see Tanium Trace User Guide: How reputation data works with Trace.

Send data to Connect destinations

You can use Connect 4.11 or later to create a connection to send the data that is in the reputation database to any Connect destination. For example, you might configure a connection to create an email notification when a malicious item is found.

  1. From the Connect menu, click Connections.
  2. Click Create Connection > Create to create a new connection.
  3. When you select a source for the connection, select Tanium Reputation.
    You can also select the reputation status to include.
  4. Configure the destination settings for the connection.

The first run of a connection that uses Tanium Reputation as a source retrieves all available reputation items. Subsequent runs of that connection retrieve only the reputation changes since the last time the connection ran.

For more information, see Tanium Connect User Guide: Managing connections.

Send data to the reputation service

If you want to pre-populate reputation data with hashes from your environment, you can send data to the reputation service as a connection destination. When this content is pre-populated, the reputation service can start querying about the status of the items from the reputation sources.

  1. From the Connect menu, click Connections.
  2. Click Create Connection > Create to create a new connection.
  3. For the source, choose a saved question that returns a hash, such as Running Processes with MD5 Hash.
  4. For the destination, choose Tanium Reputation and select the appropriate hash type for the Hash Field.

Each reputation service connection destination is configured for a specific hash column name. You must use a separate destination for each hash type that you are populating. For example, if you are populating both MD5 and SHA1 hashes from different saved questions, create two connection destinations with different values for the Hash Field field.

Send data to Trends boards

You can use Trends 2.4 or later to import a board that contains different panels of reputation metrics.

  1. From the Trends menu, click Boards and then click Import > Gallery.
  2. Select Reputation Service Metrics and then select which sections or panels you want to import.
    By default, everything is selected.
  3. Click Validate.

    If you see a warning about missing content sets, select Reputation.

  4. Click Import.

For more information, see Tanium Trends User Guide: Importing the initial gallery.

Last updated: 11/5/2019 4:16 PM | Feedback