SV-253802r997241_rule
V-253802
SRG-APP-000471
TANS-00-001600
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web UI and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
7. Resolve any open IOC-based alerts and change status to applicable status.
Note: If THR is not licensed or used for detection, this is not applicable.
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
If any alerts are unresolved, this is a finding.
V-253802
False
TANS-00-001600
Note: If THR is not licensed or used for detection, this is not applicable.
1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
If any alerts are unresolved, this is a finding.
M
5476