STIGQter STIGQter: STIG Summary: Tanium 7.x Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Tanium applications must be configured to filter audit records for events of interest based on organization-defined criteria.

DISA Rule

SV-253844r997268_rule

Vulnerability Number

V-253844

Group Title

SRG-APP-000115

Rule Version

TANS-SV-000010

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web UI and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Expand the left menu.

5. Click "Connections".

6. Click "Create Connection" or if importing, click "Import".

7. Give the "Connection" a name and description.

8. In the "Configuration" section, select "Event" as the source.

9. Select appropriate source under "Event Group" - any source to generate interest-based events (Discover, Asset, IM, THR, etc).

10. Select the appropriate events to send.

Note: Consult with the Tanium system administrator for the Destination.

11. Select "Listen for this Event".

12. Click "Save".

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Click "Connections" under "Connections" section.

5. Filter by source and review event-based sources.

If any event=based sources have a failed run for more than 72 hours, this is a finding.

Vulnerability Number

V-253844

Documentable

False

Rule Version

TANS-SV-000010

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium application, access the Tanium application web user interface (UI) and log on with multifactor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Connect".

4. Click "Connections" under "Connections" section.

5. Filter by source and review event-based sources.

If any event=based sources have a failed run for more than 72 hours, this is a finding.

Check Content Reference

M

Target Key

5476