STIGQter STIGQter: STIG Summary: Tanium 7.x Application on TanOS Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 02 Apr 2025:

The ability to uninstall the Tanium Client service must be disabled on all managed clients.

DISA Rule

SV-254931r961317_rule

Vulnerability Number

V-254931

Group Title

SRG-APP-000328

Rule Version

TANS-AP-000805

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Modules" on the top navigation banner.

3. Click "Interact".

4. In the "Categories" section, select "Client Service Hardening".

5. In "Dashboard" section, select "Hide From Add-Remove Program".

6. The results will show a "Count" of clients matching the "Tanium Client Visible in Add-Remove Programs" query.

7. Select the result line.

8. Choose "Deploy Action".

9. The "Deploy Action" dialog box will display "Client Service Hardening - Hide Client from Add-Remove Programs" as the package. The computer names comprising the "count" of noncompliant systems will be displayed in the bottom.

10. Deployment Package drop-down select "Client Service Hardening - Hide Client from Add-Remove Programs".

11. Configure the schedule to repeat at least every hour for the requested action.

12. Under "Targeting Criteria", in the "Action Group," select "All Computers" from the drop-down.

13. Click "Show preview to continue". Noncompliant systems will be displayed in the bottom.

14. Click "Deploy Action".

15. Verify settings.

16. Click "Show Client Status Details".

Check Contents

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under Actions, select "Scheduled Actions".

4. Look for a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs".

5. If a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs" does not exist, this is a finding.

If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.

If the scheduled action exists and has been approved but does not disable the visibility of the client in Add-Remove Programs, this is a finding.

If the action is not configured to repeat at least every hour, this is a finding.

If the scheduled action is not targeted at an "All Computers" Action Group, this is a finding.

Vulnerability Number

V-254931

Documentable

False

Rule Version

TANS-AP-000805

Severity Override Guidance

1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.

2. Click "Administration" on the top navigation banner.

3. Under Actions, select "Scheduled Actions".

4. Look for a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs".

5. If a scheduled action titled "Client Service Hardening - Hide Client from Add-Remove Programs" does not exist, this is a finding.

If the scheduled action exists, select it and if it is not approved (the "Approve" button at the top of the section will be displayed if not approved), this is a finding.

If the scheduled action exists and has been approved but does not disable the visibility of the client in Add-Remove Programs, this is a finding.

If the action is not configured to repeat at least every hour, this is a finding.

If the scheduled action is not targeted at an "All Computers" Action Group, this is a finding.

Check Content Reference

M

Target Key

5492