SV-254950r961728_rule
V-254950
SRG-APP-000471
TANS-AP-001250
CAT II
10
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
7. Resolve any open IOC-based alerts and change status to applicable status.
Note: If THR is not licensed or used for detection then this is not applicable.
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
If any alerts are unresolved, this is a finding.
V-254950
False
TANS-AP-001250
Note: If THR is not licensed or used for detection then this is not applicable.
1. Using a web browser on a system that has connectivity to the Tanium Application, access the Tanium Application web user interface (UI) and log on with multi-factor authentication.
2. Click "Modules" on the top navigation banner.
3. Click "Threat Response".
4. Expand the left menu.
5. Click "Alerts".
6. Filter on status "Unresolved".
If any alerts are unresolved, this is a finding.
M
5492