The Tanium IOC Detect module must be configured to forward events.

From Tanium 6.5 Security Technical Implementation Guide

Part of SRG-APP-000115

Associated with: CCI-000158

SV-81543r1_rule The Tanium IOC Detect module must be configured to forward events.

Vulnerability discussion

Indicators of Compromise (IOC) is an artifact which is observed on the network or system that indicates computer intrusion. The Tanium IOC Detect module detects, manages, and analyzes systems against IOCs real-time. The module also responds to those detections.By forwarding events the IOC Detect module, using Tanium Connect with a syslog or SIEM connection, captures the necessary forensic evidence supporting a compromise is retained.

Check content

Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. Click on "IOC Detect". Along the right column of the interface, click on the “gear” icon. The “Workbench Settings” menu will be displayed. Click on the “wrench” icon under "Event Forwarding". If "Forwarding Target" is "Disabled", this is a finding.

Fix text

Using a web browser on a system that has connectivity to the Tanium Server, access the Tanium Server web user interface (UI) and log on with CAC. Click on "IOC Detect". Along the right column of the interface, click on the “gear” icon. The “Workbench Settings” menu will be displayed. Click on the “wrench” icon under "Event Forwarding". Configured the "Event Forwarding" to be configured for "Syslog". If a syslog is already configured under Tanium Connect, the value for "Event Forwarding" may be configured to "Tanium Connect". Click on "Save Changes".

Pro Tips

Lavender hyperlinks in small type off to the right (of CSS class id, if you view the page source) point to globally unique URIs for each document and item. Copy the link location and paste anywhere you need to talk unambiguously about these things.

You can obtain data about documents and items in other formats. Simply provide an HTTP header Accept: text/turtle or Accept: application/rdf+xml.

Powered by sagemincer