Tanium EDR
Configure Tanium EDR integration with RAD Security for real-time endpoint visibility and response.
This guide walks you through integrating Tanium EDR with RAD Security for real-time endpoint visibility and threat response, enabling you to correlate endpoint security events with container and cloud runtime activity.
Tanium provides real-time endpoint data collection, threat detection, incident response, and compliance monitoring across your entire infrastructure.
Prerequisites
Before you begin, ensure you have:
- Admin access to Tanium Console
- Ability to create roles, personas, and users in Tanium
- A service account dedicated for integrations (recommended)
- Access to RAD Security workspace with integration permissions
Service Account Recommended: Use a dedicated service account for the integration rather than a personal account. This ensures continuity when team members change roles or leave.
Step 1: Access Tanium Console
Log in to Console
Log in to your Tanium Console with administrative privileges
Note Your Console URL
Save your Tanium Console URL as you'll need it for configuration
Example: https://your-company.cloud.tanium.com
Step 2: Create Custom Role with Minimal Permissions
Follow the principle of least privilege by creating a role with only the necessary permissions.
Navigate to Roles
Go to Administration > Permissions > Roles
Create New Role
Click to create a new role and provide:
- Role Name (e.g., "RAD Security Integration Role")
- Description (e.g., "Role for RAD Security API integration")
- Permission Type: Allow
Assign Gateway Permissions
In the Permissions table:
- Locate Gateway permissions
- Expand the section
- Select Execute permission for Gateway API
This permission is essential for the integration to function properly. Without Gateway API execute permissions, the integration will fail.
Assign Platform Content Permissions
In the Permissions table:
- Select Platform Content Permissions
- Check the Read option
- Click the icon with a number (n+) that appears
- Select the following Content Sets:
- Reserved
- Base
- Core Content
- Comply Reporting
These content sets provide access to the default sensors used for vulnerability checking and compliance monitoring.
Save Role
Click Save to create the role
Step 3: Create Persona with Custom Role
Personas in Tanium combine roles with computer group access to define the scope of access.
Navigate to Personas
Go to Administration > Permissions > Personas
Create New Persona
Click to create a new persona and provide:
- Persona Name (e.g., "RAD Security Integration Persona")
- Description (e.g., "Persona for RAD Security API access")
Assign Role
Assign the custom role you created in Step 2 to this persona
Configure Computer Groups
- Open the Computer Groups section
- Assign the computer groups whose endpoints you want RAD Security to ingest findings from (select All Computer Groups only if you need full coverage)
- Leave Management Rights unchecked — read-only visibility of the assigned groups is all the integration needs
RAD Security only reads EDR detection findings from Tanium; it never manages or takes action on endpoints. Do not grant Unrestricted Management Rights — read-only computer group visibility is sufficient. Scope to specific groups if you want to further limit which endpoints are ingested.
Assign Users
- Open the Users section
- Assign one or more users to this persona
Use a Service Account: Assign a dedicated service account rather than individual user accounts. This prevents disruptions when users leave or change roles.
Save Persona
Click Save to create the persona
Step 4: Generate API Token
Log in as Service Account
Log out and log back in using the service account you assigned to the persona in Step 3
Navigate to API Tokens
Go to Administration > Permissions > API Tokens
Create New API Token
Select the option to create a new API token
Configure Token Details
Provide the following information:
Notes:
- Add a description to identify the token's purpose (e.g., "RAD Security Integration")
Expiration Period:
- Recommended: 14 days for production
- Default: 7 days
- Maximum: 365 days
Shorter expiration periods enhance security by requiring regular token rotation. Set calendar reminders for token rotation.
Assign Persona
Assign the persona you created in Step 3 to set the scope and permissions for this token
Configure Trusted IP Addresses
Add trusted IP addresses that can use this token:
For Production:
- Add RAD Security IP addresses (provided by your RAD Security team)
For Testing/Sandbox:
- You can use
0.0.0.0/0for initial testing - Remove this before production deployment
Using 0.0.0.0/0 allows access from any IP address. Only use this for sandbox testing and never in production environments.
Generate Token
Click Create to generate the API token
Save Token Securely
Immediately copy and save the API token in a secure location
This is your only chance to view the token! You cannot retrieve it later. Store it in a password manager or secrets vault immediately.
Step 5: Configure in RAD Security
Navigate to your RAD Security workspace and configure the Tanium integration with the following parameters:
Required Parameters
| Parameter | Description | Example |
|---|---|---|
| Base URL | Your Tanium Console URL | https://your-company.cloud.tanium.com |
| Secret | The API token generated in Step 4 | your-api-token-here |
Verify Integration
After completing the setup, verify your integration is working:
- Navigate to Data Sources > Integrations > EDR in RAD Security
- Locate your Tanium integration
- Check the connection status shows as Connected
- Verify endpoint data is being synced
Your Tanium EDR integration is now configured! RAD Security can now correlate endpoint data with container and cloud runtime events.
What Data is Synced
Once configured, RAD Security will sync the following data from Tanium:
Default Sensors: RAD Security uses Tanium's default sensors for vulnerability checking. No additional sensor configuration is required.
Token Rotation
Regular token rotation is a security best practice. Follow these steps to rotate your API token:
Rotate Token in Tanium
- Go to Administration > Permissions > API Tokens
- Select your existing API token
- Use the Rotate feature
- Save the new token immediately
Update Token in RAD Security
- Navigate to your Tanium integration in RAD Security
- Update the token with the newly rotated value
- Verify the connection still works
Set Reminder
Set a calendar reminder for the next rotation based on your token's expiration period
Token rotation should be performed before the current token expires to avoid service interruptions.
Use Cases
Real-Time Visibility Get instant visibility into endpoint status and security posture across your entire infrastructure.
Vulnerability Management Correlate Tanium vulnerability data with runtime exploitation attempts detected by RAD Security.
Compliance Monitoring Track compliance posture and policy violations across endpoints and cloud workloads.
Incident Response Coordinate response actions across endpoints when threats are detected in containerized environments.
Troubleshooting
Security Best Practices
Use Service Accounts Always use dedicated service accounts for integrations, never personal accounts tied to individuals.
Least Privilege Access Only grant the minimum permissions required. Avoid using admin accounts for API integrations.
Rotate Tokens Regularly Set reasonable expiration periods (14-90 days) and rotate tokens before they expire.
Restrict IP Addresses
Only allow trusted IP addresses. Never use 0.0.0.0/0 in production environments.
Monitor API Usage Regularly review API token usage in Tanium to detect anomalous activity.
Secure Token Storage Store API tokens in a secure password manager or secrets vault. Never commit to version control.
Document Changes Maintain documentation of token creation, rotation, and role/persona changes.
Audit Regularly Periodically review personas, roles, and assigned users to ensure they're still appropriate.
Additional Resources
Tanium Authentication
Official guide to Tanium authentication methods
RBAC for Integrations
Learn about role-based access control for integrations
Sensor Inventory
Complete list of available Tanium sensors
Default Sensors
Documentation on default sensors for vulnerability detection
Developer Summit 2024
Watch "RBAC for Integrations" breakout session
Sensor Management
Guide to register or unregister sensors