SecurityBrief Asia - Technology news for CISOs & cybersecurity decision-makers
Asia
Tanium relaunches security platform to counter AI attacks

Tanium relaunches security platform to counter AI attacks

Wed, 7th Oct 2026 (Yesterday)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Tanium has relaunched its Security Operations platform to address attacks that use stolen credentials and standard administrative tools rather than malware.

The updated product combines detection, response and threat hunting in a single workflow built on endpoint data already used by IT teams. It is designed to work alongside existing security information and event management and endpoint detection and response products, not replace them.

The relaunch reflects a wider shift in cybersecurity as attackers rely less on malicious files and more on legitimate tools already present on corporate machines. That can make intrusions harder to spot because the activity may resemble routine work by internal administrators.

One new element, Endpoint Drift, is intended to identify devices behaving outside their normal pattern. Another, Insights Engine, is designed to detect attackers operating inside trusted processes, replacing Tanium's previous process injection detection approach.

Response functions have also been expanded so security teams can take action across large numbers of devices. Those actions include stopping a process, gathering forensic evidence and isolating a host on individual machines or across a wider estate.

Tanium has also introduced what it calls a Federated SOC model. Under that setup, separate security teams can use the same platform while maintaining different suppression rules and automated response settings for their own environments.

Another part of the relaunch focuses on threat hunting, an area often limited to experienced analysts because of the time and skill involved. Tanium said its Atlas tool allows analysts to ask questions in plain language, receive answers from endpoints in seconds and take follow-up action from the same interface.

Atlas also prioritises alerts and suggests whether each should be dismissed, escalated, investigated through a hunt or contained. Tanium has added security operations dashboards and templates intended to give teams a starting point for these workflows.

Harman Kaur, Chief Technology Officer, Tanium, said the changes were a response to the way artificial intelligence is reshaping attacker behaviour. "AI has changed who the attacker is and how fast they move. The next breach won't look like malware. It will look like one of your own administrators," Kaur said.

She added: "We have spent years learning what normal looks like on every endpoint our customers run. Now we use that to catch what doesn't belong and stop it everywhere at once. That is what security operations has to become in the AI era."

Market shift

Tanium argues that many established security tools were built to identify known malicious files or signatures, while newer attacks may begin with a valid login and spread using built-in administration tools. In response, vendors are placing more emphasis on behaviour-based detection and rapid response tied to live endpoint telemetry.

That shift has also driven greater interest in automation inside security operations centres, particularly as teams face large alert volumes and pressure to respond more quickly. Tanium is positioning its updated platform around that demand while stressing that automated actions remain governed by user-defined rules.

External analysts broadly share the view that the operational tempo of attacks has increased. Dave Gruber, Chief Analyst, Omdia, said, "The AI-fueled threat landscape has changed the dynamics of security operations."

He continued: "Speed is more important than ever before, as attack execution speeds out pace current security operations mechanisms and processes. Agentic capabilities can speed detection and response, but without access to near real-time telemetry and response, agentic SOC capabilities still lag attacker activities. Tanium's approach of grounding detection and hunting in real-time endpoint state addresses one of the most persistent gaps in enterprise SOC architectures."

Services link

Alongside the platform update, Tanium is also highlighting HuntIQ, a service that pairs its threat hunters with customer environments. The company said those specialists use the same platform and artificial intelligence tools to search for threats, improve detections and support incident response.

Tanium said lessons from that work are fed back into the product, including hunts created before a patch or common vulnerability and exposure reference is available. It cited its response to the FalconFlank zero-day as an example of that model.

The relaunch underlines how endpoint-focused vendors are trying to move beyond device management and traditional detection by tying together visibility, investigation and remediation. For security teams, the key test will be whether those integrated workflows reduce response times without adding to the operational burden of already crowded toolsets.

The updated Security Operations offering is available now.