Tanium Endpoint Management
Workflow capability for unified endpoint management and security operations using Tanium. Combines the Platform REST API, Threat Response API, and Connect API to enable endpoint visibility, action deployment, threat investigation, and data delivery automation. Designed for security operations teams, IT administrators, and incident responders who need real-time control across all managed endpoints.
What You Can Do
MCP Tools
ask-endpoint-question
Ask a natural language question to all Tanium-managed endpoints (e.g., 'Get Running Processes from all machines')
get-question-results
Get endpoint data results for a question by ID
list-saved-questions
List all saved questions configured for recurring endpoint data collection
get-saved-question-results
Get the latest collected results from a saved recurring question
deploy-package-to-endpoints
Deploy a package action to a targeted group of endpoints
list-packages
List all available deployment packages on the Tanium server
list-sensors
List all endpoint sensors available for data collection in questions
list-computer-groups
List all computer groups for endpoint targeting in actions and questions
list-threat-alerts
List threat alerts detected by Tanium Threat Response
start-endpoint-investigation
Start a live investigation connection to an endpoint for incident response
get-endpoint-events
Get Recorder events from an endpoint connection (process, network, file events)
get-process-tree
Get the full process ancestry tree for a suspicious process on an endpoint
list-data-connections
List all data delivery connections for exporting endpoint data to SIEM and other systems
create-data-connection
Create a data delivery connection to export Tanium endpoint data to a downstream system