Tanium · Capability
Tanium Threat Response API — Evidence
Tanium Threat Response API — Evidence. 5 operations. Lead operation: List Investigation Evidence. Self-contained Naftiko capability covering one Tanium business surface.
What You Can Do
GET
Listevidence
— List Investigation Evidence
/v1/plugin/products/threat-response/api/v1/evidence
POST
Createevidence
— Create Evidence From A Process
/v1/plugin/products/threat-response/api/v1/evidence
GET
Getevidenceproperties
— Get Evidence Properties
/v1/plugin/products/threat-response/api/v1/evidence/properties
GET
Getevidence
— Get Evidence By ID
/v1/plugin/products/threat-response/api/v1/evidence/{evidenceid}
DELETE
Deleteevidence
— Delete Evidence
/v1/plugin/products/threat-response/api/v1/evidence/{evidenceid}
MCP Tools
list-investigation-evidence
List Investigation Evidence
read-only
idempotent
create-evidence-process
Create Evidence From A Process
get-evidence-properties
Get Evidence Properties
read-only
idempotent
get-evidence-id
Get Evidence By ID
read-only
idempotent
delete-evidence
Delete Evidence
idempotent