Top Banner
Remediate Security Incidents Faster With Live Endpoint Data
11

Remediate Security Incidents Faster With Live Endpoint Data

Jan 21, 2018

Download

Technology

ServiceNow
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Remediate Security Incidents Faster With Live Endpoint Data

Remediate Security Incidents Faster With Live Endpoint Data

Page 2: Remediate Security Incidents Faster With Live Endpoint Data

How Tanium Works

what is happening on your endpoints at

all times

ASKa question in plain English

KNOW ACTtake action by identifying

the incident and then then remediate

Deploy a Patch

In 15 Seconds

What are the computer names and running processes with MD5 hashes from all machines ?

Kill a Process

Uninstall an ApplicationGoogle for IT Data

Quarantine Endpoint

Page 3: Remediate Security Incidents Faster With Live Endpoint Data

TheTaniumArchitecture

• Patented communications architecture

• Single agent and infrastructure

• Response times measured in seconds

• Visibility and control on-premises and off

Page 4: Remediate Security Incidents Faster With Live Endpoint Data

Tanium “Connect” Sources and Destinations

4

Connect Data Sources Tanium Connect Destinations• Action History• Audit Log• Event• Question Log

• Reputation Services• Email• SIEMs• Syslog• Databases• File (json, txt, csv)• HTTP for REST API• Reputation Service• Socket Receiver

• Reputation Service• Saved Question• Server Information• System Status

Page 5: Remediate Security Incidents Faster With Live Endpoint Data

Three Example Use Cases…

• Monitor and alert on system status thresholds

• Monitor and alert on new account creation activity

• Monitor and alert on malicious processes

• There is a lot more use cases we can discuss after the presentation.

Page 6: Remediate Security Incidents Faster With Live Endpoint Data

6

Automating Ticket creation – CPU Utilization?

xxxxx.service-now.com

Page 7: Remediate Security Incidents Faster With Live Endpoint Data

Automating Ticket creation – local Admin account?

7

xxxxx.service-now.com

Page 8: Remediate Security Incidents Faster With Live Endpoint Data

ServiceNow workflows can automatically call Tanium

8

Page 9: Remediate Security Incidents Faster With Live Endpoint Data

9

Page 10: Remediate Security Incidents Faster With Live Endpoint Data

10

Page 11: Remediate Security Incidents Faster With Live Endpoint Data

Thank You!

For more information stop at booth #1108