Back to the registry
Agent passport

Incident Scoping Agent (Preview)

Tanium Inc · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

Tanium Threat ResponseReal-time Endpoint Data Microsoft Security Copilot and Microsoft Entra ID and Microsoft Defender
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 8 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

The Tanium Incident Scoping Agent automates enterprise-wide scoping for Microsoft Defender incidents by bridging detection and investigation. Integrated directly into Microsoft Security Copilot, the Tanium agent uses real-time intelligence from the Tanium Autonomous IT Platform to confirm impacted endpoints across the enterprise.

Agent Task: Ingest entities from a Microsoft Defender incident - files, processes, registry keys, IP addresses, and domains - and identify which are notable or unusual, prioritizing what matters for investigation.

Show the rest of the publisher’s description (10 more lines)

Agent workflow

Input: Scopes each notable entity included in a Microsoft Defender incident across the entire endpoint environment using Tanium real-time intelligence, identifying additional impacted devices, users, and processes that Microsoft Defender might not have surfaced.

Output: Generates a clear scoping report with hashes, paths, users, and parent processes, so analysts have the full view across the environment.

Powered by Tanium's real-time intelligence, the Tanium Incident Scoping Agent enables:

  • Reduced mean time to investigate: Automates the manual KQL queries and console hopping analysts perform on every incident, delivering enterprise-wide results to analysts in near real time.
  • Assurance before containment: Gives analysts the full picture before they act, and the peace of mind to know that every file, process, and network artifact has been checked across the estate.
  • Entity-level intelligence: Provides prevalence and variation data - hashes, paths, parent processes, and users - so analysts can distinguish common artifacts from potential threats. For more details about Tanium, go to https://www.tanium.com/contact-us/.

Disclaimer:

Your Private Preview of the Service includes Tanium confidential and/or proprietary information and Beta software (“Preview Software”). Because Preview Software can be at various stages of development, operation and use of the Preview Software may be unpredictable. As part of the Private Preview you acknowledge and agree that: (a) Preview Software has not been fully tested; (b) use of Preview Software will be for purposes of evaluating and testing new functionality and providing Feedback to Tanium; and (c) you will inform personnel regarding the nature of the Preview Software.

Tanium’s statements regarding its plans, directions, and intent are subject to change without notice at Tanium’s sole discretion. Information regarding potential future products or functionality is intended to outline our general product direction and it should not be relied on in making a purchasing decision, nor is it incorporated into any contract. It is not a commitment, promise, or legal obligation. The development, release, and timing of any future products or functionality remain at our sole discretion.

Preview

1 image
Incident Scoping Agent (Preview) preview 1

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMP AuthorizedConfirmed95%, domain-verifiedTanium Cloud for US Government (TC-USG) is FedRAMP Authorized at Moderate impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Vendor

External enrichment

CompanyTaniumAutomated

Plans and pricing as listed

1 listed
Tanium Incident Scoping Agent
$0.00/month
1-month subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource
License TermsLicense TermsSource

Publisher resources

5 links
Supportwww.tanium.comSource
User Guidehelp.tanium.comSource
Tanium Platformwww.tanium.comSource
Tanium Solutionswww.tanium.comSource
Tanium Microsoft Spotlightwww.tanium.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.tanium.com/contact-us/
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.