Tanium Security Triage Agent
Tanium Inc · Cybersecurity & IT
Certification per Microsoft Marketplace.
Evidence tier Source Confirmed · 6 captures on record
What the publisher says
As described on Microsoft Marketplace.
The Tanium Security Triage Agent supports the first-line SOC analyst by automating the initial triage of Tanium Threat Response alerts. Integrated directly into Microsoft Security Copilot, the agent assesses alert context, collects relevant endpoint telemetry in real time, and presents clear next steps so analysts can focus on decisions, not just data collection.
Agent Task: Ingests Tanium Threat Response alerts, automatically gathers contextually relevant endpoint telemetry, and produces an assessment that helps security analysts determine appropriate next steps.
Show the rest of the publisher’s description (8 more lines)
Agent workflow
Input: Receives Tanium Threat Response alerts and collects associated real-time endpoint telemetry, such as system state, configuration, performance metrics, and events using Tanium’s Autonomous IT Platform, eliminating the need for manual data gathering.
Output: Delivers a triage assessment inside Microsoft Security Copilot, including relevant endpoint telemetry and guidance on recommended investigative or response actions.
Driven by Tanium’s AI and real-time intelligence, the Tanium Security Triage Agent enables:
- Faster alert triage: Automates relevant telemetry collection for Threat Response alerts, reducing time spent gathering context and accelerating early investigation.
- Clear next-step guidance: Provides analysts with a concise assessment and recommended actions, helping teams move quickly from alert review to decision‑making.
- Simplified SOC workflows: Keeps triage activities inside Microsoft Security Copilot while leveraging Tanium’s AI and real‑time endpoint intelligence, reducing context switching and operational friction.
For more details about Tanium, head to https://www.tanium.com/contact-us/.
Preview
3 imagesAgent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Compliance
- FedRAMP AuthorizedConfirmed95%, domain-verifiedTanium Cloud for US Government (TC-USG) is FedRAMP Authorized at Moderate impact (domain match)FedRAMP Marketplaceregistry recordas observed 2026-08-27
Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.
Vendor
External enrichment
Plans and pricing as listed
1 listedSources
Publisher resources
6 linksLinked repositories
Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.




