SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Tanium relaunches Security Operations to counter AI attacks

Tanium relaunches Security Operations to counter AI attacks

Fri, 9th Oct 2026 (Today)
Mara Sugue
MARA SUGUE News Editor

Tanium has relaunched its Security Operations product, positioning the update to address attacks shaped by artificial intelligence.

The relaunch focuses on combining detection, response and threat hunting in a single workflow tied to endpoint data already used by IT teams. The product is designed to work alongside existing security information and event management and endpoint detection and response tools, rather than replace them.

Tanium argues that attackers are increasingly using stolen credentials and common administrative tools instead of malware, making them harder to detect with systems focused on known malicious files. In response, the updated product looks for unusual behaviour on devices and lets security teams take action across large numbers of endpoints from the same platform.

Among the additions is Endpoint Drift, which learns how individual endpoints normally behave and flags machines operating outside those patterns. Tanium also introduced an Insights Engine, replacing its previous process injection detection approach with a system intended to identify attackers hiding inside trusted processes.

On the response side, analysts can stop a single process, collect forensic evidence or isolate a host on one machine or across a wider estate. Tanium also introduced a Federated SOC model that allows separate security teams to use one platform while keeping their own suppression settings and automated response rules separate.

Hunting focus

Another part of the relaunch is Tanium Atlas, which is intended to broaden access to threat hunting beyond specialist teams. Analysts can submit questions in plain language, receive answers from endpoints in seconds and take action within the same interface.

Hunt strategies created by Tanium's own threat hunters are built into the workflow. Atlas can also rank alerts and recommend whether analysts should dismiss, escalate, investigate further or contain them, while new dashboards and templates are intended to give teams a starting point.

"AI has changed who the attacker is and how fast they move. The next breach won't look like malware. It will look like one of your own administrators," said Harman Kaur, Chief Technology Officer at Tanium.

"We have spent years learning what normal looks like on every endpoint our customers run. Now we use that to catch what doesn't belong and stop it everywhere at once. That is what security operations has to become in the AI era," Kaur said.

Tanium is also offering HuntIQ, a service that pairs Tanium threat hunters with the same platform and artificial intelligence tools used in the product. According to the company, those teams work inside customer environments to identify threats, refine detections and support incident response.

HuntIQ teams can also build hunts before a patch or common vulnerabilities and exposures entry exists. Tanium cited FalconFlank as an example of a zero-day case in which this approach had been used.

Market pressure

The relaunch comes as security vendors adapt products to address attacks that unfold more quickly and often rely on legitimate tools already present in enterprise environments. That shift has increased the emphasis on near real-time visibility at the endpoint and faster action once suspicious behaviour is identified.

Dave Gruber, Chief Analyst at Omdia, said the speed of modern attacks is exposing the limits of many current security operations processes.

"The AI-fueled threat landscape has changed the dynamics of security operations," said Dave Gruber, Chief Analyst at Omdia. "Speed is more important than ever before, as attack execution speeds outpace current security operations mechanisms and processes. Agentic capabilities can speed detection and response, but without access to near real-time telemetry and response, agentic SOC capabilities still lag attacker activities. Tanium's approach of grounding detection and hunting in real-time endpoint state addresses one of the most persistent gaps in enterprise SOC architectures."

Tanium said the updated Security Operations offering is available now, tying the relaunch to a broader strategy that links endpoint management and security operations through the same underlying platform and data.