The Global Hunt (Tanium)
Goal: Use a “Fingerprint” (MD5 Hash) to see if a file is on any computer in the company.
- Open Tanium Interact: Click the nine-dot menu and select Interact.
- The Search Bar: Use the big bar in the middle that says “Ask a Question.”
- Type the Command:
Get Index Query File Details contains [PASTE_YOUR_HASH] - The “Enhanced” Link: Look below the bar for the words that say “Use enhanced search…” and click that link. 5. The Launch: Click the blue Ask Question button.
- The Result: Wait for the blue bar to finish.
- High Count (Lots of hits): The file is a common company tool.
- Low Count (1 or 2 hits): The file is rare and needs a closer look.
The “Checklist”
- [ ] Did I find the computer name?
- [ ] Did I find the file path?
- [ ] Did I check if it’s on 1 machine or 1,000 machines?