| | |

The Global Hunt (Tanium)

Goal: Use a “Fingerprint” (MD5 Hash) to see if a file is on any computer in the company.

  1. Open Tanium Interact: Click the nine-dot menu and select Interact.
  2. The Search Bar: Use the big bar in the middle that says “Ask a Question.”
  3. Type the Command: Get Index Query File Details contains [PASTE_YOUR_HASH]
  4. The “Enhanced” Link: Look below the bar for the words that say “Use enhanced search…” and click that link. 5. The Launch: Click the blue Ask Question button.
  5. The Result: Wait for the blue bar to finish.
    • High Count (Lots of hits): The file is a common company tool.
    • Low Count (1 or 2 hits): The file is rare and needs a closer look.

The “Checklist”

  • [ ] Did I find the computer name?
  • [ ] Did I find the file path?
  • [ ] Did I check if it’s on 1 machine or 1,000 machines?

Similar Posts