IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Release Notes IR Gatherer (Version 3.8)

From Tanium Knowledge Base
Jump to navigation Jump to search

Thank you for choosing Tanium. These notes are intended to document changes between releases of the Tanium Incident Response Gatherer module.

Tanium Incident Response Gatherer 3.8.4

Release Date Nov 27, 2018

Incident Response Gatherer Official Version 3.8.4.0001

Resolved Issues and Improvements

  • IR Gatherer actions now detach and execute as background processes, allowing for collections from endpoints that might exceed the typical action timeout (ex: dumping memory on a system with a large amount of RAM). The action will report as completed shortly after starting to execute, but IR Gatherer will continue to execute in the background.
  • IR Gatherer will not execute if another instance of IR Gatherer is already running on a endpoint.
  • Adds support for collecting memory from Windows 10 systems with and without Device Guard HyperVisor enforced Code Integrity. See compatibility notes, below.

Windows 10 Memory Collection Compatibility

It has been determined that memory dumping can lead to blue screen of death (BSOD) on Windows 10 systems that have Device Guard Hypervisor enforced Code Integrity (HVCI) running, but do not also have the September 2018 cumulative updates installed. BSOD's do not occur when Device Guard's HVCI is not running.

Windows 10 NOT running Device Guard HyperVisor enforced Code Integrity

Memory Collection is supported on all Windows 10 versions when Device Guard HVCI is not running.

Windows 10 running Device Guard HyperVisor enforced Code Integrity

For Windows 10 systems running Device Guard HVCI, memory collections will only be performed on Windows 10 versions meeting the following minimum requirements:

Windows 10 Release Id Required Update Build Revision Compatible Reference
1809 (and newer) N/A (Includes September '18 patches) Yes https://support.microsoft.com/en-us/help/4464619
1803 320+ Yes https://support.microsoft.com/en-us/help/4458469
1709 699+ (CurrentBuild 16299 only) Yes https://support.microsoft.com/en-us/help/4457136
1703 1358+ Yes https://support.microsoft.com/en-us/help/4457141
1607 2515+ Yes https://support.microsoft.com/en-us/help/4457127

New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x86
winpmem.gb414603.exe 3.1rc10 8bb120c8358e33fbd95a5726cbe88dee30ec7d25c7c9c256961653800fa28e44

Deprecated Content

  • No deprecated content in this release

Notes for future releases

  • Rekall Analysis will be deprecated in a future release and replaced with functionality in Live Response and IR Memory

Additional Information

Tanium Incident Response Gatherer 3.8.3

Release Date Oct 23, 2018

Incident Response Gatherer Official Version 3.8.3.0006

Resolved Issues

  • Fixes an issue that would cause SSH-based file transfers on Linux and OSX platforms to fail.

Security Update

  • This release includes security updates. Details of the issues, including affected versions and mitigation information, can be obtained within [1] Tanium's Support Portal or by contacting your TAM.

New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x86
TaniumExecWrapper.exe 3.6.18 32dc0ff75794f5321007bb6e21e4f358107b4082ec31dc9228f4f4ed39ac8810

Deprecated Content

  • No deprecated content in this release

Notes for future releases

  • Rekall Analysis will be deprecated in a future release and replaced with functionality in Live Response and IR Memory

Additional Information

Tanium Incident Response Gatherer 3.8.0

Release Date Sep 5, 2018

Incident Response Gatherer Official Version 3.8.0.0001

Resolved Issues

  • IR Gatherer will no longer execute winpmem for memory gathering on Windows 10 / Windows Server 2016 machines in order to prevent stop errors (Blue Screen) when collecting memory. Customers using IR Gatherer on Windows should move to Tanium Live Response.


Security Update

  • Because IR Gatherer uses Copy Tools 2.2.0 bundled in the Package to deliver results, this release includes security updates. Details of the issues, including affected versions and mitigation information, can be obtained within Tanium's Support Portal or by contacting your TAM.


New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x86
taniumfiletransfer.exe 1.1.13 23d8e982b39379621fce43b3636e3438dfc9860ad67f11fb9ea86ca482c92a71
Windows x64
taniumfiletransfer.exe 1.1.13 ca2a79b35cfa1ea9728111b1f9e35fa4406e93e034f8e73b47304a2d23dcf2fb

Removed Binaries

  • pscp.exe and psftp.exe are removed for Windows IR Gatherer.

Deprecated Content

  • No deprecated content in this release

Notes for future releases

  • Rekall Analysis will be deprecated in a future release and replaced with functionality in Live Response and IR Memory

Additional Information