IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.

Release Notes Incident Response (Version 4.5)

From Tanium Knowledge Base
Jump to navigation Jump to search

Thank you for choosing Tanium. These notes are intended to document changes between releases of the Tanium Incident Response module.

Tanium Incident Response 4.5.6

Release Date April 23, 2019

Incident Response Official Version 4.5.6.0002

Resolved Issues and Improvements

  • Fixes issue where Live Response Standard Collection may cause blue screen of death (BSOD) when endpoint has Symantec Endpoint Encryption (SEE) enabled.
  • Fixes Mac Running Process with SHA256 Hash sensor output.

Notes for Future Releases

  • The next release of Incident Response will be 5.X and 4.X will no longer be supported. Customers should upgrade to continue to receive updated content. Please note that the minimum client version which is compatible with IR 5.X is 6.0.314.1396 and may need to be upgraded.

Deprecated Content

  • No deprecated content in this release.

Tanium Incident Response 4.5.4

Release Date Nov 27, 2018

Incident Response Official Version 4.5.4.0001

Resolved Issues and Improvements

  • Adds support for Live Response Memory Collection on Windows 10 systems with and without Device Guard HyperVisor enforced Code Integrity. See compatibility notes, below.
  • Fixed issue that would cause Memory Collections never to complete on systems with more than ~3.5GB of RAM.

Windows 10 Live Response Memory Collection Compatibility

It has been determined that memory dumping can lead to blue screen of death (BSOD) on Windows 10 systems that have Device Guard Hypervisor enforced Code Integrity (HVCI) running, but do not also have the September 2018 cumulative updates installed. BSOD's do not occur when Device Guard's HVCI is not running.

Windows 10 NOT running Device Guard HyperVisor enforced Code Integrity

Memory Collection is supported on all Windows 10 versions when Device Guard HVCI is not running.

Windows 10 running Device Guard HyperVisor enforced Code Integrity

For Windows 10 systems running Device Guard HVCI, Live Response Memory Collection will only be performed on Windows 10 versions meeting the following minimum requirements:

Windows 10 Release Id Required Update Build Revision Compatible Reference
1809 (and newer) N/A (Includes September '18 patches) Yes https://support.microsoft.com/en-us/help/4464619
1803 320+ Yes https://support.microsoft.com/en-us/help/4458469
1709 699+ (CurrentBuild 16299 only) Yes https://support.microsoft.com/en-us/help/4457136
1703 1358+ Yes https://support.microsoft.com/en-us/help/4457141
1607 2515+ Yes https://support.microsoft.com/en-us/help/4457127

New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x86
winpmem.gb414603.exe 3.1rc10 8bb120c8358e33fbd95a5726cbe88dee30ec7d25c7c9c256961653800fa28e44

Tanium Incident Response 4.5.3

Release Date Oct. 23, 2018

Incident Response Official Version 4.5.3.0005

Resolved Issues and Improvements

  • Fixes an issue with the "WMI Event Consumers" Sensor where it was not reporting ActiveScriptEventConsumer properly. When an ActiveScriptEventConsumer's "ScriptFileName" property is null, the "ScriptText" property will now be reported in the Sensor’s "Command Line Template" column.
  • "AutoRun Files" Sensor now enumerates ASEPs from all user profiles.

Security Update

  • This release includes security updates. Details of the issues, including affected versions and mitigation information, can be obtained within [1] Tanium's Support Portal or by contacting your TAM.

New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x86
TaniumExecWrapper.exe 3.6.18 32dc0ff75794f5321007bb6e21e4f358107b4082ec31dc9228f4f4ed39ac8810
TanFileInfo_32.exe 3.6.18 c9202313849b2ac6b0c09c7761f10d3b2c527018fb4a1f70d2448dc14756c3cf
TaniumHandle_32.exe 3.6.18 903d7b8f86fadae3343715f77a2b8bd19e4bb9854e9eb0bc8b9485d45d4baafb
TanListModules_32.exe 3.6.18 b5ddfb2b231d3d518d53382ef69a3fab25111cf85810570ad2a1b87819297058
Windows x64
TanFileInfo_64.exe 3.6.18 494efe1a788062870c13b773bd71165451b947ec856275b21c15bac6a5c8c6d2
TaniumHandle_64.exe 3.6.18 9f6ab805e65d09790ab48ed08bb29558decc47d1d337fbdd1b30befc38b8889d
TanListModules_64.exe 3.6.18 d5e8e95c293771a7162e09e11a60e7f23f8d4fdbf57d238bc32c7c1307524d81
Linux x86
TaniumExecWrapper_Linux32 3.6.18 8e381e6d8f005c564454ed4c65cce869d86708b80b6381dccdd114f213d4f907
Linux x64
TaniumExecWrapper_Linux64 3.6.18 fc5926ae3cd7c00fb0edce257484da6be7647e2d6d33247202dc397bcbf536d3
OSX x64
TaniumExecWrapper 3.6.18 ec0bd07bf06da812be6fed5fa915a5af7fde9cd0fa81cb6cdbd23d91db72173f

Tanium Incident Response 4.5.2

Release Date Oct. 10, 2018

Incident Response Office Version 4.5.2.0011

Resolved Issues and Improvements

  • Updates Live Response memory collection capability for Windows 10 systems. See the compatibility matrix below.

Windows 10 Live Response Memory Collection Compatibility Matrix

Windows 10 Release Id Required Update Build Revision Compatible Reference
1809 N/A (Includes September '18 patches) Yes https://support.microsoft.com/en-us/help/4464619
1803 320+ Yes https://support.microsoft.com/en-us/help/4458469
1709 699+ (CurrentBuild 16299 only) Yes https://support.microsoft.com/en-us/help/4457136
1703 1358+ Yes https://support.microsoft.com/en-us/help/4457141
1607 2515+ Yes https://support.microsoft.com/en-us/help/4457127

Memory collection via Live Response is not supported on Windows 10 Release Ids other than those shown above, this will likely change in a future release.


Tanium Incident Response 4.5.1

Release Date Sept. 25, 2018

Incident Response Official Version 4.5.1.0019

Resolved Issues and Improvements

  • Updates Winpmem to version 3.1.rc3.
  • Updates PowerForensics to version 1.4.0 to support NTFS sparse and compressed file support, improves slack space handling.
  • Updates the solution icon to match new color scheme.
  • Adds Mac Firewall Settings sensor -- returns major firewall settings from the com.apple.alf.plist file or the requested setting.
  • Adds Mac Gatekeeper Settings sensor -- returns non-standard system Gatekeeper settings or the requested setting.
  • Adds Live Response for Windows to the Incident Response solution.
  • Bugfix: Mac Downloaded Files sensor skips processing on incompatible Mac OS versions (pre 10.10.7).
  • Bugfix: Scheduled Tasks sensor now correctly returns results on 32-bit, non-English Windows systems.
  • Bugfix: PowerShell based sensors that query event logs will fail gracefully on corrupt event logs.

New Binaries

Operating System Binary Name Binary Version SHA256 Hash
Windows x64
winpmem_3.1.rc3.exe 3.1.rc3 92150af748ede27a95b73d6021594488704144d33625a0fb9842d6bed6c1358b
PowerForensics.dll 1.4.0 29bc189ded392870f836ebd88161c7efe62faa650f6585e5fd358f5fbc3fd981

Important

Known Issues

  • Live Response memory collection is currently disabled on Windows 10 Enterprise and Server 2016 systems with Device Guard security services running.
  • Live Response memory collection is currently disabled on Windows 10 non-Enterprise systems.

Deprecated Content

  • No deprecated content in this release.

Notes for future releases

  • The Search for/in Files (Mac/Linux) package will be removed in a future release. Use Index sensors for the Search for functionality and Threat Response Detect's Yara capability for hex and string searches for Search in files functionality.
  • The Historical RDP sensor depends on an Windows Security Event Log event ID, which does not appear to be triggered on modern versions of Windows. This sensor will be deprecated in a future release.
  • Semaphore-related content will be removed in a future release.
  • The sensors and packages related to the MD5 Exploit List will be deprecated in a future release. This functionality is covered by both Detect and Index Blacklists.
  • Customers with workflows or saved questions that use the "stand-alone" MD5 or SHA1 hashing sensors, such as Running Processes with MD5 Hash, should replace these sensors with the new parameterized sensors that support multiple hash types. Tanium will remove the older sensors in a future release, with advance notice to be provided in release notes for preceding releases.

Supported Tanium Platforms

Tanium Server 6.5, 7.0, 7.1, 7.2

Additional Information