Release Notes Incident Response (Version 4.5)
Thank you for choosing Tanium. These notes are intended to document changes between releases of the Tanium Incident Response module.
Tanium Incident Response 4.5.6
Release Date April 23, 2019
Incident Response Official Version 4.5.6.0002
Resolved Issues and Improvements
- Fixes issue where Live Response Standard Collection may cause blue screen of death (BSOD) when endpoint has Symantec Endpoint Encryption (SEE) enabled.
- Fixes Mac Running Process with SHA256 Hash sensor output.
Notes for Future Releases
- The next release of Incident Response will be 5.X and 4.X will no longer be supported. Customers should upgrade to continue to receive updated content. Please note that the minimum client version which is compatible with IR 5.X is 6.0.314.1396 and may need to be upgraded.
Deprecated Content
- No deprecated content in this release.
Tanium Incident Response 4.5.4
Release Date Nov 27, 2018
Incident Response Official Version 4.5.4.0001
Resolved Issues and Improvements
- Adds support for Live Response Memory Collection on Windows 10 systems with and without Device Guard HyperVisor enforced Code Integrity. See compatibility notes, below.
- Fixed issue that would cause Memory Collections never to complete on systems with more than ~3.5GB of RAM.
Windows 10 Live Response Memory Collection Compatibility
It has been determined that memory dumping can lead to blue screen of death (BSOD) on Windows 10 systems that have Device Guard Hypervisor enforced Code Integrity (HVCI) running, but do not also have the September 2018 cumulative updates installed. BSOD's do not occur when Device Guard's HVCI is not running.
Windows 10 NOT running Device Guard HyperVisor enforced Code Integrity
Memory Collection is supported on all Windows 10 versions when Device Guard HVCI is not running.
Windows 10 running Device Guard HyperVisor enforced Code Integrity
For Windows 10 systems running Device Guard HVCI, Live Response Memory Collection will only be performed on Windows 10 versions meeting the following minimum requirements:
| Windows 10 Release Id | Required Update Build Revision | Compatible | Reference |
|---|---|---|---|
| 1809 (and newer) | N/A (Includes September '18 patches) | Yes | https://support.microsoft.com/en-us/help/4464619 |
| 1803 | 320+ | Yes | https://support.microsoft.com/en-us/help/4458469 |
| 1709 | 699+ (CurrentBuild 16299 only) | Yes | https://support.microsoft.com/en-us/help/4457136 |
| 1703 | 1358+ | Yes | https://support.microsoft.com/en-us/help/4457141 |
| 1607 | 2515+ | Yes | https://support.microsoft.com/en-us/help/4457127 |
New Binaries
| Operating System | Binary Name | Binary Version | SHA256 Hash |
|---|---|---|---|
| Windows x86 | |||
| winpmem.gb414603.exe | 3.1rc10 | 8bb120c8358e33fbd95a5726cbe88dee30ec7d25c7c9c256961653800fa28e44 |
Tanium Incident Response 4.5.3
Release Date Oct. 23, 2018
Incident Response Official Version 4.5.3.0005
Resolved Issues and Improvements
- Fixes an issue with the "WMI Event Consumers" Sensor where it was not reporting ActiveScriptEventConsumer properly. When an ActiveScriptEventConsumer's "ScriptFileName" property is null, the "ScriptText" property will now be reported in the Sensor’s "Command Line Template" column.
- "AutoRun Files" Sensor now enumerates ASEPs from all user profiles.
Security Update
- This release includes security updates. Details of the issues, including affected versions and mitigation information, can be obtained within [1] Tanium's Support Portal or by contacting your TAM.
New Binaries
| Operating System | Binary Name | Binary Version | SHA256 Hash |
|---|---|---|---|
| Windows x86 | |||
| TaniumExecWrapper.exe | 3.6.18 | 32dc0ff75794f5321007bb6e21e4f358107b4082ec31dc9228f4f4ed39ac8810 | |
| TanFileInfo_32.exe | 3.6.18 | c9202313849b2ac6b0c09c7761f10d3b2c527018fb4a1f70d2448dc14756c3cf | |
| TaniumHandle_32.exe | 3.6.18 | 903d7b8f86fadae3343715f77a2b8bd19e4bb9854e9eb0bc8b9485d45d4baafb | |
| TanListModules_32.exe | 3.6.18 | b5ddfb2b231d3d518d53382ef69a3fab25111cf85810570ad2a1b87819297058 | |
| Windows x64 | |||
| TanFileInfo_64.exe | 3.6.18 | 494efe1a788062870c13b773bd71165451b947ec856275b21c15bac6a5c8c6d2 | |
| TaniumHandle_64.exe | 3.6.18 | 9f6ab805e65d09790ab48ed08bb29558decc47d1d337fbdd1b30befc38b8889d | |
| TanListModules_64.exe | 3.6.18 | d5e8e95c293771a7162e09e11a60e7f23f8d4fdbf57d238bc32c7c1307524d81 | |
| Linux x86 | |||
| TaniumExecWrapper_Linux32 | 3.6.18 | 8e381e6d8f005c564454ed4c65cce869d86708b80b6381dccdd114f213d4f907 | |
| Linux x64 | |||
| TaniumExecWrapper_Linux64 | 3.6.18 | fc5926ae3cd7c00fb0edce257484da6be7647e2d6d33247202dc397bcbf536d3 | |
| OSX x64 | |||
| TaniumExecWrapper | 3.6.18 | ec0bd07bf06da812be6fed5fa915a5af7fde9cd0fa81cb6cdbd23d91db72173f |
Tanium Incident Response 4.5.2
Release Date Oct. 10, 2018
Incident Response Office Version 4.5.2.0011
Resolved Issues and Improvements
- Updates Live Response memory collection capability for Windows 10 systems. See the compatibility matrix below.
Windows 10 Live Response Memory Collection Compatibility Matrix
| Windows 10 Release Id | Required Update Build Revision | Compatible | Reference |
|---|---|---|---|
| 1809 | N/A (Includes September '18 patches) | Yes | https://support.microsoft.com/en-us/help/4464619 |
| 1803 | 320+ | Yes | https://support.microsoft.com/en-us/help/4458469 |
| 1709 | 699+ (CurrentBuild 16299 only) | Yes | https://support.microsoft.com/en-us/help/4457136 |
| 1703 | 1358+ | Yes | https://support.microsoft.com/en-us/help/4457141 |
| 1607 | 2515+ | Yes | https://support.microsoft.com/en-us/help/4457127 |
Memory collection via Live Response is not supported on Windows 10 Release Ids other than those shown above, this will likely change in a future release.
Tanium Incident Response 4.5.1
Release Date Sept. 25, 2018
Incident Response Official Version 4.5.1.0019
Resolved Issues and Improvements
- Updates Winpmem to version 3.1.rc3.
- Updates PowerForensics to version 1.4.0 to support NTFS sparse and compressed file support, improves slack space handling.
- Updates the solution icon to match new color scheme.
- Adds Mac Firewall Settings sensor -- returns major firewall settings from the com.apple.alf.plist file or the requested setting.
- Adds Mac Gatekeeper Settings sensor -- returns non-standard system Gatekeeper settings or the requested setting.
- Adds Live Response for Windows to the Incident Response solution.
- Bugfix: Mac Downloaded Files sensor skips processing on incompatible Mac OS versions (pre 10.10.7).
- Bugfix: Scheduled Tasks sensor now correctly returns results on 32-bit, non-English Windows systems.
- Bugfix: PowerShell based sensors that query event logs will fail gracefully on corrupt event logs.
New Binaries
| Operating System | Binary Name | Binary Version | SHA256 Hash |
|---|---|---|---|
| Windows x64 | |||
| winpmem_3.1.rc3.exe | 3.1.rc3 | 92150af748ede27a95b73d6021594488704144d33625a0fb9842d6bed6c1358b | |
| PowerForensics.dll | 1.4.0 | 29bc189ded392870f836ebd88161c7efe62faa650f6585e5fd358f5fbc3fd981 |
Important
- Customers wishing to use Autoruns related content will need to go to https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns and download and then upload/install SysInternals Autoruns.zip during the import of the Incident Response solution.
Known Issues
- Live Response memory collection is currently disabled on Windows 10 Enterprise and Server 2016 systems with Device Guard security services running.
- Live Response memory collection is currently disabled on Windows 10 non-Enterprise systems.
Deprecated Content
- No deprecated content in this release.
Notes for future releases
- The Search for/in Files (Mac/Linux) package will be removed in a future release. Use Index sensors for the Search for functionality and Threat Response Detect's Yara capability for hex and string searches for Search in files functionality.
- The Historical RDP sensor depends on an Windows Security Event Log event ID, which does not appear to be triggered on modern versions of Windows. This sensor will be deprecated in a future release.
- Semaphore-related content will be removed in a future release.
- The sensors and packages related to the MD5 Exploit List will be deprecated in a future release. This functionality is covered by both Detect and Index Blacklists.
- Customers with workflows or saved questions that use the "stand-alone" MD5 or SHA1 hashing sensors, such as
Running Processes with MD5 Hash, should replace these sensors with the new parameterized sensors that support multiple hash types. Tanium will remove the older sensors in a future release, with advance notice to be provided in release notes for preceding releases.
Supported Tanium Platforms
Tanium Server 6.5, 7.0, 7.1, 7.2