IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Tanium Cloud Release Notes Attack Path Mapping
Tanium Cloud Release Date: 30 September 2026
Improvements
- Adjusted attack path scoring weights for role-assumption and Active Directory delegation relationship types to better reflect their relative exploitability.
- Expanded the Blast Radius traversals to include additional credential, policy, encryption, membership, and delegation relationship types.
Resolved Issues
- Corrected an issue where the Blast Radius view could experience an error and show a node as having zero reachable crown jewels as a result.
- Corrected an issue where requesting Blast Radius for a highly connected node could fail with an error due to the volume of returned results.
Tanium Cloud Release Date: 29 September 2026
Important Notes
- This release of Tanium Attack Path Mapping (APM) broadens attack path coverage by surfacing findings beyond crown jewel-terminated attack paths. APM no longer requires that an attack path terminate at a crown jewel to produce a valid finding.
- This gives customers a fuller picture of exploitable attack paths across their environment, while confidence ranking and severity scoring continue to establish clear priority.
- Attack path severity continues to be anchored by Tanium and customer-designated crown jewel presence as the highest-weighted factor.
- Severity and confidence scoring have been re-tuned for this release to keep signal-to-noise high and prioritization clear, even as more findings may be surfaced.
- A path's severity now reflects the highest-value crown jewel found anywhere along the path, not only at its terminal, so more attack paths are visible without losing prioritization accuracy.
- Redesigned the Attack Path Explorer and Blast Radius node icon system around three categories (Identity, Asset, Finding) and a collection of icon shapes shared across categories, for more consistent and readable graphs.
Features
- Added separate Terminal and Crown Jewels columns to the Attack Paths list component, along with a filter for whether a path contains a crown jewel.
- Added visibility into a finding's EASM exposure and asset evidence, such as internet-facing hosts or web properties, alongside the structural attack path in the Attack Path Explorer.
- Selecting an evidence node opens a read-only details pane; hop counts continue to reflect only the structural path.
- Added additional crown jewel designation for Azure role assignments that grant Owner, User Access Administrator, Contributor, Role Based Access Control Administrator, or a broad Key Vault administrator role at the tenant root or a management group scope.
- Added crown jewel designation for the Azure Owner, Contributor, and User Access Administrator role definitions.
- Added additional crown jewel designation for AWS, Entra ID, and Microsoft Active Directory roles, built-in accounts, and non-human identities (NHI).
Improvements
- Attack path nodes for AWS ECR image scan and GuardDuty findings now draw with the finding icon instead of the AWS provider icon, matching the other vulnerability and misconfiguration findings.
- Crown jewels shown on the Attack Paths list and in path details now display a readable name instead of a raw element ID or security identifier, and can be searched or filtered by that name.
- Added new, expanded, and refined attack path detection coverage across Tanium External Attack Surface Management (EASM), AWS, Azure, Microsoft Entra ID, Active Directory, Tanium managed endpoints, and multi-provider scenarios, with over 100 new detections added, and 29 existing detections improved for accuracy and coverage.
- Added fallback graphics for existing APM providers so that APM displays each provider's correct icon shape and color instead of a generic icon.
- Added several new edge patterns and colors for previously unstyled edge types in the attack path graph, including internet exposure correlation, certificate correlation, additional vulnerability and misconfiguration finding edges, and EASM evidence and exposure edges.
- Added a dedicated placeholder icon shown inside a recognized provider's correct shape and color when a node type has no dedicated icon yet.
- Removed the crown jewel Provenance column and filter from the Attack Paths list, and moved the crown jewel provenance information from the attack path detail pane to the appropriate Node Details pane's designation information (provenance, reason, set by, last changed) when viewing a crown jewel.
- Choke Point scoring now credits a node for protecting any crown jewel downstream on its path, not only when the path's terminal is a crown jewel, and a path with no crown jewel still contributes to convergence scoring, at a reduced weight.
- Narrowed automatic crown jewel designation for Microsoft Entra ID directory roles to the four highest-confidence Tier 0 roles (Global Administrator, Privileged Role Administrator, Hybrid Identity Administrator, and Application/Cloud Application Administrator).
- Changed AWS RDS crown jewel designation to be based on multi-AZ deployment or extended automated snapshot retention, signals of a genuinely critical database, instead of public accessibility alone.
- Narrowed the AWS KMS customer master key crown jewel designation to keys protecting a data-bearing resource, such as a snapshot, volume, secret, database, table, file system, or training job, and lowered its severity value to reflect the narrower, more precise scope.
- Removed automatic crown jewel designation of EC2 instances based solely on an attached wildcard IAM policy.
- Removed automatic crown jewel designation based on Active Directory Remote Desktop Users or Remote Management Users group membership, since it describes a lateral-movement vector rather than asset value.
- Removed automatic crown jewel designation of a device based solely on being owned by a privileged Microsoft Entra ID user, since that describes a pivot path to the identity rather than the device's own value.
- Removed automatic crown jewel designation of S3 buckets based solely on internet-exposed access-block configuration, since exposure alone does not indicate the bucket holds valuable data.
- Added curated Node Details fields for Azure virtual machine, network security group, security rule, and network interface nodes.
- Redesigned the Attack Paths list toolbar into a single row showing an "X of Y attack paths" count, a search box, and a Clear filters button that appears when a filter or search is active and resets the list to show all detected paths, including closed ones.
- Added sorting support for additional Attack Paths list columns, including Status, Internet-facing, Ransomware, Botnet, and EPSS.
Resolved Issues
- Fixed an issue where exporting the Attack Paths list to CSV or PDF, or hovering a truncated cell, showed the KEV column's internal filter value instead of Yes or blank.
- Fixed an issue where the Node Details panel's "Closest crown jewel" hop count and its count of Crown Jewels reachable only through that node could read as contradictory even though both were correct.
- Fixed an issue where the Attack Path Explorer detail panel and the Blast Radius node details pane showed a persistent native scrollbar instead of the standard hover-to-show scrollbar.
- Fixed an issue where a crown jewel marker edge could point to the wrong node after data was re-ingested, which could cause a genuinely designated crown jewel to be treated as undesignated.
- Fixed an issue where several on-premises Active Directory crown jewel designation rules matched privileged groups by their English display name instead of their security identifier, which could cause a renamed or localized privileged group to go undesignated.
- Fixed an issue where a single failing crown jewel designation rule could indefinitely block cleanup of stale crown jewel markers for other resource classes.
- Fixed the AWS Lambda wildcard and privilege-escalation crown jewel designation rules to designate the function's execution role, the asset actually at risk, instead of the Lambda function itself.
- Fixed an issue where the AWS IAM user wildcard and self-escalation crown jewel designation rule could never match any inline policy due to an incorrect graph traversal, and added detection for the same condition on managed policies.
- Reduced unnecessary re-fetching of node details in the Attack Path Explorer when the browser window regains focus.
- Fixed an issue where the AWS KMS customer master key crown jewel designation rule could fail to run due to a query error.
- Fixed an issue where APM could miscount the path summary's cross-environment hop count.
- Fixed an issue where the severity breakdown's exploit maturity value could show as an untranslated raw string instead of its localized label when the value was returned in lowercase form.
- Fixed a calculation error that prevented the on-premises Active Directory unconstrained-delegation crown jewel designation rule from matching as designed.
- Fixed an issue where filtering or searching the Attack Paths list by a detection rule ID could return no results for paths whose only contributing rule association had since closed.
- Fixed a rare race condition where a reopen or start-remediation request could occur at the moment a finding was being closed by the system, which could leave that finding incorrectly reopened.
- Fixed a race condition where two concurrent requests to change an attack path's status (close, reopen, suppress, or remediation state) could conflict.
- Fixed an issue where the DNS name field for AWS load balancer nodes in the Node Details pane was always empty due to a property name mismatch.
- Fixed an issue where the CVSS score field for CVE nodes in the Node Details pane was always empty.
- Fixed an issue where selecting more than one Severity band in the Attack Paths list filter returned paths of every severity instead of only the selected bands.
- Fixed an issue where show/hide column selections in the Attack Paths list were not remembered after a page refresh.
- Fixed an issue where a long detection rule title could overflow the rule switcher in the path detail pane instead of wrapping within it.
- Fixed an issue where two hybrid-bridge edge types, connecting on-premises Active Directory computers and Azure virtual machines to their Tanium-managed endpoint counterpart, rendered as plain default lines instead of the hybrid-bridge line style.
- Corrected several issues where nodes rendered with a generic gray icon instead of their intended icons.
- Fixed an issue where searching the Attack Paths list by certain keywords, such as tier-0, exploitable, database, Kerberos, or vulnerability, returned no results even when matching paths existed.
- Fixed an issue where the Attack Path Name column in the Attack Paths list could not be resized, unlike the other default columns.
- Fixed an issue where the Blast Radius and Attack Path Explorer graph views were pinned to a fixed height and did not expand to fill a resized panel.
Tanium Cloud Release Date: 18 August 2026
Improvements
- Expanded attack path detection with additional coverage of:
- On-premises Active Directory delegation and group-membership paths to Tier 0.
- Paths from AWS Application Load Balancers to EC2 instance roles.
- AADInternals and Mimikatz activity on managed endpoints.
- Microsoft Entra ID and Intune device-ownership paths to Tier 0.
- Improved and corrected existing attack path detections.
Resolved Issues
- Fixed an issue where Choke Point scoring credited a Crown Jewel for protecting itself, which could cause it to outrank genuine upstream choke points in the remediation priority list.
- Fixed an issue where some nodes could display the wrong type, name, and icon in the Attack Path Explorer and Blast Radius views, even though the Node Details pane showed the correct information.
- Fixed an issue where the "View all paths" error message could remain visible in the Attack Path Explorer after you select a different node.
- Fixed an issue where date filters on the Attack Paths list could include or omit an extra hour of results near a Daylight Saving Time change.
- Fixed an issue where node exposure summaries used inconsistent pluralization, for example "1 vulnerabilities" and "1 KEV".
- Fixed an issue where a Blast Radius error message could be partially hidden behind the Return to Path view button.
- Fixed an issue where Entry, Crown Jewel, and Blast Radius node names could display inconsistently.
- Fixed an issue where extraneous text could appear in node names.
- Fixed an issue where attack path step descriptions had inconsistent text formatting and overlapping rows.
- Fixed an issue where asking Tanium Atlas to "show me my choke points" returned Tanium Impact reach data instead of Attack Path Mapping choke point analysis.
- Fixed an issue where an attack path panel could display more than one title.
Tanium Cloud Release Date: 31 July 2026
Features
- Added support for Microsoft Active Directory and Microsoft Azure data sources. Attack Path Mapping (APM) now maps attack paths that begin, pass through, or terminate on Microsoft AD and Azure assets, alongside existing Tanium-managed endpoint, Entra ID, AWS, and EASM coverage.
- Added Confidence, a new rating shown alongside Severity for every attack path.
- Confidence is a separate rating from Severity: it reflects how certain APM is that a specific path is real, not how damaging the path would be.
- Each hop in a path is individually rated across four levels: Confirmed (a scanned vulnerability or an actual group membership), Session-confirmed (an observed session an attacker could reuse), Partially confirmed (a grant that exists on paper but isn't yet proven usable), and Assumed (a plausible, known technique with no direct evidence in your environment).
- A path's overall Confidence reflects its single weakest hop, so a path is never shown as more trustworthy than its least-proven step.
- Confidence never modifies or lowers Severity. The two ratings are shown independently.
Improvements
- Improved the context and details APM provides in the Attack Path Explorer details pane:
- Why this severity shows the factors behind a path's severity band (terminal value, exploitability of each vulnerable hop, and reachability) in plain language, never as a raw score.
- Per-hop and path confidence shows each hop's confirmed-versus-assumed status and the path's overall confidence rating.
- Why this choke point shows the reasoning behind a node's choke-point designation.
- Explanations render only for the factors available for a given finding.
- Crown Jewel details now show more about how and why a node was designated as a Crown Jewel (provenance).
- The details pane shows a Crown Jewel's class, whether its designation is a Tanium default or a customer override, the reason for the designation, who set an override, and when it last changed.
- Every Crown Jewel now carries a Terminal Value weighting reflecting how much compromising it would actually matter (for example, a Global Admin role is weighted higher than a Helpdesk Admin role), modeled on the MITRE Crown Jewels Analysis (CJA) framework.
- You can pivot from a Crown Jewel directly to a filtered list of every other attack path that reaches it.
- Choke Point analysis now shows the reasoning behind every choke point:
- Why the node was identified as a choke point.
- How many attack paths would close if the node were remediated, mitigated, quarantined, or otherwise addressed.
- How many Crown Jewels the node protects, computed as a true "cut": Crown Jewels that would actually become unreachable if the node were removed, not simply Crown Jewels that happen to share a path through it.
- Each choke point is individually scored by how effectively addressing it reduces the overall paths to Crown Jewels.
- The Attack Paths list component now supports more ways to filter, sort, and understand each finding.
- New sortable/filterable columns: First Detected, Last Seen, and Closed (These columns are hidden by default and can be enabled by column controls.)
- New filters for scoring-derived attributes: internet-facing entry, exploit maturity (Weaponized / Functional / Proof of Concept), ransomware association, botnet association, and EPSS threshold.
- New Initial Access column and filter, classifying how a path's entry point was reached (network exploit, managed endpoint, or valid account).
- Crown Jewel and Path Name columns are now sortable and filterable by substring. Severity and KEV filters now support multiple selections at once.
- The list defaults to showing only Open attack paths, with a Status column and filter to also view Closed paths.
- When an attack path is produced by more than one detection rule, the path details pane shows a rule switcher so you can review each contributing rule individually.
- Selecting any node in the Attack Path Explorer now always shows a populated, formatted details pane, including curated field sets for AWS, EASM, Entra ID, and Active Directory node types.
- Attack Path Mapping ships with an expanded detection rule library, adding attack paths across on-premises Active Directory, Azure, and combined endpoint, AD, and cloud-provider scenarios.
- Added several improvements to Attack Path Severity scoring. Severity is now computed from exploitability combined with target value across the entire attack path. New exploitability inputs include EPSS, exploit maturity, ransomware and botnet association, asset reachability, initial-access type, and a difficulty weighting for every identity, permission, delegation, and hybrid-bridge hop along the path, including the new Active Directory and Azure bridge edges. A single hard-to-abuse hop anywhere in the chain meaningfully lowers a path's severity.
- Improved Choke Point scoring to enhance how APM calculates the set of Crown Jewels that would actually become unreachable if a node were remediated. A node's Choke Score is now composed from convergence, Crown Jewel value, and cut-leverage factors.
- Blast Radius counts that hit an internal result limit are now shown as "N+" with a "limited" indicator instead of being displayed as an exact count.
- Attack Path Mapping now reads Comply, EASM, and Cloud Entity Provider vulnerability data from Tanium Data Service native CVE nodes.
Resolved Issues
- Crown Jewel designations set by Tanium defaults now always include a reason, and designation overrides persist reliably through Attack Path Mapping periodic reconciliation.
- Improved attack path detection reliability: invalid or disconnected paths are now rejected before they can appear as findings, and duplicate detections of the same real route are correctly recognized and counted as a single finding.
- Corrected inconsistent typography in Attack Path Mapping Atlas UI components.
- Resolved an issue where suppressed and remediation-complete attack paths continued to appear as open in the default Attack Paths list view.
- Fixed a display issue where the Attack Path Explorer could fail to render any nodes for a path, showing only an "incomplete path" warning.
- Resolved an issue where two AWS detection rules could produce zero findings for environments with a large number of matching resources.
- Corrected the underlying issue that could cause a path's hop count to differ between the Path Summary panel and the Attack Paths list.
- Resolved an issue where the Blast Radius panel's "reachable" and "protected" Crown Jewel counts could appear to contradict each other.
- Corrected a condition in the multi-rule attribution view where the selected rule's title displayed twice and long rule descriptions did not truncate.
- Resolved an issue where Blast Radius analysis did not traverse a specific AWS EKS connector-role edge type, producing incomplete results for some AWS Elastic Kubernetes Service paths.
- Fixed the display issue where AWS IAM policy-version and role-policy nodes could display a meaningless name (for example, "v1") in the Attack Path Explorer.
- Resolved an issue where a specific EASM detection rule bound its entry point to the vulnerability node instead of the internet-exposed service, causing the path to render backwards.
- Resolved an issue where a Crown Jewel could intermittently disappear from Blast Radius and other analyses that traverse it, despite its designation remaining intact.
Tanium Cloud Release Date: 19 June 2026
Initial release
- Tanium has added Tanium Attack Path Mapping (APM), a new Atlas-first solution that maps multi-hop attack paths from exposed assets to high-value targets across hybrid endpoint, cloud, and identity environments.
Features
- Added continuous attack path discovery via the Attack Path Explorer. APM continuously builds a graph of attack paths and surfaces each finding as an end-to-end traversal from entry condition to a terminal Crown Jewel.
- Added the Attack Path Explorer. Attack Path Explorer is the primary investigation surface for inspecting, filtering, and pivoting through attack-path findings.
- Added Blast Radius analysis. The blast radius analysis surfaces the downstream nodes reachable from a selected node so security teams can quantify the potential reach of any individual exposure.
- Added Choke Point analysis. The choke point analysis identifies single nodes whose remediation breaks the largest number of attack paths simultaneously, enabling high-leverage remediation decisions.
- Added native integration with Tanium Atlas. APM surfaces use Atlas's natural-language search, contextual navigation, and unified workbench.
- Added Crown Jewel targeting and designation from Tanium Atlas. You can define Crown Jewels by computer name, user name, directory role, cloud resources, directory roles, AWS KMS keys, and other node types.