IMPORTANT: This site is planned to be decommissioned in 2026. Visit the Tanium Resource Center for all Tanium release notes, user guides, and support information. To view release notes in the Resource Center, see Tanium Release Notes.
IMPORTANT: If you are using semi-annual releases for on premises, see the Release notes for 2024H1 semiannual release, Release notes for 2024H2 semiannual release, or Release notes for 2025H1 semiannual release on the Tanium Resource Center.
Effective October 15, 2024: On prem release notes on the Tanium Knowledge Base are frozen. For release notes related to 7.4 or 7.5 Server and Solutions, see the Monthly updates for Tanium Version 7.4 and 7.5 Server and Solutions on the Tanium Resource Center.
Tanium Cloud Release Notes Attack Path Mapping
Tanium Cloud Release Date: 18 August 2026
Improvements
- Expanded attack path detection with additional coverage of:
- On-premises Active Directory delegation and group-membership paths to Tier 0.
- Paths from AWS Application Load Balancers to EC2 instance roles.
- AADInternals and Mimikatz activity on managed endpoints.
- Microsoft Entra ID and Intune device-ownership paths to Tier 0.
- Improved and corrected existing attack path detections.
Resolved Issues
- Fixed an issue where Choke Point scoring credited a Crown Jewel for protecting itself, which could cause it to outrank genuine upstream choke points in the remediation priority list.
- Fixed an issue where some nodes could display the wrong type, name, and icon in the Attack Path Explorer and Blast Radius views, even though the Node Details pane showed the correct information.
- Fixed an issue where the "View all paths" error message could remain visible in the Attack Path Explorer after you select a different node.
- Fixed an issue where date filters on the Attack Paths list could include or omit an extra hour of results near a Daylight Saving Time change.
- Fixed an issue where node exposure summaries used inconsistent pluralization, for example "1 vulnerabilities" and "1 KEV".
- Fixed an issue where a Blast Radius error message could be partially hidden behind the Return to Path view button.
- Fixed an issue where Entry, Crown Jewel, and Blast Radius node names could display inconsistently.
- Fixed an issue where extraneous text could appear in node names.
- Fixed an issue where attack path step descriptions had inconsistent text formatting and overlapping rows.
- Fixed an issue where asking Tanium Atlas to "show me my choke points" returned Tanium Impact reach data instead of Attack Path Mapping choke point analysis.
- Fixed an issue where an attack path panel could display more than one title.
Tanium Cloud Release Date: 31 July 2026
Features
- Added support for Microsoft Active Directory and Microsoft Azure data sources. Attack Path Mapping (APM) now maps attack paths that begin, pass through, or terminate on Microsoft AD and Azure assets, alongside existing Tanium-managed endpoint, Entra ID, AWS, and EASM coverage.
- Added Confidence, a new rating shown alongside Severity for every attack path.
- Confidence is a separate rating from Severity: it reflects how certain APM is that a specific path is real, not how damaging the path would be.
- Each hop in a path is individually rated across four levels: Confirmed (a scanned vulnerability or an actual group membership), Session-confirmed (an observed session an attacker could reuse), Partially confirmed (a grant that exists on paper but isn't yet proven usable), and Assumed (a plausible, known technique with no direct evidence in your environment).
- A path's overall Confidence reflects its single weakest hop, so a path is never shown as more trustworthy than its least-proven step.
- Confidence never modifies or lowers Severity. The two ratings are shown independently.
Improvements
- Improved the context and details APM provides in the Attack Path Explorer details pane:
- Why this severity shows the factors behind a path's severity band (terminal value, exploitability of each vulnerable hop, and reachability) in plain language, never as a raw score.
- Per-hop and path confidence shows each hop's confirmed-versus-assumed status and the path's overall confidence rating.
- Why this choke point shows the reasoning behind a node's choke-point designation.
- Explanations render only for the factors available for a given finding.
- Crown Jewel details now show more about how and why a node was designated as a Crown Jewel (provenance).
- The details pane shows a Crown Jewel's class, whether its designation is a Tanium default or a customer override, the reason for the designation, who set an override, and when it last changed.
- Every Crown Jewel now carries a Terminal Value weighting reflecting how much compromising it would actually matter (for example, a Global Admin role is weighted higher than a Helpdesk Admin role), modeled on the MITRE Crown Jewels Analysis (CJA) framework.
- You can pivot from a Crown Jewel directly to a filtered list of every other attack path that reaches it.
- Choke Point analysis now shows the reasoning behind every choke point:
- Why the node was identified as a choke point.
- How many attack paths would close if the node were remediated, mitigated, quarantined, or otherwise addressed.
- How many Crown Jewels the node protects, computed as a true "cut": Crown Jewels that would actually become unreachable if the node were removed, not simply Crown Jewels that happen to share a path through it.
- Each choke point is individually scored by how effectively addressing it reduces the overall paths to Crown Jewels.
- The Attack Paths list component now supports more ways to filter, sort, and understand each finding.
- New sortable/filterable columns: First Detected, Last Seen, and Closed (These columns are hidden by default and can be enabled by column controls.)
- New filters for scoring-derived attributes: internet-facing entry, exploit maturity (Weaponized / Functional / Proof of Concept), ransomware association, botnet association, and EPSS threshold.
- New Initial Access column and filter, classifying how a path's entry point was reached (network exploit, managed endpoint, or valid account).
- Crown Jewel and Path Name columns are now sortable and filterable by substring. Severity and KEV filters now support multiple selections at once.
- The list defaults to showing only Open attack paths, with a Status column and filter to also view Closed paths.
- When an attack path is produced by more than one detection rule, the path details pane shows a rule switcher so you can review each contributing rule individually.
- Selecting any node in the Attack Path Explorer now always shows a populated, formatted details pane, including curated field sets for AWS, EASM, Entra ID, and Active Directory node types.
- Attack Path Mapping ships with an expanded detection rule library, adding attack paths across on-premises Active Directory, Azure, and combined endpoint, AD, and cloud-provider scenarios.
- Added several improvements to Attack Path Severity scoring. Severity is now computed from exploitability combined with target value across the entire attack path. New exploitability inputs include EPSS, exploit maturity, ransomware and botnet association, asset reachability, initial-access type, and a difficulty weighting for every identity, permission, delegation, and hybrid-bridge hop along the path, including the new Active Directory and Azure bridge edges. A single hard-to-abuse hop anywhere in the chain meaningfully lowers a path's severity.
- Improved Choke Point scoring to enhance how APM calculates the set of Crown Jewels that would actually become unreachable if a node were remediated. A node's Choke Score is now composed from convergence, Crown Jewel value, and cut-leverage factors.
- Blast Radius counts that hit an internal result limit are now shown as "N+" with a "limited" indicator instead of being displayed as an exact count.
- Attack Path Mapping now reads Comply, EASM, and Cloud Entity Provider vulnerability data from Tanium Data Service native CVE nodes.
Resolved Issues
- Crown Jewel designations set by Tanium defaults now always include a reason, and designation overrides persist reliably through Attack Path Mapping periodic reconciliation.
- Improved attack path detection reliability: invalid or disconnected paths are now rejected before they can appear as findings, and duplicate detections of the same real route are correctly recognized and counted as a single finding.
- Corrected inconsistent typography in Attack Path Mapping Atlas UI components.
- Resolved an issue where suppressed and remediation-complete attack paths continued to appear as open in the default Attack Paths list view.
- Fixed a display issue where the Attack Path Explorer could fail to render any nodes for a path, showing only an "incomplete path" warning.
- Resolved an issue where two AWS detection rules could produce zero findings for environments with a large number of matching resources.
- Corrected the underlying issue that could cause a path's hop count to differ between the Path Summary panel and the Attack Paths list.
- Resolved an issue where the Blast Radius panel's "reachable" and "protected" Crown Jewel counts could appear to contradict each other.
- Corrected a condition in the multi-rule attribution view where the selected rule's title displayed twice and long rule descriptions did not truncate.
- Resolved an issue where Blast Radius analysis did not traverse a specific AWS EKS connector-role edge type, producing incomplete results for some AWS Elastic Kubernetes Service paths.
- Fixed the display issue where AWS IAM policy-version and role-policy nodes could display a meaningless name (for example, "v1") in the Attack Path Explorer.
- Resolved an issue where a specific EASM detection rule bound its entry point to the vulnerability node instead of the internet-exposed service, causing the path to render backwards.
- Resolved an issue where a Crown Jewel could intermittently disappear from Blast Radius and other analyses that traverse it, despite its designation remaining intact.
Tanium Cloud Release Date: 19 June 2026
Initial release
- Tanium has added Tanium Attack Path Mapping (APM), a new Atlas-first solution that maps multi-hop attack paths from exposed assets to high-value targets across hybrid endpoint, cloud, and identity environments.
Features
- Added continuous attack path discovery via the Attack Path Explorer. APM continuously builds a graph of attack paths and surfaces each finding as an end-to-end traversal from entry condition to a terminal Crown Jewel.
- Added the Attack Path Explorer. Attack Path Explorer is the primary investigation surface for inspecting, filtering, and pivoting through attack-path findings.
- Added Blast Radius analysis. The blast radius analysis surfaces the downstream nodes reachable from a selected node so security teams can quantify the potential reach of any individual exposure.
- Added Choke Point analysis. The choke point analysis identifies single nodes whose remediation breaks the largest number of attack paths simultaneously, enabling high-leverage remediation decisions.
- Added native integration with Tanium Atlas. APM surfaces use Atlas's natural-language search, contextual navigation, and unified workbench.
- Added Crown Jewel targeting and designation from Tanium Atlas. You can define Crown Jewels by computer name, user name, directory role, cloud resources, directory roles, AWS KMS keys, and other node types.