Skip to main content
Skip table of contents

ISG Tanium: Execute

This guide includes key steps for executing actions with sensors previously loaded to Tanium.

Additional information, including architecture, can be found on the ISG Tanium page.

Step 1: Select Target Systems

On the Tanium Home page, use Tanium’s Interact tool to Ask a Question or use the Question Builder to retrieve and group specific systems endpoints for cryptographic inventory.

AgileSec Tanium Actions run by OS, so it is recommended to group target endpoints by OS Platform. 

image-20260422-183922.png

Example: Sort by OS with Ask a Question

As an example, you may sort by OS using Ask a Question as follows.

image-20251229-115311.png

Or search for Windows OS specifically.

image-20260422-185726.png

Check the box beside the results you want to target then click Deploy Action.

Step 2: Execute Deploy Action

Select the ISG - Deploy action and execute it against the previously defined target systems.

Deploy-Action.png

Deploy Action Field

Description / Notes

Deployment Package

Specific Action to run.

Example: ISG - Deploy [<OS>]

Deployment Path

Path to store the different ISG Discovery Packages on the Target Systems.

Tanium provides default path suggestions in the Action Deployment UI. In most cases, users can rely on the default values unless they have a specific requirement to change them.

DB Path

Path to store the different ISG Local Databases on the target systems.

By default, DB Path is the same as the Deployment Path.

Minimum available space for the filesystem (GB)

Deployment Path and DB Path must have at least the specified amount of free space or Action will fail.

Action Details

  • Name

  • Description

  • Name of action

  • Brief Description

Deployment Schedule

  • Schedule Type

  • Distribute Over

Schedule Type options:

  • One-Time Deployment

  • Recurring Deployment

One-Time Deployment is recommended for Deploy and Undeploy actions.

Discover and Run actions use One-Time Deployment by default but may be configured with a Recurring Deployment.

Targeting Criteria

  • Action Group

Select the previously defined Target Systems from Step 1 to execute action on.

After filling out the required fields, click Show Preview to Continue, review, then click Deploy Actions to proceed to action execution.

Step 3: Execute Run Action

After successful deployment of the AgileSec Plugin, you can execute the Run Action against Windows or Linux devices. Select the ISG - Run Action, set the different parameters, then click Deploy Action.

image-20251229-115342.png

Run Action Field

Description

Recommended Default

Scan Path

Set the Directories or Drives to include in the analysis

Windows: C:/, D:/

Linux: /

Note: using / for Linux may be heavy and time-consuming as it scans the entire Linux target machine. Adjust the path based on performance and scope requirements.

Host Scan Type

Select the type of scan to run:

  • Run-Incremental: Perform Incremental Scan since last scan and export results to AgileSec Server. After every 5 incremental scans, a complete scan executes.

  • Run-Full: Perform complete scan and export results to AgileSec Server

  • Network: Only scan network interfaces and export results to AgileSec Server

Run-Full

Ignore Missing Path

Avoid fail if a given scan path is missing. For example, when targeting Windows systems, if C:/, D:/, E:/, F:/ are given as scan paths, some machines may not have D:/, causing a fail if this option is not enabled.

When enabled, scan will still fail if all given scan paths do not exist.

Checked

Include Tanium

Select to include Tanium directory in scan process

Not Checked

Skip Mounts

Set to skip network mounts

Checked

Scan Priority

Set priority of the discovery process vs other processes:

  • Low: Set Low priority for discovery process 

  • Normal: Set Normal priority for discovery process 

  • High: Set High priority for discovery process 

Low

CPU Priority

Set number of threads to parallelize the discovery process run:

  • Low: Set single thread / core usage

  • Normal: Set 4 threads usage

  • High: Set 8 threads usage

Normal

Config File

Add a custom configuration file

Leave blank unless a specific, custom configuration is needed.

EDR Id

An organization ID used by sensor to retrieve a token

EDR Id obtained from AgileSec UI (Platform Management → EDR Management)

Ingest URL:

Ingest URL of your AgileSec Server
Examples:

  • https://ingest.agilesec.net/

  • https://www.my-agilesec-server.local/ingest/

<Your AgileSec Server Ingest URL>

JavaScript errors detected

Please note, these errors can depend on your browser setup.

If this problem persists, please contact our support.