This document explains how to configure the Tanium v1.0.0 plugin in the Cloud Exchange platform. This plugin is used to fetch the indicators of type Hash (MD5 and SHA256) from the Modules > Threat Response > Alerts page in the Tanium platform. This plugin does not support sharing of indicators to the Tanium platform. This plugin supports retraction of indicators pulled from the Tanium platform.
Prerequisites
To complete this configuration, you need:
- A Netskope tenant (or multiple, for example, production and development/test instances).
- A File Profile on your Netskope tenant.
- A Netskope Cloud Exchange tenant with the Tenant plugin and Threat Exchange plugin already configured.
- Connectivity to the Tanium platform.
- A subscription for Tanium Threat Response Module services.
- Admin access in Tanium to generate an API Token and pull alerts.
- Connectivity to the following host: https://*-api.titankube.com/.
Tanium Plugin Support
This plugin is used to fetch the indicators of type Hash (MD5 and SHA256) from the Modules > Threat Response > Alerts page in the Tanium platform. This plugin does not support sharing of indicators to the Tanium platform. This plugin supports retraction of indicators pulled from the Tanium platform.
| Fetched Indicator Types | Shared Indicator Types |
|---|---|
| Hash (MD5 and SHA256) | NA |
IoC Retraction
IoC Retraction (Pull): Indicators will be fetched from Tanium, and in the subsequent pull cycles, if some indicators are deleted on Tanium, then they will be marked as Retracted in Netskope Cloud Exchange.
| Retraction Type | Supported Retraction Type |
|---|---|
| IoC Retraction (Pull) | Yes |
| IoC Retraction (Push) | No |
Mappings
Pull Mappings
| Netskope CTE Field | Tanium API Field |
|---|---|
| type | (identify type from value) |
| value | details.match.properties.file.md5 details.match.properties.file.sha256 details.match.properties.parent.file.md5 details.match.properties.parent.file.sha256 |
| firstSeen | details.finding.first_seen |
| lastSeen | details.finding.last_seen |
| severity | severity |
| comments | Priority: <priority> Intel Name:<intelDoc.name> Intel Description: <intelDoc.description> Intel Source Name: <intelDoc.source.name> Path: <details.match.properties.{parent}.file.fullpath> |
| tags | parent_process_hash child_process_hash matchType |
Severity Mappings for Pull
| Netskope Severity | Tanium Severity |
|---|---|
| low | low |
| medium | medium |
| high | high |
| critical | critical |
| unknown | info |
Permissions
Users should have the Admin User Role to generate an API Token and pull alerts.
API Details
List of APIs used
| API Endpoint | Method | Use Case |
|---|---|---|
| /plugin/products/threat-response/api/v1/alerts | GET | Fetch Threat Response Alerts |
Fetch Threat Response Alerts
API endpoint: <API Base URL>/plugin/products/threat-response/api/v1/alerts
Method: GET
Headers
| Key | Value |
|---|---|
| session | <API Token> |
| User-Agent | netskope-ce-5.1.2-cte-tanium-v1.0.0 |
Parameters
| Key | Value |
|---|---|
| expand | intelDoc |
| limit | 1000 |
| offset | 0 |
| alertedAtFrom | <time> |
| sort | alertedAt |
Sample API Response
{
"data": [
{
"id": 244,
"eid": 1004,
"state": "inprogress",
"type": "detect.match",
"guid": "00000000-0000-0000-d672-a2f862b6c592",
"priority": "high",
"severity": "info",
"details": "{\"match\":{\"hash\":\"8671925402277025835\",\"type\":\"process\",\"source\":\"recorder\",\"version\":1,\"contexts\":[{\"file\":{\"uniqueEventId\":\"4611686018429125664\"},\"event\":{\"fileDelete\":{\"path\":\"D:\\\\Users\\\\kes@google.in\\\\Downloads\\\\NSClient_addon-crest.betaskope.com_6410_rQ14jxRpa5CwQd5gjVkl_7qP2WqobiUcqDK17of58ZioLqPxKk8SMcjJb3d58_.msi:Zone.Identifier\"},\"timestampMs\":\"1737540697695\"}}],\"properties\":{\"pid\":9528,\"args\":\"C:\\\\Windows\\\\Explorer.EXE\",\"file\":{\"md5\":\"d2baaaaa96839af424e3bd69a0b22c71\",\"sha1\":\"00e6d95a94e564d94b58788816be303a06047b0b\",\"sha256\":\"a438bf739441f96f2db9f9bd49aa361a298f9498ba814acea29d5ea6a2d4468c\",\"fullpath\":\"C:\\\\Windows\\\\explorer.exe\"},\"name\":\"C:\\\\Windows\\\\explorer.exe\",\"ppid\":9248,\"user\":\"google\\\\kes\",\"parent\":{\"pid\":9248,\"args\":\"C:\\\\Windows\\\\system32\\\\userinit.exe\",\"file\":{\"md5\":\"6d1d512b5f2670d3e4035939bc57e655\",\"sha1\":\"71882ca27c9028062dcb37178a1694af54cd9586\",\"sha256\":\"095d63e4c5b6430fad8e1acafce578231a0efea3c870c68ed4eeae8484aa9530\",\"fullpath\":\"C:\\\\Windows\\\\System32\\\\userinit.exe\"},\"name\":\"C:\\\\Windows\\\\System32\\\\userinit.exe\",\"ppid\":860,\"user\":\"google\\\\kes\",\"parent\":{\"pid\":860,\"args\":\"winlogon.exe\",\"file\":{\"fullpath\":\"C:\\\\Windows\\\\System32\\\\winlogon.exe\"},\"name\":\"C:\\\\Windows\\\\System32\\\\winlogon.exe\",\"ppid\":780,\"user\":\"NT AUTHORITY\\\\SYSTEM\",\"parent\":{\"pid\":780,\"args\":\"\\\\SystemRoot\\\\System32\\\\smss.exe 000000d0 0000008c \",\"file\":{\"fullpath\":\"C:\\\\Windows\\\\System32\\\\smss.exe\"},\"name\":\"C:\\\\Windows\\\\System32\\\\smss.exe\",\"ppid\":556,\"user\":\"NT AUTHORITY\\\\SYSTEM\",\"parent\":{\"pid\":556,\"args\":\"\\\\SystemRoot\\\\System32\\\\smss.exe\",\"file\":{\"fullpath\":\"C:\\\\Windows\\\\System32\\\\smss.exe\"},\"name\":\"C:\\\\Windows\\\\System32\\\\smss.exe\",\"ppid\":4,\"user\":\"NT AUTHORITY\\\\SYSTEM\",\"parent\":{\"pid\":4,\"file\":{\"fullpath\":\"System\"},\"name\":\"System\",\"user\":\"NT AUTHORITY\\\\SYSTEM\",\"start_time\":\"2025-01-21T10:29:31.000Z\",\"recorder_unique_id\":\"8569627172349557237\"},\"start_time\":\"2025-01-21T10:29:31.000Z\",\"recorder_unique_id\":\"3804061124233752300\"},\"start_time\":\"2025-01-21T10:29:35.000Z\",\"recorder_unique_id\":\"18323218992899302098\"},\"start_time\":\"2025-01-21T10:29:35.000Z\",\"recorder_unique_id\":\"8017205500022428559\"},\"start_time\":\"2025-01-21T10:33:04.000Z\",\"recorder_unique_id\":\"3695158773730177212\"},\"start_time\":\"2025-01-21T10:33:11.000Z\",\"recorder_unique_id\":\"6415688394152031122\"}},\"finding\":{\"whats\":[{\"source_name\":\"recorder\",\"intel_intra_ids\":[{\"id_v2\":\"10420185013891409313\"},{\"id_v2\":\"13232781051211547001\"}],\"artifact_activity\":{\"acting_artifact\":{\"process\":{\"pid\":9528,\"file\":{\"file\":{\"hash\":{\"md5\":\"d2baaaaa96839af424e3bd69a0b22c71\",\"sha1\":\"00e6d95a94e564d94b58788816be303a06047b0b\",\"sha256\":\"a438bf739441f96f2db9f9bd49aa361a298f9498ba814acea29d5ea6a2d4468c\"},\"path\":\"C:\\\\Windows\\\\explorer.exe\",\"signature_data\":{\"issuer\":\"Microsoft Windows Production PCA 2011\",\"status\":1,\"subject\":\"Microsoft Windows\"}},\"artifact_hash\":\"4668134681718746372\",\"instance_hash\":\"4668134681718746372\"},\"user\":{\"user\":{\"name\":\"kes\",\"domain\":\"google\",\"user_id\":\"S-1-5-21-769425621-2486857270-3423107360-1145\"}},\"parent\":{\"process\":{\"pid\":9248,\"file\":{\"file\":{\"hash\":{\"md5\":\"6d1d512b5f2670d3e4035939bc57e655\",\"sha1\":\"71882ca27c9028062dcb37178a1694af54cd9586\",\"sha256\":\"095d63e4c5b6430fad8e1acafce578231a0efea3c870c68ed4eeae8484aa9530\"},\"path\":\"C:\\\\Windows\\\\System32\\\\userinit.exe\",\"signature_data\":{\"issuer\":\"Microsoft Windows Production PCA 2011\",\"status\":1,\"subject\":\"Microsoft Windows\"}},\"artifact_hash\":\"16325832498882432364\",\"instance_hash\":\"16325832498882432364\"},\"user\":{\"user\":{\"name\":\"kes\",\"domain\":\"google\",\"user_id\":\"S-1-5-21-769425621-2486857270-3423107360-1145\"}},\"parent\":{\"process\":{\"pid\":860,\"file\":{\"file\":{\"path\":\"C:\\\\Windows\\\\System32\\\\winlogon.exe\",\"signature_data\":{\"issuer\":\"Microsoft Windows Production PCA 2011\",\"status\":1,\"subject\":\"Microsoft Windows\"}},\"artifact_hash\":\"13433015920877340112\",\"instance_hash\":\"13433015920877340112\"},\"user\":{\"user\":{\"name\":\"SYSTEM\",\"domain\":\"NT AUTHORITY\",\"user_id\":\"S-1-5-18\"}},\"parent\":{\"process\":{\"pid\":780,\"file\":{\"file\":{\"path\":\"C:\\\\Windows\\\\System32\\\\smss.exe\",\"signature_data\":{\"issuer\":\"Microsoft Windows Production PCA 2011\",\"status\":1,\"subject\":\"Microsoft Windows Publisher\"}},\"artifact_hash\":\"13095238853773225043\",\"instance_hash\":\"13095238853773225043\"},\"user\":{\"user\":{\"name\":\"SYSTEM\",\"domain\":\"NT AUTHORITY\",\"user_id\":\"S-1-5-18\"}},\"parent\":{\"process\":{\"pid\":556,\"file\":{\"file\":{\"path\":\"C:\\\\Windows\\\\System32\\\\smss.exe\",\"signature_data\":{\"issuer\":\"Microsoft Windows Production PCA 2011\",\"status\":1,\"subject\":\"Microsoft Windows Publisher\"}},\"artifact_hash\":\"13095238853773225043\",\"instance_hash\":\"13095238853773225043\"},\"user\":{\"user\":{\"name\":\"SYSTEM\",\"domain\":\"NT AUTHORITY\",\"user_id\":\"S-1-5-18\"}},\"parent\":{\"process\":{\"pid\":4,\"file\":{\"file\":{\"path\":\"System\",\"signature_data\":{\"status\":7}},\"artifact_hash\":\"10673367317368319370\",\"instance_hash\":\"10673367317368319370\"},\"user\":{\"user\":{\"name\":\"SYSTEM\",\"domain\":\"NT AUTHORITY\",\"user_id\":\"S-1-5-18\"}},\"handles\":[],\"arguments\":{},\"start_time\":\"2025-01-21T10:29:31.000Z\",\"tanium_unique_id\":\"8569627172349557237\"},\"artifact_hash\":\"133628619820746138\",\"instance_hash\":\"17432442374944931046\"},\"handles\":[],\"arguments\":\"\\\\SystemRoot\\\\System32\\\\smss.exe\",\"start_time\":\"2025-01-21T10:29:31.000Z\",\"tanium_unique_id\":\"3804061124233752300\"},\"artifact_hash\":\"6295600673353488791\",\"instance_hash\":\"10239728948408888913\"},\"handles\":[],\"arguments\":\"\\\\SystemRoot\\\\System32\\\\smss.exe 000000d0 0000008c \",\"start_time\":\"2025-01-21T10:29:35.000Z\",\"tanium_unique_id\":\"18323218992899302098\"},\"artifact_hash\":\"1682511555763885258\",\"instance_hash\":\"9882236691747135410\"},\"handles\":[],\"arguments\":\"winlogon.exe\",\"start_time\":\"2025-01-21T10:29:35.000Z\",\"tanium_unique_id\":\"8017205500022428559\"},\"artifact_hash\":\"15202984064548280121\",\"instance_hash\":\"9617131730790084616\"},\"handles\":[],\"arguments\":\"C:\\\\Windows\\\\system32\\\\userinit.exe\",\"start_time\":\"2025-01-21T10:33:04.000Z\",\"tanium_unique_id\":\"3695158773730177212\"},\"artifact_hash\":\"15310695090792779169\",\"instance_hash\":\"3453834692933203077\"},\"handles\":[],\"arguments\":\"C:\\\\Windows\\\\Explorer.EXE\",\"start_time\":\"2025-01-21T10:33:11.000Z\",\"tanium_unique_id\":\"6415688394152031122\"},\"artifact_hash\":\"8671925402277025835\",\"instance_hash\":\"8851274989043869165\",\"is_intel_target\":true},\"relevant_actions\":[{\"verb\":4,\"target\":{\"file\":{\"path\":\"D:\\\\Users\\\\kes@google.in\\\\Downloads\\\\NSClient_addon-crest.betaskope.com_6410_rQ14jxRpa5CwQd5gjVkl_7qP2WqobiUcqDK17of58ZioLqPxKk8SMcjJb3d58_.msi:Zone.Identifier\"},\"artifact_hash\":\"13157424290436624405\",\"instance_hash\":\"13157424290436624405\"},\"timestamp\":\"2025-01-22T10:11:37.000Z\",\"tanium_recorder_context\":{\"file\":{\"unique_event_id\":\"4611686018429125664\"},\"event\":{\"file_delete\":{\"path\":\"D:\\\\Users\\\\kes@google.in\\\\Downloads\\\\NSClient_addon-crest.betaskope.com_6410_rQ14jxRpa5CwQd5gjVkl_7qP2WqobiUcqDK17of58ZioLqPxKk8SMcjJb3d58_.msi:Zone.Identifier\"},\"timestamp_ms\":\"1737540697695\"}},\"tanium_recorder_event_table_id\":\"4611686018429125664\"}]}}],\"domain\":\"threatresponse\",\"hunt_id\":\"2\",\"type_id\":\"intel\",\"intel_id\":\"701:1:94c7b075-2c70-4bb2-b4a1-9453ebdbf0fc\",\"last_seen\":\"2025-01-22T10:11:39.000Z\",\"threat_id\":\"10420185013891409313,13232781051211547001\",\"finding_id\":\"-2994151614556224110\",\"first_seen\":\"2025-01-22T10:11:39.000Z\",\"source_name\":\"recorder\",\"system_info\":{\"os\":\"Microsoft Windows Server 2022 Datacenter\",\"bits\":64,\"platform\":\"Windows\",\"patch_level\":\"10.0.20348.0.0\",\"build_number\":\"20348\"},\"reporting_id\":\"reporting-id-placeholder\"},\"intel_id\":701,\"config_id\":2,\"config_rev_id\":1}",
"intelDocId": 701,
"groupingId": 50,
"intelDocRevisionId": 1,
"scanConfigId": 2,
"scanConfigRevisionId": 1,
"computerName": "KATHYCOMBS-PC8893.jones.info",
"computerIpAddress": "16.181.5.2",
"matchType": "process",
"path": "C:\\Windows\\explorer.exe",
"receivedAt": "2025-01-22T10:15:40.062Z",
"suppressedAt": null,
"alertedAt": "2025-01-22T10:11:39.000Z",
"findingId": "-2994151614556224110",
"ackedAt": "2025-01-22T10:28:35.026Z",
"firstEIDResolutionAttempt": "2025-01-22T10:15:43.488Z",
"lastEIDResolutionAttempt": "2025-01-22T10:15:43.488Z",
"createdAt": "2025-01-22T10:15:40.223Z",
"updatedAt": "2025-02-24T11:02:31.600Z",
"sentToConnect": true,
"reactions": [],
"intelDoc": {
"id": 701,
"type": "tanium-signal",
"typeVersion": "1.0",
"md5": "0363a2dc3dad684bd1b8654052813e34",
"blobId": "d1d19d68-d9a4-49ac-a8ae-49fc7015672a",
"revisionId": 2,
"intrinsicId": "Zone Identifier ADS Deletion",
"name": "Zone Identifier ADS Deletion",
"description": "Detects deletion of Zone Identifier ADS files that may be related to attacker actvity to cover their tracks.",
"size": 593,
"compiled": {
"expressions": [],
"terms": [
{
"condition": "ends with",
"negate": true,
"value": "\\windows\\explorer.exe",
"object": "process",
"property": "path"
},
{
"event_group": 1,
"condition": "ends with",
"negate": false,
"value": ":Zone.Identifier",
"object": "file",
"property": "path"
},
{
"event_group": 1,
"condition": "is",
"negate": false,
"value": "delete",
"object": "file",
"property": "operation"
}
],
"operator": "and",
"text": "group(file.path ends with ':Zone.Identifier' AND file.operation is 'delete') AND process.path ends with NOT '\\\\windows\\\\explorer.exe'",
"syntax_version": 2
},
"isSchemaValid": true,
"sourceId": 9,
"customHash": null,
"mitreAttack": {
"techniques": [
{
"id": "T1070",
"name": "Indicator Removal"
},
{
"id": "T1070.004",
"name": "Indicator Removal on Host Mitigation: File Deletion"
}
]
},
"platforms": [
"windows"
],
"createdAt": "2024-09-09T19:30:28.353Z",
"updatedAt": "2025-08-25T18:06:12.747Z",
"throttledFindingCount": 0,
"allowAutoDisable": true,
"disabled": false,
"disabledEndpointCount": 0,
"firstDeploymentTimestamp": "2025-02-12T23:26:41.672Z",
"lastDeploymentTimestamp": "2025-08-25T18:06:12.714Z",
"status": "HIGH_FIDELITY",
"editedAt": "2025-02-12T07:36:08.637Z",
"source": {
"id": 9,
"enabled": true,
"type": "tanium-signals",
"name": "Tanium Signals",
"nameSlug": "tanium-signals",
"description": "Tanium authored Signals stream",
"config": {
"subscriptionIntervalMins": 60,
"shouldRequireSignature": true,
"ignoreSsl": false,
"manifestUrl": "https://content.tanium.com/files/misc/ThreatResponse/ThreatResponse.xml"
},
"state": {
"lastIngestVersion": "4.16.0.0001",
"lastRunAt": 1756361558483
},
"createdAt": "2024-09-09T19:30:04.942Z",
"updatedAt": "2025-08-28T06:12:38.484Z"
}
}
},
…
],
"meta": {
"totalCount": 43,
"filteredCount": 43
}
}
Performance Matrix
This reading is conducted on a Large Cloud Exchange Stack with these specs by pulling 100k IoCs from Tanium.
| Description | Specification |
|---|---|
| Stack Size | Large RAM: 32 GB Core: 16 |
| Indicators fetched from Tanium | ~25k per min |
User Agent
netskope-ce-5.1.2-cte-tanium-v1.0.0
Workflow
- Create an API token on Tanium.
- Configure the Tanium plugin.
- Add a Business Rule.
- Add Actions.
- Validate the Tanium plugin.
Watch a Video
Click play to watch a video:
Create an API token on Tanium
- Enter the required details. Set Expiration per your requirements, and specify an IP address to allow access from a particular machine, or use a general IP to enable access from any source.

- Click Create, and then click Yes in the Confirm Your Action prompt.
- Copy the Token from the View API Token tab. This will be used to configure the Tanium plugin.

- Click Close.
Configure the Tanium plugin
- Log in to Cloud Exchange and go to Settings > Plugins.
- Search for and select the Tanium v1.0.0 (CTE) plugin box.

- Enter the Basic Information:
- Configuration Name: Unique name for the configuration.
- Sync Interval: Interval to fetch data from this plugin and share data to this plugin from other sources.
Note that it is better to have a larger value for Sync Interval if you want to pull IoCs in large numbers. - Aging Criteria: Expiry time of the plugin in days (Default: 90).
- Override Reputation: Set a value to override the reputation of indicators received from this configuration.
- Enable SSL Validation: Enable SSL Certificate validation.
- Use System Proxy: Enable if the proxy is required for communication.

- Click Next and enter the Configuration Parameters:
- API Base URL: API Base URL of Tanium instance. For example: https://<domain>-api.titankube.com
- API Token: API Token generated from the Tanium instance previously.
- Type of Threat Data to Pull: Type of Threat data to pull. Allowed values are MD5 and SHA256.
- Enable Tagging: Enable/Disable tagging functionality.
- Retraction Interval: Specify the number of days for which IoC retraction should be run for Tanium indicators. Note that this parameter is applicable only for Netskope Cloud Exchange version 5.1.0 or later, and if IoC(s) Retraction is enabled in Threat Exchange Settings.
- Initial Range: Number of days to pull the data for the initial run.
Add a Threat Exchange Business Rule for Tanium
To share indicators fetched from Tanium to Cloud Exchange, you need to have a business rule that will filter out the indicators that you want to share. To configure a business rule:
- Go to Threat Exchange > Business Rules and click Create New Rule.
- Add the filter according to your requirements in the rule. When finished, click Save.

Add Threat Exchange Sharing for Tanium
To share IoCs from Tanium to Cloud Exchange:
- Go to Threat Exchange > Sharing and click Add Sharing Configuration.
- Select your Source Configuration (CTE Tanium), a Business Rule, the Destination Configuration (CTE Netskope), and a Target.
- Click Save.

Validate the Tanium Plugin
Validate the Pull
Pulled data will be listed on the Threat IoCs page. You can filter the IoCs pulled from the platform using the filter: sources.source Like “<plugin configuration name>”.

To verify pulled logs in Cloud Exchange, go to Logging and search logs from the CTE Tanium plugin.
For example: message Like “CTE Tanium”

To verify the data available for pulling on the Tanium platform, log in to Tanium and go to Modules > Threat Response > Alerts.

To verify the Retracted IoCs, check the logs for IoC Retraction. For example: message Like [Retraction]:

You can filter the retracted IoCs from the platform using the filter: sources.source Is equal “<plugin configuration name>” && sources.retracted Is equal true.


Notes
- The IoCs that fall under the Retraction Interval will be marked as Retracted: Yes in Cloud Exchange.
- Sharing result will only be marked if the IoCs are pulled from the source plugin after creating the sharing configuration.
Validate the Push
Here you can see IoCs were added to the File hash list on Netskope Tenant.

Then some of the shared IoCs got marked as retracted, so they were deleted from the list.

Troubleshooting the Tanium Plugin
Unable to pull IoCs from the Tanium platform
After the plugin configuration, if the IoCs are not pulled from the platform, it may be due to one of these reasons:
- No IoCs are available on the platform to pull.
- IoCs are not available for the given configuration parameters (like Types of Threat data to pull).
What to do: Identity the root cause per the above descriptions, and then follow these steps to resolve the issue.
No IoCs are available on the platform to pull
Check if the IoCs are available on the platform to pull. If available, check the resolution for the next point.
IoCs are not available for the given time range
If the IoCs are available on the platform to pull, but the plugin has not pulled the IoCs in Cloud Exchange, check the number of days mentioned in the initial range parameter of the plugin configuration. On the Tanium platform, check if you have data for the given time range.

If the data is still available for the given time range, it’s possible that the IoCs for the provided filter in the plugin configuration are not available, so check the values from the plugin configuration parameter, and then filter the same on the Tanium platform.




