Secops While You Sleep: Tanium Tech Talks #167

Aug 3, 2026

They're living off the land, using the same legitimate tools your developers rely on. Today we're walking through a set-and-forget SOC workflow: from a morning news headline to a scoped investigation, to a background agent that keeps hunting for you and alerts you the moment something new turns up.

In this episode you'll learn:
☕ How to turn a news headline into a scoped hunt in your first 15 minutes of the day
🗣️ How to ask Atlas for a hunt in plain language — no query syntax needed
🛰️ How Tanium enriches findings with MITRE ATT&CK context for faster escalation
🔎 How live platform data surfaces active sessions and impacted endpoints instantly
⏰ How to schedule a hunt as a background agent that re-runs on its own
🔔 How automated alerts drop you back into full investigation context
🧑‍💻 How background agents extend a stretched SOC without replacing your analysts

Whether you're a SOC lead trying to scale coverage or a junior analyst learning to frame a hunt, this one's for you.

RESOURCES:
Demo Video - https://help.tanium.com/bundle/z-kb-articles-youtube/page/pPpC60Qyozg.html
Docs - https://help.tanium.com/bundle/ug_atlas_cloud/page/atlas/background_agents.html

CHAPTERS:

0:00 Intros

1:57 From news headline to threat lead (VS Code / nation-state actors)

4:42 DEMO: Asking Atlas in plain language

5:43 Enriched results — active tunnel session & endpoint impact

8:13 MITRE ATT&CK enrichment & incident context

11:15 Attackers living off the land

12:10 DEMO: Scheduling a hunt as a background agent

14:03 Automated alerts & jumping back into context

16:18 Why continuous hunting is now mandatory

18:00 Extending your workforce with agents

20:40 Wrap-up