Secops While You Sleep: Tanium Tech Talks #167
They're living off the land, using the same legitimate tools your developers rely on. Today we're walking through a set-and-forget SOC workflow: from a morning news headline to a scoped investigation, to a background agent that keeps hunting for you and alerts you the moment something new turns up.
In this episode you'll learn:
☕ How to turn a news headline into a scoped hunt in your first 15 minutes of the day
🗣️ How to ask Atlas for a hunt in plain language — no query syntax needed
🛰️ How Tanium enriches findings with MITRE ATT&CK context for faster escalation
🔎 How live platform data surfaces active sessions and impacted endpoints instantly
⏰ How to schedule a hunt as a background agent that re-runs on its own
🔔 How automated alerts drop you back into full investigation context
🧑💻 How background agents extend a stretched SOC without replacing your analysts
Whether you're a SOC lead trying to scale coverage or a junior analyst learning to frame a hunt, this one's for you.
RESOURCES:
Demo Video - https://help.tanium.com/bundle/z-kb-articles-youtube/page/pPpC60Qyozg.html
Docs - https://help.tanium.com/bundle/ug_atlas_cloud/page/atlas/background_agents.html
CHAPTERS:
0:00 Intros
1:57 From news headline to threat lead (VS Code / nation-state actors)
4:42 DEMO: Asking Atlas in plain language
5:43 Enriched results — active tunnel session & endpoint impact
8:13 MITRE ATT&CK enrichment & incident context
11:15 Attackers living off the land
12:10 DEMO: Scheduling a hunt as a background agent
14:03 Automated alerts & jumping back into context
16:18 Why continuous hunting is now mandatory
18:00 Extending your workforce with agents
20:40 Wrap-up