Tanium - Get File Details workflow This workflow queries the Tanium server for the existence of files with a specific hash value or file name. The activities collect the results and store them as enrichment data on a security incident. Figure 1. Security Operations Tanium Integration - Get File Details workflow Note: This workflow illustrates how you can query the Tanium server for the existence of files with a specific hash value or file name, collect the data, and store it as enrichment data on a security incident. In its current implementation, the workflow does not return the enriched data for use by the system. It is provided to exemplify the process you can use to increase the effectiveness of your security incident investigation. Tanium: Build Get Sensor ID Request activityThis activity takes a sensor name, and builds a request to perform a lookup on the Tanium server . It returns a sensor ID used by subsequent activities. Tanium: Execute Request activityThis workflow activity executes an HTTP request. The inputs define the endpoint and the expected request body. The request body itself is the encrypted SOAP envelope. Tanium: Get Sensor ID From Response activityThis activity processes the SOAP response body provided as input, and outputs the corresponding sensor ID.Tanium: Get Question ID from Response activityThis workflow activity processes the response body to obtain the Question ID.Tanium: Build Check if Done Request activityThis workflow activity builds a request of the Tanium server to check if data collection for the question is complete. It returns the encrypted request and other components necessary to execute the request.Tanium: Determine if done from Response activityThis workflow activity determines if a request has completed based on the response body.Tanium: Build Get Result Data Request activityThis workflow builds a request to collect all the data returned from Tanium in answer to a question. It takes a Question ID as input and provides the output to execute the request, including an encrypted SOAP envelope payload.Tanium: Get Result Data from Response activityThis workflow activity processes the response body from the result data and outputs an array of JSON objects representing the results from Tanium.Create Enrichment Data records activityThis workflow activity stores workflow output data in a table.