INTEGRATION

Tanium

Enriching OT and IT asset visibility in Nozomi Vantage with endpoint inventory, software and vulnerability data from Tanium Cloud.

About
Tanium

Tanium Cloud is a cloud-delivered endpoint management and security platform providing real-time visibility, asset inventory and security across managed endpoints. By integrating Tanium Cloud with Nozomi Vantage, security teams gain a consolidated view of managed assets across IT and OT environments — importing endpoint inventory, software and vulnerability data directly into Vantage. This enriches the asset registry with authoritative data from the Tanium management plane, accelerating incident investigation, reducing blind spots in critical infrastructure environments and enabling analysts to correlate endpoint platform telemetry with OT network observations without switching consoles.

Features

Importer Data Types

Vantage imports the following from
Tanium Cloud
:
  • Asset Details Enrichment and Create New in Vantage

    Tanium Cloud supplies records including computer name, IP and MAC addresses, OS platform and version, manufacturer, model, serial number, chassis type, last-registration time and Tanium client version — to enrich existing Vantage assets and create new asset records for endpoints not yet observed on the OT network.

  • Asset Software Inventory Import

    Tanium Cloud reports installed application name, publisher, version, install date and silent-install metadata from the Tanium Software Inventory module. This per-asset software list is imported into Vantage, giving OT security teams an authoritative view of what is running on each observed device.

  • Asset CPE and CVE Import

    Tanium Cloud produces CVE findings with CVSS scores, exploitability and applicable patch references from the Tanium Comply module. These findings are imported into Vantage as CPE-correlated vulnerability records, enabling prioritized remediation tracking within the Nozomi asset context.

Joint Use Cases

  • Correlating Tanium signals with OT network alerts

    When Nozomi Vantage raises an anomaly alert for a device inside an OT segment, the analyst can pivot to the same asset's Tanium Cloud record in Vantage to review recent posture changes, package inventory deltas and recent question results, all without leaving the Vantage investigation workflow. This cross-layer correlation surfaces whether a network-layer anomaly coincides with activity observed by Tanium, reducing the time needed to confirm or dismiss an incident.

  • Closing asset inventory gaps across IT and OT

    Devices recorded by Tanium Cloud but not yet observed by Nozomi network sensors are automatically created as new asset records in Vantage, populated with hostname, OS, hardware and chassis details drawn from the Tanium management plane. OT operations teams can audit the resulting unified inventory to identify unmonitored or underprotected assets in industrial and critical infrastructure zones, then prioritize sensor deployment accordingly.

  • Prioritizing vulnerability remediation on critical OT assets

    CVE findings and severity scores imported from Tanium Cloud are surfaced alongside Nozomi's OT risk scoring for each asset, allowing security engineers to rank remediation effort by both vulnerability severity and the operational criticality of the affected device. This joint view enables compliance reporting workflows, such as IEC 62443 gap assessments, to reference both network-observed risk and Tanium-confirmed vulnerability data from a single Vantage dashboard.

Integration Prerequesites

  • Active Nozomi Vantage tenant with the connector-configuration role assigned to the administering account
  • Tanium Cloud tenant with API token granted Read permission on the Asset, Software and Comply sources
  • Tanium Cloud license tier and feature set that includes software-inventory collection
  • Tanium Cloud module or license that produces per-asset CVE findings enabled in the source tenant
  • Consistent hostname, IP or MAC addressing between Tanium Cloud-recorded assets and Vantage-observed assets to enable accurate asset correlation and deduplication

Take the next step.

Discover how easy it is to identify and respond to cyber threats by automating your OT and IoT asset discovery, inventory, and management.