Skip to main content
Boosting Organizational Cyber Defense with the Tanium Connectors for OpenCTI and OpenBAS by Filigran
Partner Spotlight

Boosting Organizational Cyber Defense with the Tanium Connectors for OpenCTI and OpenBAS by Filigran

As part of Tanium’s ongoing partnership with Filigran, provider of open-source cybersecurity solutions, the new Tanium Connector for OpenBAS with the existing Tanium Connector for OpenCTI will help organizations more quickly identify and remediate cyber threats.

In this age of evolving technology, organizations have seen a marked increase in sophisticated cyber threats. Additionally, the advent of “Zero-Trust” with Bring Your Own Device (BYOD) becoming an expected practice among the workforce has presented its own unique challenges. System administrators and security teams are often at odds with each other over the apparent dichotomy between security and usability.

Meanwhile, those same security teams have been tasked with the virtually impossible task of securing all the assets and data within their charge, thus posing a series of existential questions that every security team must ask: “What are my assets? Who am I protecting them from? How do I protect them?”

Tanium and Filigran have formed a partnership to help security teams answer these questions and secure their IT environments. Tanium’s leading endpoint security and management platform and Filigran’s threat intelligence and breach attack simulation products keep organizations better informed and better equipped through the Power of Certainty.

With Tanium, organizations are able to quickly and effortlessly answer that first question. Addressing “What are my assets?” is a challenge that many organizations struggle with. After all, if you don’t know about something, how can you possibly hope to protect it?

Next, teams must address the second question. “What threats must I protect my assets from?” To answer this, organizations require information about the threat actors and techniques targeting similar organizations and/or similar data today; this is where Filigran comes into play.

What are Filigran OpenCTI and OpenBAS?

Filigran is a provider of open-source cybersecurity solutions covering threat intelligence management, breach and attack simulation, and cyber risk management. Among Filigran’s innovations are the first truly integrated cyber threat intelligence and breach attack simulation solutions: OpenCTI and OpenBAS.

OpenCTI enables organizations to distill multiple threat intelligence feeds, both paid and open source, into meaningful threat intelligence curated for their specific needs. Using playbooks, OpenCTI allows threat teams to automate enrichment and expansion of their Threat Intelligence to build meaningful relationships and powerful analytics.

OpenBAS is Filigran’s breach attack simulation solution. Security teams use OpenBAS to create simulated cyberattacks that leverage the tactics, techniques, and procedures (TTPs) that are highlighted in each threat report provided by OpenCTI.

Tanium and OpenCTI

OpenCTI is fully integrated with Tanium’s Threat Response module, automatically ingesting indicators to determine if the described threat is present in the environment.

If a threat is found, teams can use Tanium to take immediate, automated remediation action on any endpoint. With Tanium, teams can automatically interrupt the attack via endpoint quarantine, process termination and file deletion.

The integration between Tanium and OpenCTI is bi-directional. That means that any alert observed in Threat Response will also be sent to OpenCTI for enrichment and further evaluation leading to exhaustive threat hunt capabilities.

Finally, now that these security teams have identified their assets and know who/what they’re defending against, we come to the million-dollar question: “How do I protect them?” Once teams have used OpenCTI to distill the threat intelligence and Threat Response to determine that a threat is not present in their environment, OpenCTI has the built-in capacity to send any threat report to OpenBAS.

Figure 1: OpenCTI main dashboard giving detailed analytics into your Threat Intelligence
Figure 1: OpenCTI main dashboard giving detailed analytics into your Threat Intelligence

Tanium and OpenBAS

The new Tanium Connector integrates with OpenBAS to leverage the existing Tanium client on an endpoint to emulate these adversary actions and evaluate whether the current security tooling is able to detect or even prevent any part of the attack. This information is then used to create lessons learned and after-action reports that guide security teams to advance the security posture of the organization—and to keep pace in an ever-evolving threat landscape.

Figure 2: Using OpenBAS, scenarios can quickly be turned into actual simulations targeting real endpoints to assess an organizations security posture against a specific threat
Figure 2: Using OpenBAS, scenarios can quickly be turned into actual simulations targeting real endpoints to assess an organizations security posture against a specific threat

Samuel Hassine is Filigran’s CEO and co-founder and was formerly the head of cyber threat intelligence for France’s Agence nationale de la sécurité des systèmes d'information (ANSSI). ANSSI was responsible for much of the original development that went into the OpenCTI solution, making Hassine someone how knows just how powerful the Tanium platform can be when connected to OpenCTI.

“When I started to work on OpenCTI, it was for the internal needs at the French National Cybersecurity Agency,” Hassine recalls. “We lacked a tool like that. And we couldn’t find it commercially. So, we started development, and I never thought it would have such an impact or that so many people would want to use it.”

Hassine feels that this is an indicator of how the field of threat hunting and vulnerability detection is changing. It’s becoming much more data driven, even among organizations that are relatively immature in terms of cybersecurity.

Figure 3: OpenBAS allows users to take threat reports from OpenCTI and create attack simulations based on the attack patterns identified in the Threat Intelligence
Figure 3: OpenBAS allows users to take threat reports from OpenCTI and create attack simulations based on the attack patterns identified in the Threat Intelligence

“What I’m seeing in the field is that people have started to understand what cybersecurity is and what they need to do,” Hassine says. “Organizations want to build their cybersecurity capacity, but they have limited resources. So, they need to prioritize.”

Since it can take years to build a comprehensive detection capability, data can support the effort to prioritize and reduce an organization’s attack surface. Data provides a roadmap for prioritization, so organizations can address the most prominent threats.

“It’s like malicious, massive phishing,” Hassine muses. “You don’t try to spear every fish. You go after the most dangerous ones. Most of the teams in charge of developing detection capabilities understand this and they are using threat intelligence to prioritize their development and integrations. No system can address all tactics and procedures; you have to make choices.”

In their efforts, the usage of the MITRE ATT&CK (Adversarial Tactics, Techniques, and Common Knowledge) framework as a comprehensive matrix of tactics and techniques used by threat hunters, red teamers, and defenders to better classify attacks, could turn to be very helpful.

“Let’s say you estimate your coverage is almost 60 percent of the framework,” Hassine says. “You will quickly figure it could take years to address the remaining gaps. Using relevant cyber threat intelligence data can definitely help to prioritize the next moves.”

The Tanium Connectors for OpenCTI and OpenBAS are now available to Tanium customers

The Tanium Connectors for OpenCTI and OpenBAS are easy to install and configure and lets Tanium users take advantage of the latest technical advances in these powerful solutions. Once setup, the integration feeds a real-time events stream of threat intelligence data (e.g., the latest threat signatures and indicators) directly into the Tanium platform.

For a personalized walkthrough of the Tanium platform, schedule a demo today.

Tanium customers who wish to learn more about the Tanium Connectors for OpenCTI and OpenBAS should contact their account manager.