Threat hunting is one of the most resource-intensive activities in a security operations workflow. It requires skilled analysts who can form a hypothesis, search for artifacts across a large environment, filter out noise, and document findings in a way that others can act on. Tanium's HuntIQ team works hands-on in customer environments, and Threat Navigator was built directly from those real-world workflows, moving them into the Tanium console so the process becomes faster, more collaborative, and more repeatable.
Duncan walks through each of the three core components of Threat Navigator: Searches, Hypotheses, and MITRE techniques. He demonstrates how searches use IOC or Signal syntax to query the environment in real time without pre-distributing intel or waiting for log aggregation. He also shows how iterations let hunters progressively filter results to surface what actually matters, and how completed hunts can be converted directly into signals for ongoing detection.
If you manage threat hunting operations or want to understand how Tanium is making proactive security more accessible at enterprise scale, this episode covers the specific mechanics of how Threat Navigator works, from pinning individual findings to exporting hypotheses for use in other tracking tools. Watch the full episode below.
Key takeaways
- Designed from real HuntIQ workflows: Threat Navigator was built in conjunction with Tanium's HuntIQ hunters, taking the workflows they use in customer environments, often outside the console, and moving them into the Tanium console.
“This is taking our workflows that we use in customer environments, often outside the console, and trying to move it into the Tanium console.”Tanium Senior Threat Hunter Duncan Miller
- Searches run across the environment without pre-distributing intel: Using IOC or Signal syntax, searches run across the entire environment without pre-distributing intel, without collecting logs, and without generating alerts, making them well-suited for hunting rather than alerting.
“You can use IOC syntax, you can use Signal syntax to actually build out a search that's going to go across your entire environment without pre-distributing intel, without collecting logs, waiting for those to aggregate.”Tanium Senior Threat Hunter Duncan Miller
- Iterations progressively narrow results: Each active search saves up to five iterations of data, allowing hunters to exclude known-good results and rerun the search to surface what actually matters, with results capped at 10,000 total and up to 100 results per host.
- Pinning preserves point-in-time findings: Hunters can pin specific items from search results to save them even when that data gets cleared, preserving a point-in-time reference of significant findings that need further investigation or that have been confirmed as malicious. Pinning an item also automatically saves that iteration.
- Hypotheses group searches and enable export: Hypotheses act as containers for multiple related searches and can be exported as a markdown file, giving hunters a summary they can paste directly into other tracking tools. PDF export is also planned.
- Collaborative hunting builds institutional knowledge: Because the Tanium console stores search history and iterations, team members can pick up where others left off, creating a more collaborative hunting environment where everyone on the team can see what has been done and find interesting artifacts or refine searches much faster.
- Hunts quickly become detection: Once a hunt finds something malicious, the search can be converted into a signal using the create signal button, turning a one-time hunt into repeatable, automated detection without requiring a person to review the data each time.
“Hunting is an expensive activity fundamentally. You have to have a person reviewing data. You have to understand what you're looking at. Once I've completed a hunt, and I have found something malicious in that hunt, I may run the hunt again, but it shouldn't be how I'm finding the thing I found previously, right?”Tanium Senior Threat Hunter Duncan Miller
Additional resources
- Tanium Threat Response for endpoint detection, investigation, and remediation: Learn how Tanium Threat Response enables security teams to detect, investigate, and respond to threats across every endpoint in the environment.
- How HuntIQ delivers expert-led threat hunting: A look at how Tanium's HuntIQ service strengthens security operations with expert-led threat hunting designed to uncover advanced threats before they cause harm.
- Real-world detection use cases with Tanium Threat Response: The first in a three-part series covering how customers use Tanium to detect incidents, breaches, and security violations, from behavioral threat hunting and IOC scanning to leveraging multiple threat intelligence sources across the enterprise.
Tanium's statements and content regarding its plans, directions, and intent are subject to change without notice at Tanium's sole discretion. Information regarding potential future products or functionality is intended to outline Tanium's general product direction and it should not be relied on in making a purchasing decision, nor is it incorporated into any contract. It is not a commitment, promise, or legal obligation. The development, release, and timing of any future products or functionality remain at Tanium's sole discretion.
