Knowing what's on your network is foundational to both security and operations, but most organizations discover just how incomplete that picture is only after something goes wrong. Tanium Discover is designed to close that gap through network-based discovery of interfaces across your environment, giving IT and security teams visibility into devices that may never have had a Tanium client installed.
The distinction matters: Discover surfaces interfaces, not just endpoints, which means a single laptop with both a wired and a wireless network card will appear as two separate interfaces. Understanding that distinction and knowing how to act on what Discover finds is what separates raw data from actionable intelligence.
Nash brings a background as a network engineer to their role as a senior advanced consulting engineer with Tanium's U.S. Public Sector practice, and that hands-on networking expertise shapes how they approach Discover configuration, scan strategy, and data interpretation.
In this episode, they walk through the four scan levels available in Discover: from a passive ARP cache lookup designed to generate no additional network traffic to a full Nmap-based port scan, and explains the trade-offs between data richness and network impact at each level. They also cover the newer network interface page for centralized subnet management, the satellite capability that now supports scanning up to a full /16 network range, and the label system that transforms raw interface data into organized, actionable categories.
If your organization is onboarding Discover for the first time, revisiting a deployment that hasn't been updated in a year or two, or trying to figure out why your cloud environment is returning duplicate interfaces, this episode covers the exact scenarios and sequencing you need.
Nash also shares real-world examples (including unsecured webcams with default credentials and an unauthorized gaming console in a data center) that illustrate why consistent, well-configured discovery matters. Watch the full episode below.
Key takeaways
- Interfaces, not endpoints: Tanium Discover performs network-based discovery of interfaces in your environment, and an interface and an endpoint are not the same thing, because any given endpoint can have multiple network interfaces, such as a laptop with both a wired and a wireless network card.
- Cloud environments need Asset instead: Discover uses the MAC address as its primary key, which creates problems in cloud environments like Azure where software-defined networking causes every interface to share the same MAC address, meaning you may see only one interface rather than a complete inventory. Use Asset for cloud inventory instead.
“Tanium Discover is intended to do network based discovery of interfaces in your environment.”Tanium Senior Advanced Consulting Engineer Nash King
- Four scan levels, increasing richness: Discover offers four scan levels for IPv4. Level 1 relies on the ARP cache and is built to generate no additional scan traffic; Level 2 uses ping and ICMP-based fingerprinting; Level 3 is an active ARP scan; and Level 4 uses Nmap to perform port scanning and OS detection, though Nmap requires both an open and a closed port to fingerprint an operating system.
- Distributed scans and satellites: Distributed scans are performed by Tanium-managed endpoints that scan the gaps within their own subnet, allowing scans to happen quickly across the environment. For subnets without any managed endpoints, a satellite can be designated to discover those networks, and satellites can now scan up to a full /16 network range, compared to the previous limit of 4,096 IP addresses.
- Centralized network interface page: A newer network interface page allows you to define subnets once and then reference them across multiple scan profiles for inclusion or exclusion, replacing the previous workflow where the same network had to be entered separately into each individual profile. Exclusions take priority: if a subnet is both included and excluded, it will not be scanned.
- Labels turn data into decisions: Labels are tags that can be applied manually or automatically using rules, and they are the mechanism for categorizing interfaces into three states: managed (Tanium client present and reporting), unmanaged (no Tanium client detected), and unmanageable (a decision that you make using a label). A label gallery in the Discover overview provides a downloadable JSON collection of pre-built labels for new deployments, including labels that automatically mark traditionally unmanageable device types such as Zebra printers and scanners.
- Security and operational patterns: Discover can surface rogue access points, unauthorized consumer devices in sensitive subnets, webcams with default credentials, and open ports like port 23 that may indicate Telnet exposure. Running both a Level 1 ARP scan and a Level 2 ping scan together improves detection coverage, because people who are doing bad things may disable ICMP on devices they connect to the network.
“Once you start kind of looking at what Discover finds, you can start identifying interesting patterns in your environment that may help you with cleaning up things operationally.”Tanium Senior Advanced Consulting Engineer Nash King
- Recommended setup sequence: When first deploying Discover, a Level 2 scan is configured by default and will begin returning interface data as endpoints are onboarded. From there, the recommended sequence is to create additional scan profiles as needed, define network exclusions for sensitive subnets, import the pre-built label collection from the label gallery, and then configure locations using a CSV file to establish user group visibility permissions based on subnet assignments.
Additional resources
- Tanium Discover product overview—network-based unmanaged device detection: Learn how Tanium Discover provides real-time visibility into interfaces across your network, including unmanaged and unmanageable devices.
- Asset discovery as the foundation for IT visibility and device management: An article covering why comprehensive asset discovery matters for security and operations teams, and how network-based discovery approaches support better device management.
- Tanium Discover documentation—module overview and initial configuration guidance: The official Tanium documentation for Discover, covering scan profiles, interface states, and setup steps.
- Tanium Discover documentation—configuring scan profiles and discovery methods: Detailed guidance on creating and managing distributed scan profiles, satellite configuration, and selecting scan levels for IPv4 and IPv6 discovery.
