Tanium · Arazzo Workflow
Tanium Threat Response Live Connection And Snapshot
Version 1.0.0
Open a live connection to an endpoint, poll until connected, then capture a snapshot for offline analysis.
View Spec
View on GitHub
ComplianceEndpoint ManagementPatch ManagementSecurityThreat DetectionUnified Endpoint ManagementArazzoWorkflows
Provider
Workflows
live-connection-snapshot
Connect to an endpoint, poll until connected, and capture a snapshot.
Initiates a live connection to an endpoint, polls until the connection is established, and captures a Recorder snapshot from the connected endpoint.
1
openConnection
createConnection
Initiate a live connection to the target endpoint for investigation.
2
pollConnection
getConnection
Poll the connection by id until its status reports that the endpoint is connected and ready for snapshot capture.
3
captureSnapshot
createSnapshot
Initiate a point-in-time Recorder snapshot from the connected endpoint for offline analysis.