Endpoint management company Tanium is trying to carve out a new category and a new acronym for endpoint security

At the company's Converge 2023 event this week, Tanium announced its vision for an autonomous endpoint management (AEM) platform. AEM aims to drive greater efficiency and faster risk mitigation than current endpoint management technologies, through increased automation and artificial intelligence (AI)-powered capabilities. AEM is an evolution of Tanium's converged endpoint management (XEM) technologies.

As a first step toward the AEM vision, Tanium announced several new innovations at Converge:

  • Tanium Guardian: Provides insights and recommendations on emerging vulnerabilities based on research from Tanium's security experts. It analyzes impact and suggests remediation options.
  • Tanium Automate: - Enables no-code automation of common IT tasks through orchestration and workflows. Users can build playbooks to automate processes at scale.
  • Tanium Cloud Workloads: Extends Tanium's visibility and controls to cloud native workloads like containers. Supports hybrid cloud environments.

"AEM is how we see the XEM platform evolving to being in an autonomous fabric within our core platform," Vivek Bhandari, our VP of Product Marketing at Tanium told SDxCentral.

How Tanium is defining its XEM vision

Bhandari noted that Tanium announced several new capabilities at its conference that are shipping in the next few weeks as building blocks towards AEM.

Among those capabilities the Automate module provides built in playbooks that can be customized spanning Tanium’s large set of capabilities across IT operations and security teams. Adding to that the Tanium Gateway that will provide a standardized way to programmatically interact with the Tanium platform for pushing or pulling data or taking actions via external sources.

Bhandari  explained that AEM leverages automated workflows using the integrations Tanium has  built with Microsoft security products like MDE, Sentinel, and Entra ID, as well as ServiceNow for multiple workflows covering IT asset management, user experience, vulnerability risk and compliance.

"We also laid out the vision of how we see AEM evolving over the coming months leveraging multiple AI techniques with governance, ensuring customers are always in control based on their own risk tolerance and confidence thresholds," he said.

AEM is not EDR, but it is AI

In the alphabet soup of acronyms that is modern IT, it's important to understand where Tanium's AEM fits into the cybersecurity landscape.

For endpoint security, endpoint detection and response (EDR) is a commonly used type of technology. Bhandari  noted that AEM is separate from EDR, though he noted it integrates with EDRs like Microsoft MDE to ensure EDR agents are installed, running and up to date on the endpoints. AEM will also help to automates common tasks such as vulnerability discovery, remediation, and incident response.

"AEM is also broader than EDR since it covers all the preventative security measures to minimize risk of incidents by ensuring endpoints are up to date, configured correctly, and software vulnerabilities are identified and remediated," he said.

While AEM is broader than EDR, it relies and is based on the use of artificial intelligence (AI) capabilities. Bhandari said that Tanium is using multiple AI techniques, like natural language processing (NLP),  machine learning (ML), predictive AI and also the newer generative AI models to deliver the autonomous capabilities.

It's all about the data

While the AEM direction is a new initiative from Tanium, it is based on the core innovations the company has been building out for well over a decade.

Bhandari noted that Tanium is being used across millions of endpoints every day conducting billions of actions and processing petabytes of data. This enables Tanium to anonymize the data and provide insights to its users  on the outcomes of actions at an aggregate level – allowing customers to use that as part of a confidence metric.

"This real-time data is also a fundamental requirement for delivering any autonomous capabilities," he said. "One cannot take actions based on stale or sampled data."