Direct Connect
Direct Connect is a real-time, persistent connection from the Tanium console to a specific endpoint. Unlike standard Tanium questions — which broadcast queries to thousands of machines and collect aggregated results — Direct Connect opens a dedicated, live session to a single device. Think of it as a secure, agent-based remote console that gives you deep visibility into everything happening on that endpoint right now, without requiring the user to install anything extra or grant screen-sharing access.
How Direct Connect Works
Direct Connect Capabilities
Direct Connect is not a replacement for Tanium's fleet-wide question/answer model. It complements it. Use fleet queries to identify which endpoints have a problem, then use Direct Connect to dive deep into a specific endpoint for detailed investigation.
Establishing a Direct Connect Session
Navigate
From the SEV, Investigation Workspace, or endpoint listing, select the target machine and click "Direct Connect."
Authenticate
The Tanium server sends a connection request. The client authenticates the request and verifies your RBAC permissions.
Live Session
A persistent channel opens. The console displays live tabs for processes, file system, registry, and performance metrics.
Investigate
Browse files, inspect processes, pull evidence, monitor performance -- all in real time from a single interface.
Disconnect
Close the session. The channel tears down and the endpoint returns to normal polling. Sessions auto-timeout after 15-30 min of inactivity.
The entire connection is brokered through the Tanium server — your browser never communicates directly with the endpoint. This means Direct Connect works regardless of the endpoint's network location: on-premises, remote over VPN, or on a home network, as long as the Tanium client can reach the Tanium server.
Simulated: Direct Connect Session
| Process | PID | CPU % | Memory (MB) | Disk I/O | Parent |
|---|---|---|---|---|---|
| CRMAgent.exe | 4821 | 68.2% | 3,247 | High | services.exe |
| outlook.exe | 2104 | 8.4% | 412 | Med | explorer.exe |
| chrome.exe | 3367 | 5.1% | 890 | Low | explorer.exe |
| svchost.exe | 1028 | 3.2% | 156 | Low | services.exe |
| TaniumClient.exe | 812 | 0.8% | 45 | Low | services.exe |
Capability Deep Dives
When to Use Direct Connect vs. Other Methods
| Situation | Best Tool | Why |
|---|---|---|
| Problem happening right now on one endpoint | Direct Connect | Live, real-time data from that specific machine |
| Need to browse files or download evidence | Direct Connect | File system access without remote desktop |
| Need registry-level detail | Direct Connect | Live registry browsing, no user interaction needed |
| User unavailable or non-technical | Direct Connect | No user involvement required |
| Check many endpoints at once | Fleet Queries | Direct Connect is one endpoint at a time |
| Need historical data | Fleet Queries / TDS | Direct Connect shows current state only |
| Scoping a problem across the fleet | Fleet Queries | Identify how many endpoints are affected first |
| Multi-team, multi-source correlation | Investigation Workspace | Combines fleet data, timelines, annotations |
| Building a case with evidence chain | Investigation Workspace | Persistent record with annotations over time |
Audit Trail: Every Action is Logged
Every action you take during a Direct Connect session is recorded in Tanium's audit log:
- Who initiated the session (your Tanium username)
- When the session started and ended
- Which endpoint was connected to
- Every file browsed, downloaded, or deleted
- Every process inspected or terminated
- Every registry key viewed or modified
The audit log is stored server-side and cannot be modified by the person who performed the actions. It is accessible to Tanium administrators and can be exported for compliance reporting or integration with your SIEM.
Direct Connect requires the endpoint to be online and communicating with the Tanium server. If the user says their machine "froze" and they force-powered it off, you cannot connect until it boots back up. If you suspect an intermittent issue, connect proactively while the machine is still running and symptomatic, rather than waiting for the user to reboot first.
Before starting a Direct Connect session for a sensitive investigation (HR issue, security incident, legal hold), document your purpose in the investigation workspace or your ticketing system. This establishes intent and context that complements the technical audit trail.
Scenario: What Would You Do?
Reported by: Claims adjuster, working from home
Subject: "My laptop is extremely slow right now"
Details: Can barely open Outlook and has a deadline in 30 minutes. Health score: 31 (Critical). User is remote.
What is the best immediate action?
Scenario: Choosing the Right Tool
For each situation, select the most appropriate investigation approach:
A. 15 endpoints in Accounting all show health scores below 40 since this morning. You need to understand the scope and commonality.
B. A user reports they cannot open a specific application. You suspect a corrupted config file in the user's AppData directory.
✍ Knowledge Check
1. What is the primary difference between Direct Connect and a standard Tanium fleet query?
2. Which of the following is NOT something you can do during a Direct Connect session?
3. Why is the audit trail for Direct Connect sessions important?
DEX Specialization Training © 2026