Tanium Package Repository
Custom Tanium packages, with the PowerShell source and the console settings needed to recreate each one.
A package runs a script on targeted endpoints as an action. Output goes to the action log on each endpoint, not to Interact. Use a package when the work changes something on the endpoint, or when it takes longer than a sensor is allowed to run.
| Package | What it does | Platform | Updated |
|---|---|---|---|
| Edge MSI Standardization | Makes the Enterprise MSI the only managed copy of Edge, removes the stale Store (AppX) registration even when locked, and clears stale registry entries. | Windows | 2026-09-18 |
| Find File by Name | Searches drives or folders for a file name or wildcard. Returns every matching path and its last modified date. | Windows | 2026-09-18 |
| Local Admin Removal | Removes domain accounts in the AD admin OU from the local Administrators group on managed endpoints. Two scripts, two packages. | Windows | 2026-08-10 |
Conventions used here
- Naming:
<prefix> - <what it does>, for exampleBF - Find File by Name. Keep the prefix consistent so custom content sorts together and stays separate from Tanium's default content. - Command line: every package calls PowerShell through
cmd.exeso parameters are passed the same way each time: - Parameters arrive URL-encoded. Tanium passes
*.pstto the script as%2a%2epst. Every script that takes a parameter decodes it before use. - Command timeout is set higher than the script's own internal limit, so the script can report its own status before Tanium stops it.
- Validate input. A blank or wildcard-only parameter should be rejected by the script, not acted on.
Before deploying
- Test the script locally on one machine, running as Administrator.
- Deploy to a single endpoint through Tanium and read the action log. Running as SYSTEM from the client's download folder is not the same as running it yourself.
- For large target groups, use the action's Distribute over option to spread the start times.