Tanium Sensor Repository
Custom Tanium sensors, with the PowerShell source and the console settings needed to recreate each one.
A sensor answers a question in Interact. It runs on every targeted endpoint each time the question is asked, so it has to return in seconds. Anything slower belongs in a package.
| Sensor | What it answers | Platform | Updated |
|---|---|---|---|
| Find File by Name | Does this file exist in these folders, and when was it last modified? | Windows | 2026-09-18 |
Conventions used here
- Naming: short and plain, since the name becomes part of every question typed in Interact. Avoid brackets, quotes, and
|, which Interact uses for parameters and column splitting. - Parameters are read through placeholders such as
||FileName||. The parameter Key in the console must match the placeholder exactly, including capitalization. - Parameters arrive URL-encoded. Tanium passes
*.pstto the script as%2a%2epst. Every script that takes a parameter decodes it before use. - Multi-column results use
|as the delimiter, with the columns defined in the sensor settings. - Time budget. Each script stops itself before the sensor timeout and returns a status line instead of being killed mid-run. Set the sensor timeout above that internal limit.
- Fixed status strings such as
NOT FOUNDmake results easy to filter in a question. Avoid free-form error text.
Before creating a sensor
- Replace the
||Parameter||placeholders with real values in a test copy, then run it locally to confirm it works and to measure the run time. - Compare that run time against the sensor timeout. A sensor is re-run on every question, so anything close to the limit will hurt at scale.
- Check the Max Sensor Age. Results are reused for that long before the script runs again.