Skip to main content
Atlas chat showing the slash command picker with the hunt, investigate, and signal commands
Tech Insights

Slash Commands Bring Expert SecOps Workflows to Atlas

Expert SecOps workflows, available on demand, grounded in live endpoint state.

Security teams don't have a shortage of data. They have a shortage of time, repeatability, and senior expertise available at the exact moment an analyst needs it.

That's the problem Atlas slash commands are designed to solve.

With /hunt, /investigate, and /signal, Atlas turns a simple chat interaction into a guided SecOps workflow grounded in live endpoint state. Instead of starting from a blank prompt box and hoping the analyst knows exactly what to ask, slash commands package expert Tanium tradecraft into repeatable workflows. A newer analyst runs the same expert workflow a senior hunter would.

Type /, choose a command, add a few words of context, and Atlas does the heavy lifting. It hunts across the estate, digs into suspicious activity, or turns confirmed behavior into continuous detection coverage.

The analyst stays in control. Atlas handles the toil.

From blank prompt to expert workflow

A blank AI prompt is powerful, but it's also variable. The quality of the output depends on the person typing the question, what they know, how they frame the problem, which data sources they remember to query, and whether they understand the right investigative sequence.

Slash commands change that model.

Each command carries an expert workflow built by Tanium's own threat hunters, the same team behind Tanium HuntIQ. The analyst doesn't need to write the perfect prompt or memorize the right sequence of sensors, evidence checks, MITRE mappings, and detection steps. The workflow is already encoded in the command.

The experience is simple.

  1. Open Atlas chat.
  2. Type /.
  3. Choose /hunt, /investigate, or /signal.
  4. Add plain-language context.
  5. Submit.

A hunt can start as simply as this.

/hunt lolbin activity via wmic and rundll32 on Windows servers, last 7 days

That short instruction gives Atlas the objective and scope. The slash command supplies the expert playbook.

The result is natural language flexibility on top of a codified procedure. Analysts steer the workflow in their own words, and Atlas follows the same expert process every time.

The three commands

Atlas includes three slash commands for Security Operations. They come with the Tanium Security Operations subscription.

CommandUse it when you need toWhat Atlas returns
/huntSweep the estate for an IOC, threat actor, technique, alert, or hypothesisA hunt report with findings, MITRE mapping, coverage gaps, and recommended next steps
/investigateDeep-dive a specific endpoint, artifact, or alertA timeline, verdict, blast-radius analysis, evidence summary, and response recommendations
/signalConvert a proven behavior into ongoing detection coverageA validated Tanium Signal with test results, metadata, and MITRE mapping

Together, they form a practical SecOps loop.

/hunt finds the suspicious pattern.

/investigate explains what happened.

/signal helps keep watching for it.

/hunt answers "have we seen this?"

Threat hunting often starts with incomplete information, a new advisory, a suspicious hash, a behavioral hypothesis, or an alert that might point to broader exposure.

/hunt turns that starting point into an estate-wide workflow.

Atlas classifies the hunt, extracts relevant artifacts, checks existing coverage, selects the right Tanium data sources, queries the fleet, and triages results by rarity and suspicion. It can work from structured IOCs, unstructured reports, named techniques, alert context, or behavioral hypotheses.

Example prompts

  • /hunt do we have this hash anywhere: <sha256>
  • /hunt hosts beaconing to rare external domains off-hours, Windows servers, last 14 days
  • /hunt baseline the rarest scheduled tasks across the fleet
  • /hunt followed by a pasted advisory or threat report

The output isn't just a list of hits. Atlas returns a structured hunt report. It covers what it searched, where it searched, what it found, which MITRE techniques apply, where coverage is strong or weak, and which targets deserve deeper investigation.

/investigate answers "what happened here?"

Once a hunt or alert points to a specific host, artifact, or event, the next challenge is turning suspicion into a defensible conclusion.

That's where /investigate comes in.

Use it for a specific endpoint, alert ID, process, file, hash, registry key, domain, IP, user, task, service, or driver. Atlas scopes where the item appears, pauses when the scope is too broad, and then reconstructs the activity on the most relevant targets.

Example prompts

  • /investigate alert 48213
  • /investigate FINANCE-WKS-07, svchost spawning encoded PowerShell
  • /investigate this domain: cdn-telemetry-sync[.]com and save to evidence
  • /investigate <sha256> across the estate, report only

The workflow builds context around the event, including process lineage, file activity, persistence, network behavior, surrounding alerts, timeline, lateral movement indicators, and blast radius. The final report gives analysts a verdict of benign, suspicious, or confirmed malicious, with confidence and supporting evidence.

Atlas can recommend response steps, but destructive actions remain gated. Isolation, deletion, process termination, quarantine, and deployment actions wait for explicit human approval.

/signal answers "how do we detect this next time?"

The final step in the loop is turning what the team learned into lasting coverage.

/signal helps detection engineers and analysts author, validate, test, and prepare Tanium Signals from known behaviors or confirmed findings. It translates detection intent into Signal logic, validates the syntax and supported fields, tests against historical data, and maps the result to MITRE ATT&CK.

Example prompts

  • /signal detect scheduled tasks whose command line contains a base64 PowerShell blob
  • /signal turn this finding into a deployed detection: <paste process lineage / command line>
  • /signal test this rule against the last 30 days before deploying

Atlas can propose and validate detection logic, but deployment stays human-controlled. The analyst reviews the output, confirms the intent, and approves any environment-changing step.

Why live endpoint state matters

Many AI security experiences depend on stale copies of telemetry in a data lake. That can be useful, but it's not the same as asking the endpoint what is true right now.

Atlas slash commands are grounded in Tanium's real-time endpoint layer. They can use live and historical endpoint data from across the platform, including recorder telemetry, live response context, file state, process activity, and other endpoint evidence.

That matters because SecOps decisions are time-sensitive. If an analyst is investigating a suspicious process, they need to know what is happening on the machine right now, not only what was indexed somewhere yesterday.

Slash commands bring AI guidance to where Tanium is already strongest, and that is live, current, actionable endpoint state.

Built for speed, consistency, and control

The value of slash commands isn't only that they make Atlas easier to use. It's that they make expert workflows repeatable.

Slash commands help teams work faster without giving up control.

  • Lower the skill floor. More analysts can run senior-level workflows without needing to know every step in advance.
  • Improve consistency. The same command follows the same expert process across users and shifts.
  • Move faster. Atlas automates data gathering, triage, timeline building, and report generation.
  • Preserve human judgment. Analysts steer scope, review findings, and approve actions.
  • Consistent, structured reports. Each run ends in a report covering what was searched, findings, caveats, MITRE mapping, and recommended next steps.
  • Close the loop. Hunts can lead to investigations. Investigations can lead to detection coverage.

The analyst directs, verifies, and decides. Atlas executes the workflow.

Safe by design

Slash commands are also designed with practical controls.

Access is gated server-side by module entitlement and role-based permissions. If a user is not licensed or permissioned for a command, that command doesn't appear in the picker.

The commands also separate read-heavy analysis from environment-changing action. Reads and investigation steps can run autonomously, but destructive or deploying actions are staged for explicit approval.

That guardrail isn't a limitation. It's the point.

Security teams want autonomy for the toil, not unchecked automation for decisions that can disrupt the environment.

A new operating model for SecOps

Slash commands are a simple interface change with a deeper operating-model impact.

They move analysts from manually assembling every step of a hunt, investigation, or detection workflow to supervising an expert system that can run those steps end to end. They make Atlas more approachable for newer analysts and more efficient for experienced hunters. They also help teams standardize how work gets done from first suspicion to validated detection.

The result is a faster, more consistent SecOps loop.

  1. Hunt for exposure.
  2. Investigate what matters.
  3. Convert confirmed behavior into durable detection.
  4. Keep the human in control of every action that changes the environment.

That's what /hunt, /investigate, and /signal bring to Atlas. Expert SecOps workflows, available on demand, grounded in live endpoint state.

Type /. Pick the workflow. Steer the outcome.

Want to see the commands in action? Watch the Atlas for SecOps slash commands walkthrough. For the bigger picture on where this is going, read Introducing Agentic SecOps. And if your team already runs Tanium Security Operations, open Atlas and type /.