Overview

ThreatLocker is an endpoint security product that uses default-deny application control, blocking any application, script or driver that has not been explicitly allowed, combined with ringfencing to limit what approved applications can do.

From the vendor

ThreatLocker takes a default-deny approach to endpoint security: instead of trying to detect malicious behaviour after it starts, it blocks any application, script or driver that has not been explicitly allowed to run, and ringfences approved applications so they cannot be misused to reach other parts of the system they were not intended to touch. It suits MSPs willing to invest time in building and maintaining allow lists for each client in exchange for stopping unknown threats, including novel ransomware, that signature or behaviour-based detection tools might miss entirely. It is not an install-and-forget product, and MSPs expecting a set-and-leave EDR agent should understand the ongoing policy management involved before adopting it.

Pricing is per endpoint per month, quoted through a ThreatLocker account manager rather than published, and it usually includes onboarding support to help build a client's initial allow-list policies rather than leaving an MSP to work out ringfencing rules alone from a blank slate. ThreatLocker integrates with most PSA and RMM platforms for deployment and ticketing, and it also offers a Cyber Hero support team that can help triage and approve new software requests around the clock, so legitimate software is not left blocked for long while a technician is unavailable. Before buying, ask how much ongoing time the Cyber Hero support team is actually expected to save versus how much policy management remains the MSP's own responsibility, since that balance affects the real workload of running a default-deny model across many clients. It is also worth asking how ThreatLocker handles a newly deployed client during the initial learning period, since building an accurate baseline for a new environment typically takes longer than maintaining an already-tuned one.

Our take

ThreatLocker suits MSPs prepared to actively manage allow-list policies per client in exchange for blocking unknown threats that behaviour-based tools can miss, rather than those wanting a set-and-forget agent. The included onboarding support and Cyber Hero team genuinely reduce the ongoing workload, but they do not eliminate it, so confirm how requests for new, legitimate software are handled day to day before committing a client to default-deny. It is a stronger fit for security-conscious clients willing to tolerate some friction from blocked software than for a client that expects zero interruption to how they already work.

Pricing

Free version No

Reported pricing

What MSPs report paying the vendor or a distributor, excluding VAT.

No prices reported yet.

Reports are anonymous to other MSPs and checked against your reported quantity before they count toward an aggregate.

Report a price

Features

EDR and XDR

Behavioural detection no
Automated remediation no
Rollback to pre-attack state no
USB and device control unknown
Application allow-listing yes
Offline protection unknown
Threat hunting console unknown
Managed MDR add-on unknown
SIEM and SOAR integration unknown
RMM integration yes
macOS support unknown
Linux support unknown

Vulnerability and compliance

Show all 24 features

EDR and XDR

Vulnerability and compliance

Network vulnerability scanning unknown
Authenticated scanning unknown
Missing patch detection unknown
Compliance framework mapping unknown
Risk scoring unknown
Dark web monitoring unknown
External attack surface scanning unknown
PSA integration for remediation tickets unknown
Scheduled recurring scans unknown
Client-facing reports unknown
Multi-tenant console unknown
Automated evidence collection unknown

Support and training

Deployment cloud
Platforms Windows, macOS, web
Support 24/7
HQ United States
Founded 2017

Alternatives in EDR and XDR

All EDR and XDR software
Microsoft Defender for Business Endpoint protection built into the Microsoft 365 Business Premium licence. No reviews yet SentinelOne AI-driven EDR and XDR with autonomous, one-click threat rollback. No reviews yet

Compare ThreatLocker

FAQ

Does ThreatLocker offer a free trial?
There is no free version.
Is ThreatLocker cloud or on-premises?
ThreatLocker is available as cloud.
Does ThreatLocker require ongoing management, or does it run itself once installed?

ThreatLocker requires ongoing policy management, not a one-time setup. Because it blocks anything not explicitly allowed, an MSP needs to build and maintain allow lists per client and handle requests when a user needs new, legitimate software approved. ThreatLocker's included onboarding support and its Cyber Hero team help with this, but they do not remove the need for an MSP to stay involved.

What does ThreatLocker's Cyber Hero support team actually do?

The Cyber Hero team can triage and approve new software requests around the clock, so legitimate software a user needs is not left blocked for long periods when an MSP technician is unavailable. It reduces, but does not eliminate, the ongoing policy management involved in running a default-deny model, since an MSP still sets and reviews the underlying rules.

What is ringfencing in ThreatLocker, and how is it different from application allow-listing?

Allow-listing decides which applications, scripts and drivers are permitted to run at all. Ringfencing then restricts what an already-approved application is allowed to do, such as preventing a legitimate tool from reading unrelated files or launching other processes, so it cannot be misused to reach parts of the system it was not intended to touch even once it is allowed to run.

Does ThreatLocker include help setting up initial policies?

Yes, ThreatLocker pricing usually includes onboarding support to help build a client's initial allow-list and ringfencing policies rather than leaving an MSP to design them from a blank slate. This is significant given how much of running ThreatLocker well depends on getting the initial policy set right, so confirm what onboarding support is actually included at the quoted price.

No reviews yet. Be the first MSP to review ThreatLocker.