Threatlocker


Tasmania Green

Well-known member
Member
Local time
5:39 AM
Posts
140
OS
Windows 11 Pro - version 24H2
I just watched a video where a guy talked about the advantages of running Threatlocker. I've never heard anything about the program other than its name. What do you guys think about Threatlocker? In a sense the question is moot from an individual point of view as, from what I can tell, they don't sell subscriptions to single users. But I'm still curious how it's viewed by computer users.
 

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes
I’d never heard of it. But being an enterprise solution, that isn’t surprising. You’d probably need to hear from a system administrator like andrew129260 or Mr. pseymour or a few others here.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 23H2 Build 22631.4249
    Computer type
    PC/Desktop
    Manufacturer/Model
    Sin-built
    CPU
    Intel(R) Core(TM) i7-4770K CPU @ 3.50GHz (4th Gen?)
    Motherboard
    ASUS ROG Maximus VI Formula
    Memory
    32.0 GB of I forget and the box is in storage.
    Graphics Card(s)
    Gigabyte nVidia GeForce GTX 1660 Super OC 6GB
    Sound Card
    Onboard
    Monitor(s) Displays
    4 x LG 23MP75 - 2 x 24MK430H-B - 1 x Wacom Pro 22" Tablet
    Screen Resolution
    All over the place
    Hard Drives
    Too many to list.
    OS on Samsung 1TB 870 QVO SATA
    PSU
    Silverstone 1500
    Case
    NZXT Phantom 820 Full-Tower Case
    Cooling
    Noctua NH-D15 Elite Class Dual Tower CPU Cooler / 6 x EziDIY 120mm / 2 x Corsair 140mm somethings / 1 x 140mm Thermaltake something / 2 x 200mm Corsair.
    Keyboard
    Corsair K95 / Logitech diNovo Edge Wireless
    Mouse
    Logitech G402 / G502 / Mx Masters / MX Air Cordless
    Internet Speed
    100/40Mbps
    Browser
    All sorts
    Antivirus
    Kaspersky Premium
    Other Info
    I’m on a horse.
  • Operating System
    Windows 11 Pro 23H2 Build: 22631.4249
    Computer type
    Laptop
    Manufacturer/Model
    LENOVO Yoga 7i EVO OLED 14" Touchscreen i5 12 Core 16GB/512GB
    CPU
    Intel Core 12th Gen i5-1240P Processor (1.7 - 4.4GHz)
    Memory
    16GB LPDDR5 RAM
    Graphics card(s)
    Intel Iris Xe Graphics Processor
    Sound Card
    Optimized with Dolby Atmos®
    Screen Resolution
    QHD 2880 x 1800 OLED
    Hard Drives
    M.2 512GB
    Other Info
    …still on a horse.

My Computers

System One System Two

  • OS
    Win11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Kamrui Mini PC, Model CK10
    CPU
    Intel i5-12450H
    Memory
    32GB
    Graphics Card(s)
    No GPU - Built-in Intel Graphics
    Sound Card
    Integrated
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 2TB NVMe SSD
    1 x 4TB NVMe SSD
    1 x 4TB 2.5" SSD
    PSU
    120W "Brick"
    Keyboard
    Corsair K70 Mechanical Keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
Why not just go to their web site for more info? Also, the search term "threatlocker review" will yield more info.


and

Going to their website was the first thing I did after watching the video. And I did peak at reviews a bit. But given the technical knowledge and experience of the members of this group, I thought I'd ask their opinion in addition to doing my own research. After all, the members have more experience with computers than I do.
 

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes
I've also never heard of them and have managed many equivalent products in the enterprise EDR space (Cylance, Sophos, Sentinel One, Crowdstrike to name a few)
Same, never heard of them at all. Windows defender endpoint, crowdstrike and sential one are the only ones I have dealt with.

But I am just a low totem pole guy, not high enough to make the decisions on what product we use.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    2TB XPG nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Internet Speed
    900mbps DOWN, 100mbps UP
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
Same, never heard of them at all. Windows defender endpoint, crowdstrike and sential one are the only ones I have dealt with.

But I am just a low totem pole guy, not high enough to make the decisions on what product we use.
That's okay. I was just curious. There's so much to learn out there. lol.
 

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes
That's okay. I was just curious. There's so much to learn out there. lol.
There really is. See my tagline ;-) The best advice I can give is many of these products offer free trials. It can't hurt to reach out and try some in a VM and play around with them, or find youtube tutorials about them.

One of the things you can deploy yourself and test is wazuh.

Its completely free and is perfect to tinker around:


For example, I have it deployed in a VM and then running the agent on my tiny dell OptiPlex server to monitor it. It is a really cool tool.

PDQ is another awesome tool for deployment of software - (pushing out apps and scripts is addicting) and inventory.

 

My Computers

System One System Two

  • OS
    Windows 11 Pro
    Computer type
    PC/Desktop
    Manufacturer/Model
    Custom Built
    CPU
    Ryzen 7 5700 X3D
    Motherboard
    MSI MPG B550 GAMING PLUS
    Memory
    64 GB DDR4 3600mhz Gskill Ripjaws V
    Graphics Card(s)
    RTX 4070 Super , 12GB VRAM Asus EVO Overclock
    Monitor(s) Displays
    Gigabyte M27Q (rev. 2.0) 2560 x 1440 @ 170hz HDR
    Hard Drives
    2TB Samsung nvme ssd
    2TB XPG nvme ssd
    PSU
    CORSAIR RMx SHIFT Series™ RM750x 80 PLUS Gold Fully Modular ATX Power Supply
    Case
    CORSAIR 3500X ARGB Mid-Tower ATX PC Case – Black
    Cooling
    ID-COOLING FROSTFLOW X 240 CPU Water Cooler
    Internet Speed
    900mbps DOWN, 100mbps UP
  • Operating System
    Chrome OS
    Computer type
    Laptop
    Manufacturer/Model
    HP Chromebook
    CPU
    Intel Pentium Quad Core
    Memory
    4GB LPDDR4
    Monitor(s) Displays
    14 Inch HD SVA anti glare micro edge display
    Hard Drives
    64 GB emmc
There really is. See my tagline ;-) The best advice I can give is many of these products offer free trials. It can't hurt to reach out and try some in a VM and play around with them, or find youtube tutorials about them.

One of the things you can deploy yourself and test is wazuh.

Its completely free and is perfect to tinker around:


For example, I have it deployed in a VM and then running the agent on my tiny dell OptiPlex server to monitor it. It is a really cool tool.

PDQ is another awesome tool for deployment of software - (pushing out apps and scripts is addicting) and inventory.

Brilliant. Thanks Andrew!
 

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes
Going to their website was the first thing I did after watching the video. And I did peak at reviews a bit. But given the technical knowledge and experience of the members of this group, I thought I'd ask their opinion in addition to doing my own research. After all, the members have more experience with computers than I do.
My apologies. There was no mention of that fact so I was unaware that you had already done so. It certainly does sound interesting. It also sounds expensive :-)
 

My Computers

System One System Two

  • OS
    Win11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Kamrui Mini PC, Model CK10
    CPU
    Intel i5-12450H
    Memory
    32GB
    Graphics Card(s)
    No GPU - Built-in Intel Graphics
    Sound Card
    Integrated
    Monitor(s) Displays
    HP Envy 32
    Screen Resolution
    2560 x 1440
    Hard Drives
    1 x 2TB NVMe SSD
    1 x 4TB NVMe SSD
    1 x 4TB 2.5" SSD
    PSU
    120W "Brick"
    Keyboard
    Corsair K70 Mechanical Keyboard
    Mouse
    Logitech MX Master 3
    Internet Speed
    1Gb Up / 1 Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
  • Operating System
    Win11 Pro 23H2
    Computer type
    Laptop
    Manufacturer/Model
    Lenovo ThinkBook 13x Gen 2
    CPU
    Intel i7-1255U
    Memory
    16 GB
    Graphics card(s)
    Intel Iris Xe Graphics
    Sound Card
    Realtek® ALC3306-CG codec
    Monitor(s) Displays
    13.3-inch IPS Display
    Screen Resolution
    WQXGA (2560 x 1600)
    Hard Drives
    2 TB 4 x 4 NVMe SSD
    PSU
    USB-C / Thunderbolt 4 Power / Charging
    Mouse
    Buttonless Glass Precision Touchpad
    Keyboard
    Backlit, spill resistant keyboard
    Internet Speed
    1Gb Up / 1Gb Down
    Browser
    Edge
    Antivirus
    Windows Defender
    Other Info
    WiFi 6e / Bluetooth 5.1 / Facial Recognition / Fingerprint Sensor / ToF (Time of Flight) Human Presence Sensor
My apologies. There was no mention of that fact so I was unaware that you had already done so. It certainly does sound interesting. It also sounds expensive :-)
Oh gosh. No worries. Yes, it does sound very expensive.
 

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes

My Computer

System One

  • OS
    Windows 11 Pro - version 24H2
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 7600X 6 Core AM5 5.3GHz CPU
    Motherboard
    MSI MAG B650 GAMING PLUS WIFI
    Memory
    Silicon Power XPOWER Zenith 32GB (16GBx2) CL30,1.35V UDIMM 6000MHz DDR5 RAM
    Graphics Card(s)
    MSI GeForce RTX 4060 Ventus 2X Black 8G OC Graphics Card
    Monitor(s) Displays
    Asus ROG Strix 32in HDR VA 180Hz USB Type-C FreeSync Curved Gaming Monitor
    Screen Resolution
    2560 x 1440
    Hard Drives
    Silicon Power 1TB P34A60 Gen3x4 TLC R/W up to 2,200/1,600 MB/s PCIe M.2 NVMe SSD
    PSU
    MSI 750W MAG A750GL 80+ Gold PCIe 5 ATX 3.0 Modular Power Supply
    Case
    SilverStone Fara R1 Pro V2 Tempered Glass ATX Case - Black
    Cooling
    Wraith Stealth Cooler
    Antivirus
    Malware Bytes
I haven't used ThreatLocker, only heard it mentioned in podcast ads, but I have used tools of its ilk.

These types of products do work well if you take the time to set them up (like anything else), but they can be a lot of management (like anything else). Do you use them to restrict all your users to no admin rights, and lock down which processes are even allowed to run? Well, you're certainly more secure that way, but that's a lot to manage, and it makes users mad. Do you go to the other end of the spectrum and only lock down things you know to be a problem? Well, you're constantly being reactive and not proactive. Better hope you can stay up-to-date on current threats. And if you barely use the product in that way, then why'd you spend all that money on it? That makes C-suite people mad.

In the end, it's like getting on and off the toilet. It's all about maintaining balance to avoid ending up deep in .... trouble.

But yes, these types of tools can lock down admin rights, automatically elevate certain things by file hash or certificate of the signer, etc. They can also do neato things like, "ok, we're fine with Microsoft Word running, and we're even fine with PowerShell running, but there's no reason for them to communicate with each other, so block that." That's a decent way to keep malicious PowerShell, for example, from attacking your browser, your productivity suite, etc. But again, someone has to manage all that. And if you're a decent sized company, lots of people have to manage all that.
 

My Computers

System One System Two

  • OS
    Windows 11 Pro 24H2
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC12WSHi7
    CPU
    12th Gen Intel Core i7-1260P, 2100 MHz
    Motherboard
    NUC12WSBi7
    Memory
    64 GB
    Graphics Card(s)
    Intel Iris Xe
    Sound Card
    built-in Realtek HD audio
    Monitor(s) Displays
    Dell U3219Q
    Screen Resolution
    3840x2160 @ 60Hz
    Hard Drives
    Samsung SSD 990 PRO 1TB
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
    Antivirus
    Microsoft Defender
  • Operating System
    Linux Mint 21.2 (Cinnamon)
    Computer type
    PC/Desktop
    Manufacturer/Model
    Intel NUC8i5BEH
    CPU
    Intel Core i5-8259U CPU @ 2.30GHz
    Memory
    32 GB
    Graphics card(s)
    Iris Plus 655
    Keyboard
    CODE 104-Key Mechanical with Cherry MX Clears
from what I can tell, they don't sell subscriptions to single users
It is endpoint security, basically admin is AV, if a single PC detects a threat, it alerts him and he can deal with it.
Those products should not concern normal users, they are designed to be used by a network, not individuals.
 

My Computer

System One

  • OS
    Windows 11 Home
    Computer type
    PC/Desktop
    CPU
    AMD Ryzen 5 8600G (07/24)
    Motherboard
    ASROCK B650M-HDV/M.2 3.15 (07/24)
    Memory
    2x32GB Kingston FURY DDR5 5600 MHz CL36 @4800 CL40 (07/24)
    Graphics Card(s)
    ASROCK Radeon RX 6600 Challenger D 8G @60FPS (08/24)
    Sound Card
    Creative Sound BlasterX AE-5 Plus (05/24)
    Monitor(s) Displays
    24" Philips 24M1N3200ZS/00 (05/24)
    Screen Resolution
    1920×1080@165Hz via DP1.4
    Hard Drives
    Kingston KC3000 NVMe 2TB (05/24)
    ADATA XPG GAMMIX S11 Pro 512GB (07/19)
    PSU
    Seasonic Core GM 550 Gold (04/24)
    Case
    Fractal Design Define 7 Mini with 3x Noctua NF-P14s/12@555rpm (04/24)
    Cooling
    Noctua NH-U12S with Noctua NF-P12 (04/24)
    Keyboard
    HP Pavilion Wired Keyboard 300 (07/24) + Rabalux 76017 Parker (01/24)
    Mouse
    Logitech M330 Silent Plus (04/23)
    Internet Speed
    500/100 Mbps via RouterOS (05/21) & TCP Optimizer
    Browser
    Edge & Brave for YouTube & LibreWolf for FB
    Antivirus
    NextDNS
    Other Info
    Backup: Hasleo Backup Suite (PreOS)
    Headphones: Sennheiser RS170 (09/10)
    Phone: Samsung Galaxy Xcover 7 (02/24)
    Chair: Huzaro Force 4.4 Grey Mesh (05/24)
    Notifier: Xiaomi Mi Band 9 Milanese (10/24)
    2nd Monitor: AOC G2460VQ6 @75Hz (02/19)

Latest Support Threads

Back
Top Bottom