| Platform | The ThreatLocker agent, managed by us rather than handed to you with a login and good wishes. |
|---|---|
| Posture | Default deny. Software that is not on the list does not execute, whether or not any scanner considers it malicious. |
| Baseline | A learning period first inventories what already runs across your estate and turns it into the initial policy, so the switch does not land on a workforce cold. |
| Updates | Application updates are tracked automatically and approvals move with them. A browser or accounting package updating itself does not become a support case. |
| Elevation | Requests and escalations reach people who are on duty at any hour. The person who asked is told what was decided, including when the answer is no. |
| Platforms | Windows workstations and servers, and macOS. Linux coverage is confirmed case by case at enrollment rather than assumed. |
| How it bills | Monthly, against each endpoint. |
Every business already has an approved software list
It has simply never been written down, and so it cannot be enforced. In practice the list is whatever a user was able to install, whatever a vendor left behind, and whatever arrived attached to something that looked like an invoice.
Detection tools are obliged to make a judgment call about each new binary, and judgment calls have an error rate that attackers measure and design against. Allowlisting removes the judgment call. The question stops being whether this program is hostile and becomes whether it was ever approved, which is a matter of record rather than of opinion.
How the list is built, and how it stays current
Deployment opens in learning mode, during which the agent records everything that actually executes across the estate. That is invariably more than the IT inventory claims, and it becomes the first draft of the policy. We go through it with you, strike out whatever nobody can account for, and only then close the door.
Keeping the list current is the part that defeats most self-managed deployments. Approved applications update constantly, and an allowlist that blocks its own approved software on patch Tuesday gets switched off within a fortnight. Update tracking follows those version changes automatically, so approval carries forward with the application rather than expiring against it.
Somebody has to answer at six in the evening
The honest objection to allowlisting is friction: a genuine tool is blocked, the user needs it now, and the person who can approve it has gone home. That failure is organizational, not technical, and it is why most allowlisting projects quietly end in a permanent exception rule.
Elevation requests and escalations reach people who are on shift at the time. The request is worked when it is raised, and whoever raised it is told what happened either way. An approval queue with nobody behind it is how default deny becomes default allow within a month.
What this refuses that a scanner permits
- Remote access tools dropped by a caller claiming to be from support. The tool is legitimate, signed, and utterly ordinary. It is also not on your list.
- Ransomware nobody has catalogued yet. Novelty is an advantage against detection and irrelevant against a list of approved software.
- Scripts and executables running out of user-writable folders, which is where nearly everything unwanted lands first.
- The convenience utility a well-meaning employee found online, which arrived with an installer bundle they never read.
Default deny is a decision, not a dashboard
Most security spending buys better answers to the question of whether something is hostile. This line changes the question, and that is why one agent at a modest monthly rate removes a whole category of incident rather than reducing its likelihood.
The cost is not the license, it is the discipline. An organization that will not tolerate a two-hour wait on an unusual approval should not buy allowlisting from anyone, including us. An organization that will now has a control an attacker cannot talk their way around, because the agent is not capable of being persuaded.
Where this Article stops
- Allowlisting governs what may execute. It does not inspect what an approved program then does with your files, which is the work of Article V.
- A permitted application driven by a stolen but legitimate credential is doing something allowed. Catching that is behavioral detection, and it is Article I.
- Nothing here reaches phones, tablets, or software running inside a cloud service you subscribe to rather than install.
- This line as sold is allowlisting and managed elevation. Other capabilities on the platform are not included by default; ask and we will quote them rather than imply them.