ThreatLocker
Endpoint security platform using allowlisting and default-deny policy to block unapproved software and lateral movement.
ThreatLocker takes a default-deny approach to endpoints: only approved applications run, and network and storage access follow explicit policy. That containment model limits ransomware and lateral movement even when credentials are stolen. Founded in 2017, it is popular with MSPs and IT teams that want strict control over what executes on their machines.
- Category
- Endpoint, Browser & Mobile
- Founded
- 2017
- Funding
- $489M raised (Series F, 2026)
- Website
- https://www.threatlocker.com
Seen at Black Hat USA 2026 (Titanium sponsor, booth 3333).
Outbound clicks are tokenized for directory analytics.