What is our primary use case?
In terms of use cases, there are quite a few good ones that come to mind. One instance is when people unexpectedly download items, especially in the downloads folder or the documents folder, and try to run them. It is effective at blocking those. We need to vet them to ensure they are legitimate and intended, not just random malicious downloads.
Another scenario involves items in the Windows folder itself, where sometimes an update might get blocked, requiring us to verify its legitimacy.
Occasionally, we receive help from Cyber Heroes as well. Those are the three use cases I can think of.
How has it helped my organization?
It helps keep track of shadow IT activities. We have more compliance because we know who is doing what. Previously, we did not know who was doing what, especially at the application control level. Some people had some administrative rights that we did not know about. We now have got more into compliance. We have everything in a single pane of glass. Everything has to be approved before it can be run. It helps our company become more secure and more compliant.
We have more consolidated security. We are three to four times more secure than before using the solution. It helps us be more compliant with what we do on a daily basis, even though sometimes it can be confusing, such as a whitelisted app getting blocked. That is probably because of fine-tuning. We will have to fine-tune that policy to make it run more smoothly.
It helped us consolidate security tools. We are now focused on this rather than looking into other tools we had in the past. We just go to ThreatLocker, look at the path, look at the hash, and see whether it is vetted. If yes, we just allow it. We had ManageEngine Application Control, and we thought we did not need that anymore. It was like an add-on. We had Endpoint Central. On top of that, we had Application Control and other things. Now, with ThreatLocker, we do not need them anymore.
I am not the finance person, but I believe it has helped our organization save on operational costs because we got this product with other security products from our managed service provider. They gave us a good rate when we combined multiple solutions together. We purchased Huntress for antivirus and other security tools from them.
I would rate it highly in its ability to block access to unauthorized applications. It works and does its job. It does what it is supposed to do, especially if you train it well. If we fine-tune the policies, it works the best. Some of the policies might be confusing, but it works well.
I am not sure if it has helped reduce help desk tickets. We still get help desk tickets here and there. We are a small company. We do not have a whole lot of applications running in our environment. In a large organization with thousands of employees, it might reduce helpdesk tickets.
We can now shift the gear and focus on other things, such as server logs or security logs, more firewall rules, etc. It saves us at least three hours every day.
What is most valuable?
The most valuable feature is its learning capability. Not every application it learns is allowed to run, so my involvement is necessary. Those based on path and certification are particularly important. When an application is on a specific path in our network and has a valid certificate or hash, it assures me that the application is safe to run and offers comfort that it is probably 100% okay to proceed. It locks a threat.
What needs improvement?
This is my first Zero Trust conference, and so far, it has been good. The only thing I have noticed is that sometimes they encounter technical issues. For example, in one of the demo labs, the laptop trying to connect to the projector was not working, which affected the demonstration of the victim versus attacker laptop scenarios. It would be helpful to fix these issues.
Additionally, when people come to the hacking lab, presenters should ensure their fonts are larger. With 500 to 600 people in the room, it is difficult to see everything clearly, especially when there are only two projectors. Improving the sound quality and similar aspects would be beneficial.
For how long have I used the solution?
It has been over three years now since we have been using it. We got it through our MSP. They have given us access as admins, though not with full control, to allow the whitelisting of some applications and paths if needed.
What do I think about the stability of the solution?
It is pretty stable. It is doing its job well. The algorithms and coding, developed by smart individuals, ensure the app performs its tasks effectively.
What do I think about the scalability of the solution?
It is quite scalable. From what I understand and have learned, we can manage as many environments as we want. It remains scalable and manageable from one portal.
How are customer service and support?
Customer service is pretty good. I would rate it highly. Their response is almost instantaneous when issues arise. I just communicate my concern, and within minutes, I get a response.
How would you rate customer service and support?
Which solution did I use previously and why did I switch?
We previously used ManageEngine Application Control, but we eliminated it. It was doing a similar thing, but it was a little bit different.
By switching, we were getting a better discount, and the consultants or the advisor also said that this solution is better based on the previous experience with the solution.
How was the initial setup?
We have a cloud version when it comes to the portal. The agents are installed on every machine and server. For the most part, we use the Azure cloud. We also have AWS.
The initial setup was pretty easy since we received assistance from a third party. Everything is deployed via GPO, so once a computer joins, it installs by itself. However, we have limited access to the portal as of now, and I hope this will change.
What was our ROI?
From a technical perspective, it does its job by saving our team time and reducing confusion. It saves effort working on people who engage in shadow IT by preventing unauthorized applications from running on their computers. The installation of the ThreatLocker agent has ceased such activities. With only three IT personnel, it has proved efficient, assisting us in managing and streamlining our workload.
What's my experience with pricing, setup cost, and licensing?
I do not know about the licensing and price as it comes bundled from our MSP. However, it seems fairly reasonable for us, which is why we chose it.
Which other solutions did I evaluate?
We did not evaluate other solutions.
What other advice do I have?
It is not easy to use. I am still learning. I highly recommend finishing the Cyber Hero course to understand the solution, the way it works, and the secret behind each tool. This course is available in ThreatLocker University. It has a lot of modules that you can go through. Once you can master those, you will have a good idea of what is going on. After that, it is easy to implement.
I would rate it a nine out of ten. At the Zero Trust conference, eliminating some technical difficulties in future iterations could raise this to ten. Overall, everything is excellent, and everything is well-prepared, from the laptops provided to the overall setup. These minor issues could happen anywhere, not just here. If resolved, it would be a perfect ten. It is not a huge issue.
Disclosure: My company does not have a business relationship with this vendor other than being a customer.