ThreatLocker
CISO ReviewedZero Trust endpoint protection platform that blocks unknown applications by default through allowlisting, ringfencing, and storage control.
Visit Website ↗ + Add to CompareEditorial: 78/100 · includes 1 verified CISO review
Overview
ThreatLocker builds a Zero Trust endpoint protection platform built around default-deny application allowlisting: instead of trying to detect malicious software after the fact, it blocks any application, script, or executable that hasn’t been explicitly approved. The platform layers on “Ringfencing” (limiting what approved applications are allowed to do, such as preventing Word from spawning PowerShell), storage control, elevation control for admin privileges, and network access controls, all managed centrally by IT and MSP teams.
Founded in 2017 by Danny Jenkins, Sami Jenkins, and John Carolan, ThreatLocker grew primarily through the managed service provider (MSP) channel before expanding into direct enterprise sales. The company is headquartered in Orlando, Florida, and has scaled to roughly $100 million in annual revenue and a reported valuation north of $1.6 billion as of its Series D round, with a $190 million Series F closed in mid-2026 to fund international expansion and AI-related risk controls.
The core differentiator versus traditional endpoint detection and response (EDR) tools is philosophical: rather than trying to identify bad behavior among everything that’s allowed to run, ThreatLocker starts from nothing being allowed to run until it’s been vetted. That approach trades some administrative overhead for a materially smaller attack surface, which is why it has found strong traction among MSPs securing many client environments with limited staff.
Innovation Matrix Assessment
Steady, multi-year expansion from core allowlisting into ringfencing, elevation control, storage control, patch management, and newly announced AI-risk controls funded by the 2026 Series F.
Default-deny application control materially shrinks the executable attack surface for MSPs and lean IT teams managing many endpoints, a genuinely different operational posture than detect-and-respond tooling.
Independently reported: $190M Series F (2026) led by Elephant with Koch Disruptive Technologies participating, prior $115M Series D, ~$100M ARR per CEO statements, and a reported $1.6B+ valuation. Sustained MSP-channel and enterprise expansion since the Series F further strengthens this signal.
While application allowlisting itself isn't new, ThreatLocker's default-deny-by-default operating model — inverting the industry's default-allow posture at scale across MSP and enterprise endpoints — represents a more structural shift in endpoint security practice than a typical point tool; revised upward to reflect that.
Named a Strong Performer in Gartner's 2024 Voice of the Customer for Endpoint Protection Platforms with a 4.9/5 rating and 100% willingness-to-recommend among reviewed vendors. A growing base of MSP deployments with consistently strong peer-review feedback supports a somewhat higher efficacy assessment.
Application control remains foundational against ransomware and supply-chain attacks, and the company is extending the model toward AI-related endpoint risk, suggesting continued relevance as threats evolve.
Why CISOs Should Care
Cuts the number of things that can execute on an endpoint down to an explicit allowlist, which blocks entire classes of ransomware and living-off-the-land attacks that evade signature- or behavior-based EDR.
What Makes It Different
Default-deny-first architecture rather than detect-and-respond-after-the-fact, paired with a channel model built specifically for MSPs managing many client environments at once.
The Matrix Verdict
83/100 — MEANINGFUL INNOVATOR
A Meaningful Innovator: ThreatLocker didn't invent application allowlisting, but it productized and scaled it effectively, with strong independent customer satisfaction signals and real revenue traction. Its disruption score is held back by its own success — at $100M+ ARR and a multibillion-dollar valuation it now competes as an established incumbent, not a scrappy category-definer.
What CISOs Are Saying
“Many breaches would have been stopped in their tracks if the companies had already deployed the Threat Locker zero trust agent.”
— Anonymous CISO, Cyber Defense Genius reviewer network
Editorial Note: Claims vs. Verified Findings
CEO claims of 3,000% three-year revenue growth and specific ARR figures are self-reported and not independently audited; Gartner Peer Insights ratings and funding round terms, by contrast, are independently documented.
Sources
- SecurityWeek — https://www.securityweek.com/threatlocker-raises-190-million-in-series-f-funding/
- PR Newswire (Series F) — https://www.prnewswire.com/news-releases/threatlocker-secures-190-million-in-series-f-funding-to-drive-product-innovation-and-global-expansion-302837156.html
- Gartner Peer Insights — https://www.gartner.com/reviews/product/threatlocker-platform
- ThreatLocker Gartner VoC press release — https://www.threatlocker.com/press-release/threatlocker-2024-gartner-voice-of-the-customer-endpoint-protection-platform-report
- Wikipedia — https://en.wikipedia.org/wiki/ThreatLocker
Alternatives to ThreatLocker
Endor Labs
Reachability-based software composition analysis that filters open-source dependency risk down to what code paths are actually exploitable.
Socket
A software supply chain security platform that combines automated dependency analysis with human verification to catch malicious and…
JFrog
Public software supply chain security platform (Xray plus Advanced Security) that scans binaries and artifacts end-to-end from the…
Apiiro
Builds a continuous 'code risk graph' that maps code, developers, and cloud deployment to prioritize AppSec findings by…
ArmorCode
Tool-agnostic ASPM layer that correlates findings from 300+ existing security tools into one prioritized backlog, without running its…
HUMAN Security
Bot mitigation and digital fraud prevention platform, formerly White Ops, protecting ad, application, and enterprise traffic from automated…