The top 10 ThreatLocker policies for 2025
ID: b3a47972-5088-5d17-b088-6270499798a6
STIX ID: report--b3a47972-5088-5d17-b088-6270499798a6
Feed Name: ThreatLocker Blog
This document outlines ThreatLocker’s top 2024 community policies for improving endpoint security, covering Application, Network, and Event/Storage controls that detect or alert on behaviors mapped to MITRE ATT&CK (e.g., Windows event log clearing, account creation, safe mode boot, PowerShell elevation and network use, RegSvr32 outbound communications) and notable IOCs like Defender tampering; it also highlights a policy to block a revoked AnyDesk certificate tied to a prior incident, provides runner-up policies, and directs readers to the ThreatLocker Portal’s Community module for deployment and ratings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
