logo

The top 10 ThreatLocker policies for 2025

ID: b3a47972-5088-5d17-b088-6270499798a6

STIX ID: report--b3a47972-5088-5d17-b088-6270499798a6

Feed Name: ThreatLocker Blog

Date Published: 2025-03-06

Date Updated: 2026-05-01

...
...

This document outlines ThreatLocker’s top 2024 community policies for improving endpoint security, covering Application, Network, and Event/Storage controls that detect or alert on behaviors mapped to MITRE ATT&CK (e.g., Windows event log clearing, account creation, safe mode boot, PowerShell elevation and network use, RegSvr32 outbound communications) and notable IOCs like Defender tampering; it also highlights a policy to block a revoked AnyDesk certificate tied to a prior incident, provides runner-up policies, and directs readers to the ThreatLocker Portal’s Community module for deployment and ratings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.