Skip to main content

Deploy Threatlocker Agent

Summary​

This monitor detects both Mac and Windows agents that are missing Threatlocker agents. For windows Agents, client EDF Threatlocker_Organization_Name and for Mac agents Client EDF ThreatLockerMacGroupKey should not be blank in order to detect machines missing the agent. The monitor will exclude agents with either Location-Level EDF Exclude Threatlocker or Computer-Level EDF Exclude Threatlocker is marked.

Dependencies​

Target​

Both Windows and Mac Agents

Alert Template​

  • △ Custom - Execute Script - Threatlocker Agent Deployment

Changelog​

2025-06-27​

  • Initial version of the document