Everything is permitted until something objects.
The ordinary endpoint operates on a rule that reads: allow anything, unless a product recognizes it as bad. Every piece of malware ever written has been, for some window of time, unrecognized. That window is the entire business model of the people attacking you.
Allowlisting inverts the rule. Nothing runs unless it is on the list. A novel loader with no signature anywhere is not a difficult case under this model, because being unknown is itself the disqualification.
ThreatLocker: default deny, then ringfence what you allowed.
Deployment opens with a learning period. The agent records what genuinely runs across your estate and assembles the baseline from observed reality rather than from a policy somebody imagined in a meeting. Approvals draw on behavior seen across a very large installed base, which is why the list comes together in days instead of quarters.
- Default deny. Executables, libraries, and scripts start because policy permits them by name. Anything else is refused, logged, and routed to us.
- Ringfencing. This is the part most buyers underrate. Being approved is not the same as being trusted with everything. Ringfencing governs what a permitted application may do next: which other applications it can call, what files it may reach, whether it may talk to the internet, what it may touch in the registry. It is the control that answers living off the land, where the intruder brings no payload at all and instead borrows the scripting engine or the remote tool you already approved.
- Elevation without handing out local admin. A named application can be allowed to run elevated for a named person, without that person holding administrator rights generally.
- Storage control. Policy over removable media and network shares, so which USB device may be read becomes a question with an answer.
The published line commits to something we take seriously: a 24x7 team handling every elevation request and escalation. Allowlisting fails as a control the moment approvals take a day, because somebody will then be instructed to turn it off. Ours are worked around the clock.
The first three weeks are the honest part
We will not pretend this control is invisible. There is a learning period, and after it there will be a morning when somebody installs something unusual and it does not start. Whether allowlisting survives inside a business is decided almost entirely by how fast that request gets answered.
So that is the part we staff. Requests reach a person, not a queue somebody reads on Tuesdays. Approvals are judged against the software, the user, and the situation. Updates to already-approved applications are tracked and rolled through automatically, so routine patching raises no request at all.
The lines in this family
One line / price fetched liveZero Trust Allowlisting
per endpoint| Model | Default deny application allowlisting |
|---|---|
| Controls | Allowlisting / ringfencing / elevation / storage policy |
| Baseline | A learning period builds the list from what your estate genuinely runs |
| Update handling | Updates to approved applications tracked and approved automatically |
| Requests | Elevation requests and escalations handled by our team, 24x7 |
| Platforms | Windows and macOS, workstations and servers alike |
| Counted by | One endpoint / monthly |
One line, one rate, applied the same way to a workstation and to a server. It is usually the highest-yield single control in this catalog.
What allowlisting will not do for you
It does not read your mail, so it cannot stop somebody typing their password into a convincing page. Credential theft that never involves running a program is untouched by it, and that belongs to Email security and to the identity correlation in Managed detection.
It does not catch misuse of what you already approved. Ringfencing narrows that considerably, but an intruder operating strictly inside permitted tools and permitted behavior is a detection problem rather than a permission one. This is why the two families are bought together.
And it adds friction, most of all early on. Any vendor telling you otherwise is selling. We think the trade is strongly worth making, and we staff the friction so that it is counted in minutes.
Heads up: card statements show FORTIFY 24X7 - CyberDefense is a Fortify 24x7 brand, and your subscription is billed by Fortify 24x7.