ThreatLocker Data-backed Assessment (2026)
Affiliate disclosure: Some links may be affiliate or partner links. If you sign up through one, we may earn a commission at no extra cost to you. This never changes our scores or rankings. Learn more.
- Starting price
- Custom quote
- Free trial
- 30 days
- Deployment
- Cloud
- Best for
- MSPs wanting Zero Trust allowlisting and ringfencing
Our verdict
ThreatLocker earns 8.2/10 in our review, weighted from 4.8/5 (~250 G2 reviews) and its feature/pricing profile. Best for MSPs wanting Zero Trust allowlisting and ringfencing. Starting price: Custom quote.
Backed by 4.8★ · 250 reviews on G2.
Pros & cons
✓ Pros
- Powerful Zero Trust controls
- Excellent support
- Strong MSP fit
✕ Cons
- Allowlisting requires ongoing tuning
- Quote pricing
- Different model than AV/EDR
Key features
- Application allowlisting
- Ringfencing
- Storage control
- Elevation control
- 24/7 Cyber Hero support
What users say
“Intelligent onboarding using learning mode to capture the current software and typically used files in an environment makes it seem less [daunting] to implement a zero trust endpoint protector that lets you sleep easily at night.”
“It is a love-hate relationship with ThreatLocker; everybody hates it because it causes so much need for user input to request to allow applications, but it is a necessary evil because security is paramount.”
“One downside of ThreatLocker is that it can be a bit complex to set up and manage, especially for smaller businesses or teams without dedicated IT resources. The pricing of this tool is comparatively high as compared to the other tools.”
How ThreatLocker compares
| ThreatLocker | SentinelOne Singularity | CrowdStrike Falcon | |
|---|---|---|---|
| Starting price | Custom quote | $69.99/endpoint/yr | $59.99/device/yr |
| Pricing model | quote | per endpoint | per endpoint |
| Free trial / tier | 30 days | Free trial | 15 days |
| Best for | MSPs wanting Zero Trust allowlisting and ringfencing | Teams wanting autonomous AI-driven EDR/XDR | Organizations wanting best-in-class cloud-native EDR + threat intel |
| Deployment | Cloud | Cloud | Cloud |
| G2 rating | 4.8/5 (250) | 4.7/5 (2000) | 4.7/5 (290) |
| Capterra rating | — | — | — |
| Our score | 8.2 | 8.4 | 8.3 |
Affiliate disclosure: Some links may be affiliate or partner links. If you sign up through one, we may earn a commission at no extra cost to you. This never changes our scores or rankings. Learn more.
Full review
ThreatLocker Review
ThreatLocker takes a deliberately different approach to endpoint security. Instead of chasing threats after the fact like traditional AV/EDR, it flips the model: deny everything by default, allow only what you explicitly permit. For the right buyer—especially MSPs—it’s a compelling proposition.
At a Glance
| Attribute | Detail |
|---|---|
| Vendor | ThreatLocker |
| Best for | MSPs wanting Zero Trust allowlisting and ringfencing |
| Deployment | Cloud |
| Our score | 8.2 / 10 |
| G2 rating | 4.8 / 5 (250 reviews) |
Pricing
| Item | Detail |
|---|---|
| Model | Quote-based |
| Starting price | Not published |
| Free tier | No |
| Free trial | 30 days |
| As of | 2026-06 |
Pricing is quote-only, which is a genuine friction point. There’s no starting price to anchor against, so budgeting means talking to sales. The 30-day trial helps you validate fit before committing, but the lack of transparency is a mark against it.
Features
- Application allowlisting — the core: block everything not explicitly approved
- Ringfencing — constrains what approved apps can do (limiting living-off-the-land attacks)
- Storage control — granular policy over USB and file access
- Elevation control — manage admin privileges without standing local admin
- 24/7 Cyber Hero support — human-backed support around the clock
Ringfencing is the standout here. Allowlisting alone stops unknown binaries, but ringfencing addresses the harder problem: what happens when a trusted app (PowerShell, Office) gets weaponized. That’s where ThreatLocker earns its Zero Trust credentials.
Pros & Cons
Pros
- Powerful Zero Trust controls that go beyond signature-based detection
- Excellent support (the Cyber Hero reputation is reflected in the 4.8 G2 score)
- Strong MSP fit — multi-tenant management and a model that scales across clients
Cons
- Allowlisting requires ongoing tuning — this is not set-and-forget
- Quote pricing with no public numbers
- A fundamentally different model than AV/EDR, requiring a mindset shift
Verdict
ThreatLocker is a legitimately strong product—its 4.8/5 across 250 G2 reviews is hard to argue with, and our 8.2 reflects real capability paired with real caveats. The biggest one isn’t a flaw so much as a warning: default-deny demands operational discipline. If your team can’t commit to maintaining allowlists, you’ll fight it constantly. That’s exactly why it shines for MSPs, who have the staffing and processes to manage tuning across clients.
Buy it if you want proactive, deny-by-default control and have (or are) an MSP with the operational muscle to run it. Look elsewhere if you want turnkey, hands-off detection or need transparent, self-serve pricing.
Frequently asked questions
- Is ThreatLocker worth it?
- ThreatLocker earns 8.2/10 in our review, weighted from 4.8/5 (~250 G2 reviews) and its feature/pricing profile. Best for MSPs wanting Zero Trust allowlisting and ringfencing. Starting price: Custom quote.
- What does ThreatLocker cost?
- From Custom quote — see the pricing page.
Based on aggregated third-party ratings (4.8/5 (~250 G2 reviews)) and ThreatLocker's published feature and pricing data. This page does not claim firsthand product use. See how we test.