All Collections
›
Integrations
›
Endpoint Detection and Response
ThreatLocker
Last updated 6 months ago
How to connect ThreatLocker to Cork
Locate your ThreatLocker instance:
In your ThreatLocker portal under the “Help” button on the top right written next to the “ThreatLocker Access” text in parentheses.
This may be a single letter like B, C, G, etc
Create an API User
Navigate to the Administrators page and select "API Users"
Create a new user and name the token something like "Cork Integration"
Press "Generate API Token", copy this first
Keep it set to expire for 365 days
Select a Role
You may need a new API User Role, if so, please ensure it has the following permissions:
View organization
View computers
View reports
View system audit
View ThreatLocker threats
View ThreatLocker policies
View ThreatLocker remediations
View unified audit
Select All Organizations
Press "Create"
Enter the credentials in Cork
Use just the single letter for the instance (c, d, e, etc)
Paste the API token from Step 2C
Press "Connect & Continue"
If this fails, and you regenerated the token in step 2C, make sure you click "Save" on ThreatLocker
Related Articles
Datto EDR (Infocyte)
Observed EDRs
Webroot
Sophos
Deep Instinct