ThreatLocker
How to connect ThreatLocker to Cork
- Locate your ThreatLocker instance:
- In your ThreatLocker portal under the “Help” button on the top right written next to the “ThreatLocker Access” text in parentheses.
- This may be a single letter like B, C, G, etc
- Create an API User
- Navigate to the Administrators page and select "API Users"
- Create a new user and name the token something like "Cork Integration"
- Press "Generate API Token", copy this first
- Keep it set to expire for 365 days
- Select a Role
- You may need a new API User Role, if so, please ensure it has the following permissions:
- View organization
- View computers
- View reports
- View system audit
- View ThreatLocker threats
- View ThreatLocker policies
- View ThreatLocker remediations
- View unified audit
- Select All Organizations
- Press "Create"
- Enter the credentials in Cork
- Use just the single letter for the instance (c, d, e, etc)
- Paste the API token from Step 2C
- Press "Connect & Continue"
- If this fails, and you regenerated the token in step 2C, make sure you click "Save" on ThreatLocker